Kaspersky reports nearly 270,000 travel-related cyberattacks in the past year, highlighting increased threats from fake booking pages, holiday scams, and malware aimed at transport and accommodation services, urging travellers to stay vigilant.
Cybercriminals are increasingly exploiting the habits of travellers, using the pressure of booking flights, rides and accommodation to push people into clicking on malicious links or entering payment details on fake pages. Kaspersky said it recorded nearly 270,000 attack attempts over the past year disguised as travel-related brands, with the biggest concentration aimed at transport services. The wider threat picture is also worsening: the company said it detected an average of 500,000 malicious files a day in 2025, while malicious email attacks rose 15% and password-stealing malware also increased sharply.
In its latest travel-focused analysis, Kaspersky said it observed 262,663 detections linked to transport brands between the second quarter of 2025 and the first quarter of 2026. Emirates accounted for 61% of those detections, followed by Uber at 37%, showing how attackers tend to concentrate on familiar, high-volume services. Kaspersky said Trojans made up 30.5% of the files and objects it identified in this category, while Trojan-bankers accounted for 22.5%, pointing to a strong emphasis on stealing financial credentials rather than simply disrupting bookings.
The company also highlighted a Ryanair-themed compensation scam in which victims are told they are due a payout and are then pushed to submit account details or pay a small processing fee. According to Kaspersky, the fraud depends on urgency and uses a short time window to pressure users into acting before checking whether the offer is genuine. Similar tactics were seen in fake Booking.com pages that mimic the real reservation flow closely enough to deceive users into entering personal and card information, only to leave them with no booking and no confirmation.
Kaspersky said the risks are not limited to airlines and ride-hailing platforms. It recorded 5,414 attack attempts against travel and accommodation brands in the same period, with Trojans again the most common threat type at 54.6%. The company said these accounts can hold payment data, booking histories and private messages, making them valuable targets for criminals seeking both money and access to devices. Its broader research also shows that cybercrime remains highly opportunistic, with email, shopping and gaming platforms all heavily targeted in 2025.
Kaspersky’s advice is straightforward: book through official websites or apps, check web addresses carefully, avoid offers that demand immediate action and use strong, unique passwords with multi-factor authentication where available. The company also recommends downloading apps only from official stores, monitoring bank statements after making reservations and treating QR codes with caution unless their source can be verified. Its Safe Travel Guide adds that public Wi-Fi should be used carefully and that additional protections such as a VPN can help reduce exposure when travellers are accessing accounts on the move.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





