Holiday Photos Are Fuelling a New Bank Fraud Scam
Criminals are scanning public Instagram and Facebook posts, then using AI to craft eerily personalised phishing messages that reference where you were, and when.

Key points
- Fraudsters are using publicly visible holiday photos on Instagram and Facebook to build convincing fake bank alerts.
- AI tools can read location tags, captions, and background details in images to extract where a person travelled and on what dates.
- The scam produces a text or email that quotes your destination back at you, making it feel like a genuine fraud warning from your bank.
- No system was hacked. The only data used is what victims posted themselves.
You post a couple of holiday snapshots on Instagram. A sunlit street, a river in the background, a caption about needing more of this. A few days later a text arrives: "We detected unusual activity while you were travelling in Porto. Please verify your card immediately."
It feels legitimate because it knows exactly where you were. It is not.
As first reported by The Guardian, this scam works by combining two things that are now very cheap and very accessible: public social media posts, and AI tools that can read images and extract details from them. Criminals, or automated tools they run, scan public profiles for recent travel posts, pull the location, and fire off a spoofed bank message, meaning one designed to look as though it came from your real bank, using your destination as the hook.
How does the scam actually work?
The criminal never breaks into your bank or your phone. They just read what you posted publicly.
AI image-analysis tools, software that can look at a photograph and describe what it contains, can now identify landmarks, street signs, and scenery well enough to pinpoint a city. If your post also includes a location tag or a caption mentioning the place, the job is even easier. The fraudster then sends you a text or email that mimics your bank's branding and references your trip, nudging you to click a link and "verify" your card details on a fake website.
| What the scammer uses | Where they get it |
|---|---|
| Your travel destination | Location tag, caption, or image analysis |
| Approximate travel dates | Post timestamp |
| Your phone number or email | Data broker lists or previous breaches |
| Your bank's name and logo | Publicly copied from the real bank |
The personal detail, your city, your dates, is what makes the message feel real. Phishing, where criminals send fake messages to trick people into handing over passwords or payment details, works best when the target believes the sender already knows something about them.
Should people who travel worry?
Not excessively, but the risk is real and easy to reduce with small habit changes.
No regulator has opened a formal enforcement action specifically tied to this technique at the time of writing, though the UK's Financial Conduct Authority and the Information Commissioner's Office both cover fraud and personal-data misuse respectively. The scam sits in a legal grey zone: the data was public, so no breach-notification law is triggered, yet the use of that data to defraud someone is plainly criminal.
What should you do?
Four practical steps worth taking now:
- Set your social profiles to private, or delay posting holiday photos until after you return home.
- Never click a link in an unexpected text or email about your bank card, however specific it seems. Open your banking app directly, or call the number on the back of your card.
- Your bank will never ask for your full card number, PIN, or password by text or email. If a message asks for any of those, it is a scam.
- Report suspicious messages in the UK to 7726 (the free SMS spam-reporting service), or to your national consumer-fraud authority.



