2 Sources
[1]
'We detected unusual activity': the scam that uses AI to exploit your holiday photos
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. "We detected unusual activity while you were travelling in Porto - please verify immediately," says the message. You click on the link to confirm your bank details. Since you have not put any details of your trip on any of your social networks - bar the indistinct pictures - you don't suspect there is anything suspicious about the messages. But the text was a fraud designed to extract your financial details. The criminals behind it figured out where you had been on holidays - lending credibility to their text - by using AI to analyse the image for the most sparse signs of where it was taken. New research has shown that by picking up on details in the picture - such as the background, the architecture, the signage or the light - the AI agent can pinpoint where it was taken. For criminals, this information gives attempts to defraud by text message or email an added legitimacy. McAfee, the producer of anti-virus software, used two freely available AI models to test more than 21,000 travel images. One of the models identified 91% of images accurately while the other got 87%. Staff were then asked to replicate the experiment with their own pictures and became uncomfortable with how easy their travels were pinpointed. The company says that it shows that computers don't need photos to be tagged or attached metadata to identify where they are taken. "What AI does is give context ... so that makes the scam [and] makes the threats credible," says Vonny Gamot, the head of EMEA at McAfee. What it looks like Pictures are more likely to be identified by AI if they have recognisable landmarks, skylines, signage and street markings. Food stalls and storefronts can also pinpoint quickly where the picture was taken. If the picture is taken on a beach or a hotel room, the accuracy of the AI is lowered. But McAfee reports that it is likely that the system can identify which country they were taken in - which is all the scammers need. When a staff member tested ChatGPT to identify a picture of a river with some trees in the foreground, it correctly pinpointed it as Hastings-on-Hudson, an area in New York state. Another picture of a group of flowers was identified as the Keukenhof gardens in the Netherlands. The AI agent correctly deduced that the layout of the tulips, along with smaller blue flowers planted between them, meant that it was the famous gardens in the picture. Criminals can use the information to make their approaches more convincing. They might say that your card was flagged for unusual activity while you were somewhere. Or that they are calling you after your stay in a particular hotel. Or that they want to confirm your identity because there has been an attempt to log in to your account from that country. What to do If you want to post pictures, delay until after you get home and change your settings so that only the people you know can see them. As with all scams, be wary about any urgency in the messages you are sent, such as being told that you need to act immediately. Fraudsters use this as a tactic in the hope that people react without thinking something through fully. Don't click on links that are provided in texts or emails; instead contact the company or bank through the details on their website or on the back of your bank card.
[2]
Your holiday photos could help scammers figure out exactly where you are
AI can extract surprisingly precise location clues from innocent-looking Instagram and Facebook posts, making phishing scams much more convincing. That innocent holiday snap might be doing more than showing everyone how good the weather is. A new scam highlighted by The Guardian shows how criminals can use AI to analyse photos posted on Instagram and Facebook, work out where they were taken, and then use that information to make phishing messages look frighteningly legitimate. The trick is surprisingly simple. Imagine posting a few family photos from Porto without mentioning the city anywhere. A few days later, a text arrives claiming that your bank detected unusual card activity while you were travelling in Porto and asking you to verify your details through a link. Because the message contains a detail that only someone who knows about the trip should know, it suddenly feels much more convincing. Except the scammer may never have known about the trip at all. The photo told them. AI doesn't need your location tag Research from McAfee tested more than 21,000 travel images using two freely available AI models. One correctly identified the location in 91% of cases, while the other reached 87%. Crucially, the images didn't need location tags or embedded metadata for the AI to work out where they were taken. The obvious giveaways are things such as famous landmarks, street signs, storefronts, road markings and recognisable skylines. But AI can apparently dig much deeper than that. McAfee found that even seemingly generic images could reveal useful clues. A beach or hotel room might only give away the country, but that could still be enough information for a scammer to make a message sound credible. Recommended Videos In one test, ChatGPT correctly identified a seemingly ordinary river scene as Hastings-on-Hudson in New York. Another image showing flowers was traced to the Keukenhof gardens in the Netherlands, based partly on the arrangement and combination of flowers in the image. The scam gets convincing very quickly Once scammers know where someone has been, they can use that context to make phishing messages far more convincing, whether it's a fake bank alert about card activity, a suspicious login from the country visited, or even a hotel asking for verification. As McAfee's head of EMEA, Vonny Gamot, told The Guardian, AI can provide the extra context that makes otherwise generic scams feel much more credible. The simplest precaution is also the most annoying: consider waiting until the trip is over before posting holiday photos publicly, or at least limit them to friends and family. And if a message claims that a bank account or card has been compromised, don't click its link, no matter how convincing it looks. Contact the bank directly through its official app, website, or the number on the back of the card instead. The unsettling part is that scammers don't need a photo with a famous landmark or location tag anymore. A seemingly ordinary picture can contain enough visual clues for AI to work out where it was taken, turning a harmless holiday snap into useful intelligence. Your photos may be memories to you, but to a scammer with the right AI tools, they can be a surprisingly detailed map of where you've been.
Share
Copy Link
Criminals are using AI to analyze holiday photos posted on Instagram and Facebook to pinpoint travel locations with 91% accuracy. This information enables fraudulent messages claiming unusual card activity that appear legitimate, tricking users into sharing bank account details through phishing links.

Criminals are weaponizing AI to exploit your holiday photos posted on Instagram and Facebook, creating an AI scam that turns innocent vacation snapshots into tools for fraud. New research from McAfee reveals how AI to analyze social media photos can identify locations with alarming precision, enabling scammers to craft phishing messages that feel disturbingly legitimate
1
.The scam works deceptively simply. You post family photos from Porto without mentioning the city. Days later, a text arrives claiming your bank detected unusual card activity while you were traveling in Porto, urging immediate verification. Because the message contains specific location details, it suddenly carries credibility. But the scammer never knew about your trip through conventional means—the photo revealed everything
2
.McAfee tested more than 21,000 travel images using two freely available AI models, with startling results. One model achieved 91% accuracy in location identification, while the other reached 87%
1
. Crucially, these AI systems don't require geotags or metadata to pinpoint where travel photos were taken.The AI analyzes visual elements including architecture, signage, street markings, storefronts, food stalls, and skylines. Even seemingly generic images reveal enough clues for identification. While beach or hotel room photos lower accuracy, the AI typically identifies at least the country—sufficient information for fraudulent messages to appear credible
1
.In testing, ChatGPT correctly identified a river scene as Hastings-on-Hudson in New York. Another image showing flowers was traced to the Keukenhof gardens in the Netherlands, based on the arrangement and combination of tulips with smaller blue flowers planted between them
1
2
.Vonny Gamot, head of EMEA at McAfee, explains that AI provides context that makes threats credible
1
. Scammers leverage this location intelligence to extract bank account details through multiple approaches: messages about cards flagged for unusual activity in specific locations, calls referencing particular hotels, or identity confirmation requests citing login attempts from visited countries.The unsettling reality is that scammers no longer need famous landmarks or location tags. A seemingly ordinary picture contains enough visual clues for AI to construct a detailed map of where you've been
2
. What appears as memories to users becomes valuable intelligence for criminals equipped with AI tools.Related Stories
Delay posting holiday photos on social media until after returning home. Adjust privacy settings so only known contacts can view your travel photos on Instagram and Facebook
1
.Recognize urgency tactics in phishing messages. Fraudsters create pressure for immediate action, hoping victims react without scrutinizing details. Never click links provided in texts or emails claiming account issues. Instead, contact banks directly through official websites, apps, or numbers on the back of bank cards
1
2
.McAfee staff who tested AI location identification on their own photos became uncomfortable with how easily their travels were pinpointed
1
. This discomfort should translate into heightened awareness about what seemingly innocent social media posts reveal, and how AI to exploit your holiday photos represents a growing cybersecurity concern requiring vigilance from all users.Summarized by
Navi
[1]
[2]
24 Feb 2026•Technology

15 Jun 2026•Technology

18 Dec 2024•Technology

1
Technology

2
Technology

3
Policy and Regulation
