4 Sources
[1]
Scammers Are Using AI to Pinpoint Where Your Holiday Photos Are Taken
Scammers are increasingly exploiting photos posted on social media to gather personal information about a target so they can use it against them. Research from McAfee, an anti-virus software company, found that AI models can geolocate even the most obscure travel photos, some achieving over 90% accuracy. The AI doesn't rely on any metadata or embedded coordinates; it just uses the image itself, picking up on clues like the background, the architecture, the signage, the light, or any naturally occurring details in a photo. McAfee fed over 20,000 images into two freely available AI vision models and asked them to geolocate each photo. One model achieved 87% accuracy, while the other achieved 91%. "That means in roughly 9 out of 10 cases, an AI model that's available for free, to anyone, could look at an ordinary travel photo and correctly name where it was taken," McAfee says. "And when the exact city wasn't identified, the country alone was almost always correct. For a scammer, that's more than enough. It's also enough to turn a vague, generic scam into one that feels specific, timely, and believable." How the Scam Works Say someone is on holiday in Costa Rica and shared a snap to Instagram and Facebook of themselves posing in front of a beautiful but anonymous vista. They haven't added any information about where they are exactly, but they just want to let people know they're doing something cool. But a few days later, while still on vacation, that person gets a text message that purports to be from their bank. It reads: "We detected unusual activity while you were traveling in Costa Rica -- please verify immediately." It seems legit, so they click on the link to confirm their details. Barring the vague photos shared on social media, nobody knows they are in Costa Rica. Nobody that is, except the clever AI model and the crooks that are using it. How to Prevent This Scam The Guardian suggests the best way is to delay posting photos on social media until you're back home. Alternatively, users can change their settings so that only trusted people can see them. Scammers often employ urgency as a tactic: if you get a text message referencing your holiday destination, treat that as a red flag rather than a sign of credibility. Scammers use location familiarity precisely because it feels reassuring. And finally, don't click on links included in text or emails; it's better to contact the bank or company using the details provided on their website. Image creditsHeader photo licensed via Depositphotos.
[2]
'We detected unusual activity': the scam that uses AI to exploit your holiday photos
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. "We detected unusual activity while you were travelling in Porto - please verify immediately," says the message. You click on the link to confirm your bank details. Since you have not put any details of your trip on any of your social networks - bar the indistinct pictures - you don't suspect there is anything suspicious about the messages. But the text was a fraud designed to extract your financial details. The criminals behind it figured out where you had been on holidays - lending credibility to their text - by using AI to analyse the image for the most sparse signs of where it was taken. New research has shown that by picking up on details in the picture - such as the background, the architecture, the signage or the light - the AI agent can pinpoint where it was taken. For criminals, this information gives attempts to defraud by text message or email an added legitimacy. McAfee, the producer of anti-virus software, used two freely available AI models to test more than 21,000 travel images. One of the models identified 91% of images accurately while the other got 87%. Staff were then asked to replicate the experiment with their own pictures and became uncomfortable with how easy their travels were pinpointed. The company says that it shows that computers don't need photos to be tagged or attached metadata to identify where they are taken. "What AI does is give context ... so that makes the scam [and] makes the threats credible," says Vonny Gamot, the head of EMEA at McAfee. What it looks like Pictures are more likely to be identified by AI if they have recognisable landmarks, skylines, signage and street markings. Food stalls and storefronts can also pinpoint quickly where the picture was taken. If the picture is taken on a beach or a hotel room, the accuracy of the AI is lowered. But McAfee reports that it is likely that the system can identify which country they were taken in - which is all the scammers need. When a staff member tested ChatGPT to identify a picture of a river with some trees in the foreground, it correctly pinpointed it as Hastings-on-Hudson, an area in New York state. Another picture of a group of flowers was identified as the Keukenhof gardens in the Netherlands. The AI agent correctly deduced that the layout of the tulips, along with smaller blue flowers planted between them, meant that it was the famous gardens in the picture. Criminals can use the information to make their approaches more convincing. They might say that your card was flagged for unusual activity while you were somewhere. Or that they are calling you after your stay in a particular hotel. Or that they want to confirm your identity because there has been an attempt to log in to your account from that country. What to do If you want to post pictures, delay until after you get home and change your settings so that only the people you know can see them. As with all scams, be wary about any urgency in the messages you are sent, such as being told that you need to act immediately. Fraudsters use this as a tactic in the hope that people react without thinking something through fully. Don't click on links that are provided in texts or emails; instead contact the company or bank through the details on their website or on the back of your bank card.
[3]
Your holiday photos could help scammers figure out exactly where you are
AI can extract surprisingly precise location clues from innocent-looking Instagram and Facebook posts, making phishing scams much more convincing. That innocent holiday snap might be doing more than showing everyone how good the weather is. A new scam highlighted by The Guardian shows how criminals can use AI to analyse photos posted on Instagram and Facebook, work out where they were taken, and then use that information to make phishing messages look frighteningly legitimate. The trick is surprisingly simple. Imagine posting a few family photos from Porto without mentioning the city anywhere. A few days later, a text arrives claiming that your bank detected unusual card activity while you were travelling in Porto and asking you to verify your details through a link. Because the message contains a detail that only someone who knows about the trip should know, it suddenly feels much more convincing. Except the scammer may never have known about the trip at all. The photo told them. AI doesn't need your location tag Research from McAfee tested more than 21,000 travel images using two freely available AI models. One correctly identified the location in 91% of cases, while the other reached 87%. Crucially, the images didn't need location tags or embedded metadata for the AI to work out where they were taken. The obvious giveaways are things such as famous landmarks, street signs, storefronts, road markings and recognisable skylines. But AI can apparently dig much deeper than that. McAfee found that even seemingly generic images could reveal useful clues. A beach or hotel room might only give away the country, but that could still be enough information for a scammer to make a message sound credible. Recommended Videos In one test, ChatGPT correctly identified a seemingly ordinary river scene as Hastings-on-Hudson in New York. Another image showing flowers was traced to the Keukenhof gardens in the Netherlands, based partly on the arrangement and combination of flowers in the image. The scam gets convincing very quickly Once scammers know where someone has been, they can use that context to make phishing messages far more convincing, whether it's a fake bank alert about card activity, a suspicious login from the country visited, or even a hotel asking for verification. As McAfee's head of EMEA, Vonny Gamot, told The Guardian, AI can provide the extra context that makes otherwise generic scams feel much more credible. The simplest precaution is also the most annoying: consider waiting until the trip is over before posting holiday photos publicly, or at least limit them to friends and family. And if a message claims that a bank account or card has been compromised, don't click its link, no matter how convincing it looks. Contact the bank directly through its official app, website, or the number on the back of the card instead. The unsettling part is that scammers don't need a photo with a famous landmark or location tag anymore. A seemingly ordinary picture can contain enough visual clues for AI to work out where it was taken, turning a harmless holiday snap into useful intelligence. Your photos may be memories to you, but to a scammer with the right AI tools, they can be a surprisingly detailed map of where you've been.
[4]
AI can now figure out where your photos were taken, even without GPS data: Report
AI powered image analysis is creating a new privacy concern for social media users by making it possible to estimate where a photograph was taken without relying on GPS or location metadata. According to McAfee Labs findings, AI systems can identify the location shown in 87 to 91 per cent of tested travel photos. AI can identify locations from visual clues The modern geolocation systems do not necessarily need EXIF or GPS information to determine where a picture was taken. Instead, they examine details visible within the image, including buildings, road signs, architecture, road markings, vegetation, landscapes and recognisable landmarks. Even the photos that appear generic can get useful clues. A hotel room, beach, river or street scene may reveal details about the country or region through its surroundings, design and natural features. This means deleting location metadata from a photograph may not be enough to prevent its location from being identified. Scammers can use AI generated location clues But the bigger question is how this technology can be used to frame an attack against somebody. For example, someone posting photographs from a holiday can unintentionally reveal that they are travelling or identify the city they are visiting. A scammer can then use that information to create a more convincing message, such as a fake banking alert referring to activity in the same location. Because the message contains information which matches the victim's recent social media activity, it may appear more legitimate and increase the chances of the victim falling for the scam. How to reduce the risk The users can take many steps to limit how much location information their photos reveal. One simple way is to avoid posting holiday photographs while still travelling and upload them after returning home. You can also restrict social media posts to friends or trusted contacts can also reduce exposure. Users should also look at their images before posting them and check whether signs, landmarks, hotel names or other identifiable details reveal their location. Removing GPS and EXIF metadata remains useful, but it should not be considered complete protection. The visual information contained inside the photograph can still be analysed by AI, meaning users may need to think about what their images reveal beyond the metadata attached to them.
Share
Copy Link
McAfee research reveals AI vision models can geolocate 91% of travel photos posted on social media without metadata. Scammers exploit this to create convincing phishing messages and fake bank alerts that reference exact vacation locations, turning innocent Instagram and Facebook posts into tools for targeted fraud.
Scammers using AI are exploiting holiday photos shared on Instagram and Facebook to launch increasingly sophisticated phishing attacks. Research from McAfee
1
demonstrates that freely available AI vision models can identify locations in travel photos with alarming precision—one model achieved 91% accuracy while another reached 87% when tested against over 21,000 images2
. These AI-driven scams don't require location tags or metadata to work. Instead, AI-powered image analysis examines visual clues embedded within photographs—architecture, signage, road markings, vegetation, landscapes, and even the arrangement of flowers3
.
Source: Digit
The mechanics behind these AI scams are disturbingly straightforward. Someone posts seemingly anonymous photos from Porto, carefully avoiding any mention of their destination. Days later, they receive a text claiming unusual activity was detected on their bank account while traveling in Porto
2
. The message feels legitimate precisely because it references a detail only someone aware of the trip should know. But the scammer never had insider knowledge—AI to geolocate travel photos provided that intelligence. McAfee's head of EMEA, Vonny Gamot, explains that AI gives context to make threats credible2
. Even generic images reveal enough information for targeted fraud messages. A beach or hotel room might only identify the country, but that's sufficient for scammers to craft convincing fake bank alerts3
.
Source: Digital Trends
The technology behind these privacy risks operates without traditional location markers. Modern geolocation systems examine buildings, road signs, storefronts, natural features, and recognizable landmarks
4
. McAfee staff tested the system with their own photographs and became uncomfortable with how easily AI identified their travels2
. ChatGPT correctly identified a river scene as Hastings-on-Hudson in New York, while another image showing flowers was traced to Keukenhof gardens in the Netherlands based on tulip layout and smaller blue flowers planted between them2
3
. Deleting EXIF data or GPS information provides minimal protection since visual information within photographs remains analyzable4
.Related Stories
Delay posting holiday photos on social media until returning home, or adjust privacy settings so only trusted contacts can view them
1
2
. Review images before posting to check whether signs, landmarks, hotel names, or other identifiable details reveal locations4
. Treat urgency in messages as a red flag rather than credibility—scammers deliberately use location familiarity because it feels reassuring1
. Never click links in texts or emails claiming account compromise. Contact banks directly through official websites, apps, or numbers on card backs2
3
. What makes this threat particularly unsettling is that scammers no longer need famous landmarks or location tags—ordinary pictures contain enough visual clues for AI to map where you've been, transforming harmless memories into intelligence for fraud3
.Summarized by
Navi
[2]
[3]
24 Feb 2026•Technology

25 Jan 2025•Technology

15 Jun 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
