‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos
Fraudsters are using AI to analyze holiday photos posted on social media, accurately pinpointing locations to craft highly convincing phishing scams that trick individuals into revealing bank details.
Intelligence analysis by Gemini 2.5 Flash

A new scam leverages readily available AI tools to identify the precise location where holiday photos were taken, even from seemingly indistinct backgrounds. This information allows criminals to send personalized text messages or emails, such as alerts about 'unusual activity' in the specific travel destination, making their fraudulent requests for financial details appear legitimate …
Imagine you post a picture of your family on holiday, maybe with a cool building in the background. Naughty grown-ups can use clever computer programs, like super-smart detectives, to look at that picture and figure out exactly where you were, even if you didn't say! Then, they might send you a fake message pretending to be your bank, saying there was a problem while you were in that exact place. Because they know where you were, it feels real, and they hope you'll click a bad link and give them your money details.
Analysis
McAfee
McAfee, a prominent anti-virus software producer, conducted crucial research demonstrating the alarming ease with which AI can pinpoint photo locations. Their study utilized two freely available AI models, testing over 21,000 travel images. The findings revealed that these models could accurately identify locations with high precision, often without the need for geotags or metadata, simply by analyzing visual cues within the picture itself. This research underscores a significant vulnerability for individuals sharing holiday photos online.
The company's head of EMEA, Vonny Gamot, emphasized that AI provides critical "context" that makes these scams and threats highly credible. The internal experiment, where McAfee staff replicated the test with their own pictures, reportedly caused discomfort due to how easily their travel destinations were identified. This highlights the personal and pervasive nature of this new form of digital exploitation, moving beyond generic phishing attempts to highly targeted social engineering.
91%
One of the AI models tested by McAfee achieved an impressive 91% accuracy rate in identifying the location where images were taken, while the other managed 87%. This high success rate is attributed to the AI's ability to discern subtle details such as background architecture, signage, street markings, and even the quality of light. Recognizable landmarks, skylines, food stalls, and storefronts significantly increase the accuracy of location identification.
Even in less distinct settings, like beaches or hotel rooms, the AI could often identify the country, which is sufficient for scammers to lend credibility to their fraudulent messages. The article cites examples where ChatGPT correctly identified Hastings-on-Hudson from a river scene and the Keukenhof gardens from a picture of tulips, showcasing the advanced capabilities of these tools. This precision allows criminals to craft messages that are eerily specific, making them far more convincing than traditional, generic scam attempts.
Porto
The article illustrates the scam's execution with a compelling scenario: a person posts indistinct holiday photos from Porto on social media. Days later, they receive a text message claiming, "We detected unusual activity while you were travelling in Porto – please verify immediately." The victim, unaware that AI has pinpointed their location from their photos, clicks a fraudulent link, believing the message to be legitimate due to its specific reference to their recent travel.
This personalized approach is what makes the AI-powered scam so effective. Instead of a generic warning, the message includes a detail that only someone with knowledge of the victim's recent activities would possess, thereby bypassing typical suspicions. The criminals can then use this information to request bank details, confirm identity after a supposed hotel stay, or flag unusual account login attempts from that specific country, all designed to extract sensitive financial information under false pretenses.
Key points
- AI tools can accurately identify photo locations from social media posts, even without geotags or metadata.
- Fraudsters use this AI-derived location data to create highly personalized and credible phishing scams.
- McAfee research showed AI models achieved over 90% accuracy in pinpointing locations from travel images.
- Scams often involve fake messages about 'unusual activity' in the specific location where a victim recently traveled.
- To avoid scams, delay posting holiday photos, use strict privacy settings, and never click links in suspicious messages; contact institutions directly.
Increased public awareness about these AI-powered scams, coupled with adherence to security best practices like delaying photo posts and adjusting privacy settings, can empower individuals to protect their financial information. Banks and social media platforms may also develop enhanced security measures to detect and prevent such sophisticated fraud.
The increasing sophistication of AI tools means fraudsters will likely continue to find new and more convincing ways to exploit personal data, potentially leading to a rise in financial losses for consumers. This could also erode trust in legitimate digital communications from banks and other service providers, making it harder for people to discern real alerts from scams.



