As millions of travelers prepare for summer holidays, cybercriminals seem to be doing the same.
New research from travel eSIM app Saily, based on dark-web intelligence provided by NordStellar, found that discussions related to Airbnb scams have increased nearly 30x compared to the first half of 2023.
The findings suggest scammers are increasingly moving away from obvious fake listings and instead targeting verified host accounts, allowing fraudulent properties to appear under trusted profiles with reviews, booking history, and verified status.
Researchers observed growing criminal discussions around hijacked hotel booking accounts, phishing kits targeting tourists, fake travel eSIM stores, and even deepfake identity verification services sold for travel related accounts. According to the findings, at least 15 travel specific scam tutorials and methods appeared in underground communities between January and May 2026 alone.
“Travel scams are becoming significantly harder to spot because criminals are increasingly abusing systems people already trust. Instead of creating obviously fake websites, attackers are moving inside legitimate travel platforms and verified communication channels,” says Vykintas Maknickas, CEO at Saily.
1. “Verified” hotel booking messages may not be real
Researchers identified growing discussions around compromised hotel-side booking accounts being used to message travelers directly through legitimate-looking chats. In many cases, victims receive fake payment requests through what appears to be an official hotel conversation.
Unlike traditional phishing scams, these attacks often happen inside trusted booking platforms, making them significantly more convincing for travelers who already completed a reservation.
“If a traveler receives a payment request inside what appears to be a legitimate hotel conversation, many people won’t immediately question it. That’s what makes these attacks so effective,” says Maknickas.
What to do: Never enter payment details through links sent in booking chats. If a hotel requests additional payment, confirm it directly through official contact channels.
2. Fake travel eSIM stores are targeting tourists
Researchers also observed growing activity around fake travel eSIM stores and stolen travel eSIM accounts being sold in underground communities. Some scams imitate legitimate providers to steal payment details or personal information from travelers looking for quick mobile data abroad.
In some cases, disposable eSIMs are reportedly being sold alongside phishing tools and OTP bypass services designed to help scammers avoid detection while targeting travelers.
What to do: Only purchase eSIMs directly from official providers and avoid links shared through ads, social media comments, or unknown travel groups.
3. Public Wi-Fi remains one of the easiest targets
Cybercriminals continue exploiting insecure hotel, airport, and café Wi-Fi networks through fake hotspots and data interception attacks designed to capture passwords, banking details, or login sessions.
Researchers say travelers often become less cautious while abroad, especially when urgently searching for internet access after landing or arriving at hotels.
What to do: Avoid accessing sensitive accounts on public Wi-Fi where possible and rely on secure mobile connectivity instead.
4. Deepfake identity scams are entering travel services
Researchers observed growing discussions around deepfake identity verification bypass services being sold for platforms linked to travel and mobility, including accommodation, ride-sharing, and payment services.
These services are increasingly packaged together with stolen accounts, fake IDs, and verification tools designed to bypass platform security systems.
“The worrying shift is that scammers are moving inside trusted ecosystems instead of trying to lure users away from them,” Maknickas adds.
What to do: Be cautious of suspicious verification requests, unusual account activity, or anyone pressuring you to continue communication outside official platforms.
5. Airbnb scam activity jumps 30 times since 2023
As travelers rush to secure accommodation for their summer holidays, cybercriminals appear to be preparing as well. New findings from NordStellar’s dark-web monitoring dataset show that discussions related to Airbnb scams have increased nearly 30x compared to the first half of 2023. Researchers say one of the most concerning trends involves compromised host accounts, which allow fraudsters to publish fake listings under profiles that already have reviews, booking history, and verified status.
Unlike traditional accommodation scams that rely on obviously fake profiles, compromised host accounts can make fraudulent listings appear far more trustworthy. This makes it significantly harder for travelers to distinguish between legitimate offers and scams, particularly during peak travel periods when accommodation is scarce and booking decisions are often made quickly.
“Travelers have become relatively good at spotting obvious scams. What’s much harder to identify is a fraudulent listing published under what appears to be a legitimate, verified host account. Criminals understand that trust is one of the most valuable assets on booking platforms and are increasingly trying to exploit it,” Maknickas adds.
What to do: Be cautious of listings that seem unusually cheap for the area, hosts who pressure you to act quickly, or requests to continue conversations or payments outside the platform. Whenever possible, keep all communication and transactions within Airbnb’s official channels.
Methodology:
We used Nordstellar’s dark-web forum and Telegram dataset from January 2023 to May 2026, split into calendar six-month chunks with the earliest year as the baseline. That lets us see whether the 2025-2026 jump in travel-scam talk is genuinely new. We searched for the scams the Telegraph article describes, plus adjacent topics that came up. For each topic we counted mentions per six-month bucket, then read recent posts to confirm they were really about travel.
A warning on the numbers: a few Telegram channels post dozens of generic spam ads every day, padded with words like “hotel” or “Airbnb”. That inflates raw counts. Treat absolute numbers as a direction, not an exact size.
ABOUT SAILY:
Saily is an affordable and secure travel eSIM app that helps people to manage mobile and internet connections from anywhere in the world. Saily offers 24/7 instant customer support, flexible plans, and coverage in 200+ destinations. Saily was created by the experts behind NordVPN – the advanced security and privacy app.The research also uncovered a broader shift in travel scams ahead of the summer season, including compromised hotel booking accounts used to send fake payment requests, fake travel eSIM stores, and deepfake identity verification services marketed for travel-related platforms.