Cybercriminals are increasingly targeting travellers, who now rely on digital platforms at every stage of their journey. In the last year, Kaspersky solutions have recorded almost 270,000 attack attempts that exploited the names of well-known brands in the tourism sector. To help users explore the world with greater peace of mind, Kaspersky has created “Kaspersky Safe Travel Insights”, a guide designed to travel more consciously and safely.
Brands in the transport sector: the main objective
Booking a trip today means using ride-sharing apps, airline sites and online travel agencies, constantly switching between browser tabs and devices, often under pressure to grab a great deal. This mix of urgency, trust in popular brands and continuous navigation creates fertile ground for cybercriminals, who exploit phishing pages, fake applications and fraudulent offers disguised as legitimate travel and transportation services.
Kaspersky researchers analyzed widespread cyber threats by exploiting the names of the main brands in the transport sector. From Q2 2025 to Q1 2026, Kaspersky solutions recorded 262,663 detections associated with these brands. Attacks imitating Emirates accounted for 61% of the total, followed by Uber with 37%. Trojans were the most widespread threat.
Among the scams identified by Kaspersky researchers, a classic fraud emerges that promises alleged compensation in the name of Ryanair. Victims receive a message advising them of their right to a refund for a flight; they are then asked to enter their account credentials or pay a small “processing fee” to release the funds. The scam leverages a strong sense of urgency, allowing only a few seconds to complete the transaction before the refund supposedly expires. This is a clear wake-up call: legitimate claims never have such a tight deadline, and airlines never ask for a fee upfront to process a refund.
Booking platforms and travel services
In addition to brands in the transport sector, Kaspersky also analyzed threats that exploit the name of the main travel and booking platforms. Again, Trojans were the most prevalent threat, accounting for 54.6% of detections. Web pages that mimic well-known platforms can be designed to steal credentials, steal payment data, install malware, or allow attackers to gain access to the victim’s device.

In another scam using the Booking.com name, victims are redirected to a very convincing fake booking page where they are asked to enter their personal and payment details to complete an apparently successful booking. In reality, no confirmation is sent, the room is never booked and the money ends up directly in the hands of scammers. Since the fake page faithfully reproduces the Booking.com payment process, many victims only notice the deception upon arrival at the property, when they discover that there is no reservation.
Expert advice

To protect yourself from these travel-related scams, Kaspersky recommends:
- Book directly via official websites or apps. Avoid clicking on links in emails, text messages or social media messages and instead go directly to the website of the airline, ride-sharing service or booking platform.
- Check the URL carefully before entering your payment details. Phishing pages often use domains very similar to official ones, which are difficult to distinguish at first glance.
- Be wary of “too good to be true” offers, especially if they require immediate action.
- Use strong, unique passwords for travel accounts and enable multi-factor authentication (MFA) when available.
- Download apps dedicated to travel and transport exclusively from official stores, always checking reviews and required authorizations.
- Please check your bank and credit card statements after each booking and report any unrecognized charges immediately.
- Only scan QR codes from trusted and verified sources. Before proceeding, always check the website address and payment details and avoid downloading files or applications via links contained in QR codes unless you have verified their legitimacy.
- When you need to use public Wi-Fi, a VPN allows you to encrypt your Internet connection, providing an extra layer of protection when accessing travel services, email, and online accounts.
52 billion reasons to worry: Your browser data is the new goldmine for hackers