Tourists have historically been targeted by cybercriminals, for a range of reasons. They tend to be fatigued, mentally, and drawn to the promise of good deals. They also have reason to expect correspondence from hotels, airlines, and booking agencies, which might make them more susceptible to phishing.
The threats faced by the average traveller have evolved considerably in recent years. Let’s take a look at some of the trends worth paying attention to, and consider how we might protect ourselves.
The Shift to Mobile-First Attacks
Since more and more of us are willing to use our phone as our primary device for communicating via the internet, it makes sense that attacks should be optimized for handhelds. When we’re on the move, and our phone becomes our sole means of engaging with online services, this becomes even more so. One good example is the phenomenon of ‘quishing’, which uses real-world QR codes in order to direct users to malicious websites.
AI-Driven Phishing and Social Engineering
Phishing campaigns are now conducted under a very different set of conditions. Once, it was only feasible to throw out millions of emails in the hope that a few of them would be successful; now, phishers can use AI to make their messages far more tailored and convincing. Impersonating trusted services, and scamming the same person in the same way via many channels, can make the threat far more challenging.
Public WiFi, Rogue Networks and Data Interception
If you’re traveling, then you might be tempted to connect to a public Wi-Fi network, for the sake of convenience. But these networks provide hackers with easy access to thousands of tourists, especially when they’re in public places that enjoy high traffic. If you’re tempted to log in using a network in an airport, for example, it’s often prudent to verify the network’s name, and to route your traffic through a VPN on your device. In fact, it’s often best to simply avoid public WiFi altogether, and stick to your cellular network.
Expanding Attack Surface Across Travel Ecosystems
As we make greater use of digital services, we create a larger ‘attack surface’ for malicious actors to latch onto. A data breach in one of the services you use, for example, might cause problems in others. This goes especially if you’re using the same password over and over again. The use of a password manager, and a principle of least privilege, can be very helpful.
