Holidaymakers who post pictures of their travels on Instagram or Facebook could be unwittingly handing fraudsters the tools to make their scams more convincing, according to new research from the cybersecurity firm McAfee.
The company found that artificial intelligence tools can identify the location of a photograph using only subtle visual clues, such as background architecture, signage, street markings or the quality of light, even when no location tag or metadata has been attached to the image.
Criminals can then use this information to craft fraudulent text messages or emails that appear to reference a victim's genuine travel plans, lending the approach a false sense of legitimacy. A typical message might read: "We detected unusual activity while you were travelling in Porto – please verify immediately," accompanied by a link asking the recipient to confirm their bank details.
Because the victim may not have shared any explicit details of their trip beyond an apparently indistinct photograph, they may have no reason to suspect the message is fraudulent.
McAfee tested two freely available AI models against a database of more than 21,000 travel images. One model correctly identified the location shown in 91% of cases, while the second achieved an accuracy of 87%. Staff at the company were then asked to try the same experiment using their own personal photographs, and reported feeling uncomfortable at how easily the AI systems were able to pinpoint where the pictures had been taken.
Vonny Gamot, head of EMEA at McAfee, said the technology gave scammers valuable context. "What AI does is give context … so that makes the scam [and] makes the threats credible," she said.
According to the research, images are most likely to be identified accurately when they contain recognisable landmarks, distinctive skylines, signage or street markings. Food stalls and shopfronts can also allow AI systems to quickly narrow down a location.
Photographs taken on beaches or inside hotel rooms are harder for the technology to pinpoint precisely. However, McAfee said it remained likely that such images could still be used to identify the country in which they were taken – which researchers said was often sufficient information for scammers to construct a credible approach.
In one example cited by the company, a staff member asked ChatGPT to identify the location shown in a picture of a river with trees in the foreground. The AI tool correctly identified the scene as Hastings-on-Hudson, an area in New York state.
In another test, a photograph of a bed of flowers was correctly identified as the Keukenhof gardens in the Netherlands. The AI system was reportedly able to deduce this from the specific layout of the tulips and the presence of smaller blue flowers planted between them.
Researchers said fraudsters could exploit such location data in a number of ways, including falsely claiming that a bank card had been flagged for suspicious activity in a particular city, that they were following up after a stay at a specific hotel, or that there had been an attempted login to an account from the country in question.
McAfee has urged social media users to take a number of precautions to reduce their exposure to this type of scam. It recommends delaying the posting of holiday photographs until after returning home, and reviewing privacy settings so that images are only visible to trusted contacts rather than the wider public.
As with other forms of fraud, the company advises consumers to be wary of any message that creates a sense of urgency, such as demands to act immediately, since this tactic is often used to prevent people from pausing to consider whether a request is genuine.
Consumers are also advised never to click on links contained within unsolicited texts or emails. Instead, anyone concerned that their bank account or personal details may have been compromised should contact their bank or the relevant organisation directly, using contact details found on an official website or printed on the back of a bank card.