Cyberthreats
From booking to boarding: Why travel creates the perfect conditions for social engineering
The main holiday season may be drawing to a close, but travel is far from over. Some people have already returned home, while others are still heading to the airport, checking into hotels or making last-minute changes to their plans.
I have recently returned from travelling myself. I love discovering new places, meeting people and learning about cultures beyond my own. Travel opens our horizons – but it also changes the context in which we make decisions.
My career began in tourism. Today, I work in cybersecurity. This combination has made me more aware of the moments in which the trust, excitement and occasional stress of travelling can be used against us.
The problem is not that people suddenly become careless when they travel. It is that travelling creates exactly the conditions in which social engineering can work particularly well.
Table of contents
When urgency feels entirely normal
When travelling, we move between locations, platforms, currencies, languages and networks. We check departure boards, search for unfamiliar addresses and try to resolve problems before reception closes or a flight departs.
At the same time, we expect to hear from airlines, hotels, booking platforms, payment providers and local transport services. A message claiming that a reservation needs to be reconfirmed, a payment has failed or a flight has changed may therefore feel entirely plausible.
In this environment, urgency does not automatically feel suspicious. It feels like part of the journey.
That is what makes travel-related social engineering so effective. An attacker does not necessarily need to invent a completely new story. They only need to place a convincing request within a journey that is already under way.
A legitimate channel does not guarantee a legitimate request
Travel scams are no longer limited to badly written emails or implausible offers. A message can look professional, refer to a real journey and arrive at exactly the moment when we expect an update.
It may even appear within a communication channel that we already use and trust. If an account involved in the booking process has been compromised, simply opening the official app may not be enough to establish that a payment request is genuine.
The better question is therefore not only, ‘Does this message look real?’ It is: ‘Does this request match the booking and payment process I originally agreed to – and can I verify it independently?’
Be particularly careful if you are suddenly asked to enter payment details again, transfer money through a different method or act immediately to prevent a cancellation.
Instead of relying on the contact details or links within the message, check the original booking terms and contact the accommodation, airline or booking service through a separately sourced channel. A brief pause may feel inconvenient, particularly when travelling. But urgency is exactly the moment in which that pause matters most.
The network matters, too
Travelling also changes how we connect. Airports, railway stations, hotels and cafes make public Wi-Fi convenient and sometimes necessary. But convenience should not be confused with trust.
An open or unfamiliar Wi-Fi network is not the same as your own mobile data connection. Where possible, use mobile data or another trusted connection for banking, payments and changes to important accounts.
If a sensitive transaction is not urgent, it can wait. If it is urgent, check which network your device is actually using and verify the service and the request independently before entering any information.
The aim is not to make people afraid of using technology while travelling. It is to create a small moment of reflection within journeys that are often designed around speed and convenience.
We need to talk about the experiences that go wrong
There is another reason why travel-related scams remain difficult to address: people do not always talk about them.
Being deceived can come with a sense of shame. We may believe that we should have noticed something, reacted differently or known better. This can be even harder when a message looked convincing, referred to a real booking or appeared in a familiar environment.
But social engineering is designed to manipulate context, trust and emotion. Experiencing it is not proof of carelessness or a lack of intelligence.
These incidents are now, unfortunately, part of everyday digital life – during our travels as well as at home and at work. Silence does not make us safer. Sharing what happened can.
The more openly we discuss these experiences, the easier it becomes for others to recognise similar situations. Each conversation helps reduce the stigma, makes the methods visible and gives someone else the opportunity to pause before acting.
3 habits can make a meaningful difference
Pause when a message creates urgency. Pressure to pay or respond immediately is a reason to verify, not a reason to hurry.
Check the request, not just the channel. Even a familiar environment cannot automatically guarantee that an unexpected request is genuine.
Choose your connection deliberately. For payments and other sensitive activities, prefer mobile data or a trusted private network to public Wi-Fi.
Travel opens our horizons by allowing us to learn from new places, cultures and people. We can bring the same openness to conversations about the moments that did not go as planned.
By sharing our experiences rather than hiding them, we can help make the digital side of travelling safer for one another.












