Rise of sophisticated travel scams prompts urgent consumer warnings

As fake travel apps and spoofed booking websites proliferate online, experts warn travellers of the increasing threat of cyber fraud, stressing the importance of verifying links, using strong passwords and being cautious with holiday offers, especially during peak travel periods and major events like the World Cup 2026.

Fake travel apps, spoofed booking websites and bogus holiday offers are proliferating as more people arrange trips online, with cybersecurity specialists warning that the combination of urgency, payment details and multiple platforms gives fraudsters an easy opening. In Muscat, Sunil D’souza said holidaymakers should double-check a booking URL before entering card details because phishing pages built to resemble airlines, transport services or booking platforms often rely on lookalike domain names that can be missed at first glance.

A report from Kaspersky said one transport brand alone helped block nearly 270,000 cyberattack attempts over the past year. The company said most of the activity centred on fake versions of a small number of widely recognised brands, with airline impersonation accounting for 61% of detections linked to transport services and road transport apps making up 37%. The report added that Trojans were the most common malware type, while Trojan-Bankers, which are designed to steal banking credentials and payment information, were also heavily represented.

The threat is not confined to transport. Kaspersky said it recorded 5,414 attack attempts tied to travel and accommodation services in a year, with Trojans making up 54.6% of detections in that category. The company said travel accounts are attractive to criminals because they can contain payment details, personal information, booking histories and messages with hotels or activity providers. It also warned that attackers often exploit major events and peak travel periods, including in a separate warning about World Cup 2026 travellers.

Consumer protection guidance from the US Federal Trade Commission matches that warning, advising travellers to be sceptical of “free” holiday offers that require upfront payments, to avoid links in unexpected emails or texts and to be wary of wire transfers and gift cards as payment methods. Tariq al Barwani, founder of Tech Oman, said travellers should treat offers that seem “too good to be true” with caution and should use strong, unique passwords, turn on multi-factor authentication where available, download apps only from official stores and monitor bank and card statements after booking. Kaspersky also urged users to verify QR codes, website addresses and payment details before proceeding, and to avoid downloading files from QR code links unless they have been checked carefully.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.