AI travel photo scams have found a new vector: the holiday pictures you post on Instagram or Facebook, stripped of any caption or location tag, are enough for fraudsters to know exactly where you have been. New research from McAfee Labs, published 1 July 2026, shows that freely available AI vision models can geolocate travel images with alarming accuracy, handing scammers the one thing that makes a phishing text genuinely dangerous: credibility.

How AI Travel Photo Scams Are Built

McAfee’s Safer Summer Travel Report tested two publicly accessible AI models across 21,236 travel images. Gemma3 27B correctly identified the city and country in 87% of cases; Qwen3 VL 30B reached 91% accuracy. Neither model required special access or technical expertise to operate.

A separate controlled test used 102 images contributed by McAfee staff members who had never previously posted those photographs publicly. The results were sufficiently uncomfortable that employees rethought what they shared online.

McAfee is clear that these figures are not universal. As the company’s own report states, results varied by image type, landmark density, and geographic region, and the research does not claim that every travel photo will be correctly identified. Images taken on a beach or inside a hotel room are harder to pin down than those with recognisable architecture or street signage. But for a scammer’s purposes, identifying the country, or even a plausible city, is sufficient to craft a convincing message.

Steve Grobman, chief technology officer at McAfee, put it plainly in comments reported by ABC7 Chicago: ‘the most minute detail in a post can be picked up in AI models… anything you are posting is not only available to human ears and eyes but AI models that bad actors are using.’

The mechanics of the scam follow a logical sequence. A fraudster runs your holiday photo through an AI vision tool, gets a location read, then sends a text or email referencing that location. ‘We detected unusual activity while you were travelling in Porto, please verify immediately.’ You assume only someone with genuine access to your account could know where you had been. You click. That assumption is the exploit.

As McAfee’s researchers wrote, and as summarised by KnowBe4: ‘Knowing where someone is or where they’ve recently been is one of the oldest tricks in a scammer’s playbook. But until recently, getting that information required either knowing the person or getting lucky. AI removes the guesswork, allowing attackers to build highly specific, contextual scams at scale.’

Vonny Gamot, head of EMEA at McAfee, describes the shift concisely: ‘What AI does is give context… so that makes the scam [and] makes the threats credible.’

I think the key insight here is structural. This is not a more sophisticated phishing campaign in the traditional sense. The message itself may be entirely generic. What AI travel photo scams add is a personalisation layer, derived not from hacking your account but from scanning your public feed, that bypasses the instinctive scepticism most people have learned to apply to unsolicited messages.

What You Can Do Before You Post

The practical advice is straightforward, if inconvenient for anyone who enjoys the real-time social dimension of travel. Post your holiday photographs after you return home, not during the trip. Restrict your audience to people you know. And treat any message that references your recent location as a reason for heightened suspicion, not as confirmation that the sender is legitimate.

The standard rules still apply: never click a link in an unsolicited text or email. Contact your bank directly using the number on the back of your card or the address on its official website. Action Fraud, the UK’s national fraud reporting service, and the National Cyber Security Centre both maintain guidance on identifying and reporting this category of scam.

McAfee has also developed a product it calls McAfee’s Scam Detector, designed to identify highly targeted scam messages before users act on them. That a major cybersecurity company felt the need to build a dedicated tool for this threat is itself a reasonable measure of how industrialised the problem has become.

The broader point is this: the public posts most people treat as innocuous, a river shot, a restaurant terrace, a row of tulips, are now inputs into automated fraud pipelines. Location metadata has long been a known risk. What this research demonstrates is that the image itself, even without a tag or a caption, carries enough information to do the same job. The summer travel season is the peak window for exactly this kind of opportunism. Post accordingly.

Shares: