AI geolocation of holiday photos raises privacy and security alarms

New McAfee research reveals that AI models can pinpoint the location of holiday snapshots without metadata, prompting concerns over personal privacy, scams, and the misuse of geolocation tools.

A new McAfee study suggests that ordinary holiday snapshots and social media posts may reveal far more than many users realise. According to the company, open-weight AI models were able to work out where a photo was taken even when no GPS data, location tags or captions were available, raising fresh concerns about how easily personal travel habits can be pieced together from images alone.

McAfee said it tested Google’s Gemma 3 27B and Alibaba’s Qwen 3 VL 30B on 21,236 travel images. Gemma correctly identified the city and country 87% of the time, while Qwen reached 91%. The models relied on visual clues in the picture itself, including buildings, signage, skylines, street markings, shop fronts and food stalls. Well-known landmarks were easier to place, but even less distinctive scenes often still gave away the country, according to the study.

The findings reflect a wider market for AI-powered geolocation tools that claim to identify where a picture was taken from the image alone. Services including GeoSpy, GeoAxis, Load Q, GeoInfer, Oceanir and PhotoRadar say they can analyse architecture, terrain, plants, signs and other visible markers without needing EXIF data or other metadata. Some of these tools say they are used by investigators, journalists and enterprises, underscoring how quickly location tracing has moved beyond specialist circles.

McAfee warned that the same capability could make scams more convincing. A fraudster could feed public travel photos into an AI model, infer a likely destination and timing, and then send messages tailored to that trip, such as alerts about supposed card fraud or suspicious logins. Those messages do not have to be perfect; they only need to sound credible enough to lower a target’s guard. The warning comes as India’s cybercrime problem continues to grow. Figures cited by the Ministry of Home Affairs show 28.15 lakh cases were recorded in 2025, up from 22.68 lakh in 2024, while losses from cybercrime last year were put at Rs 22,495 crore.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.