The Wire
TechnologyArtificial IntelligenceCybersecurityWorld

AI can turn holiday photos into targeted phishing bait

AI can turn holiday photos into targeted phishing bait
Photo: theguardian.com

The Guardian says scammers are scraping holiday photos to make phishing messages sound credible.

Why it matters: The tactic turns ordinary social sharing into attack surface. It also shows how AI can make bank-impersonation scams more personalized, harder to spot and easier to scale.

  • The Guardian reports fraudsters can use vacation photos on Instagram or Facebook to infer where someone has been.
  • McAfee-backed research says one AI model correctly identified the location in 91% of travel-photo tests.
  • McAfee says it tested 21,236 publicly available travel photos plus 102 controlled images, without GPS metadata or location tags.
  • U.S. and U.K. cyber guidance both warn that public social media details can help scammers craft convincing phishing messages.

Fraudsters are using vacation photos posted online to make phishing emails and texts feel more convincing, according to The Guardian.

The scam works by scraping ordinary travel images from social platforms such as Instagram and Facebook, then using AI to infer where someone has been. That context can be folded into messages that look timely and specific, such as a fake bank alert tied to a recent trip.

McAfee says its research found AI models could geolocate travel photos with high accuracy. In one test, Qwen3 VL 30B correctly identified the city and country in 91% of images, while Gemma3 27B hit 87%. McAfee says it tested 21,236 publicly available travel photos and an additional controlled set of 102 images, using free AI image models and no GPS metadata or location tags. McAfee's report says visual cues like landmarks, signage, architecture, storefronts and street markings can give away a photo's country or city.

"What AI does is give context ... so that makes the scam [and] makes the threats credible," said Vonny Gamot, head of EMEA at McAfee.

Public guidance backs up the warning. The U.S. State Department says people should not share personal details online because scammers can exploit them. The U.K. National Cyber Security Centre says publicly available social media information can make phishing messages look convincing and urges users to review privacy settings and think carefully about what they post.

By the numbers

  • 91% - McAfee says Qwen3 VL 30B correctly identified the city and country in its travel-photo test set.
  • 87% - McAfee says Gemma3 27B correctly identified the city and country in its travel-photo test set.
  • 21,236 - publicly available travel images used in McAfee's testing.

Yes, but: McAfee's figures are striking, but the dossier does not include an independent technical replication of the exact results.

Based on reporting from

  • The Guardian

See how this story touches your network - open The Wire in Jane.

Open in Jane