Travel Phishing Up 122 Percent: BSI Issues Summer Alert

Natalie Hoffmann··6 min read
Traveler checking a booking confirmation on a smartphone at an airport

Just as Europe heads into peak vacation season, Germany's Federal Office for Information Security (BSI) has issued a formal warning about fake booking confirmations and travel phishing - and the numbers behind the warning are stark. Check Point Research measured a 122 percent increase in cyber attacks on the travel and hospitality sector over the past three years, with tens of thousands of new travel-themed domains appearing every month. For employers, this is not just a consumer story: the phone that receives the fake hotel confirmation is very often the same phone that holds corporate email and the company MFA app.

What the BSI Is Warning About

In its 19 June 2026 press release 'Sicher reisen, digital geschuetzt bleiben' (travel safely, stay digitally protected), the BSI highlights the risks that cluster around vacation travel:

  • Fake booking confirmations and phishing that imitate airlines, hotels, and booking platforms - timed to arrive when travelers are expecting exactly such messages.
  • Public Wi-Fi and USB charging risks in airports, hotels, and cafes, where untrusted networks and charging points can expose devices and traffic.
  • Weak account protection: the BSI urges enabling two-factor authentication on travel and payment accounts before departure.
  • Oversharing as reconnaissance: out-of-office notes, vacation photos, and live location shares tell attackers exactly who is away, for how long, and often who is covering for them - raw material for social engineering.

That last point is the one security teams should sit with. The BSI is explicitly framing vacation behavior - including workplace artifacts like out-of-office replies - as input to social engineering attacks.

The Numbers Behind the Surge

Check Point Research put hard figures on the trend in a 15 June 2026 analysis. Travel and hospitality organizations faced 1,032 weekly attacks per organization in May 2023; by May 2026 that had risen to 2,291 - the 122 percent three-year surge. Year over year, May 2026 attacks on the sector grew 24 percent, against a global average of just 2 percent across all industries. Attackers are not merely following the seasonal money; they are disproportionately concentrating on it.

The infrastructure buildout is just as telling. In May 2026 alone, 47,318 new travel-related domains were registered - up 33 percent from April - and roughly 1 in every 112 of them was malicious or suspicious. Each of those domains is a potential landing page for a fake confirmation, a bogus payment request, or a cloned login form.

The Lures: Fake Bookings That Look Real

Check Point's researchers documented the lures in detail, and they are built for plausibility rather than volume:

  • More than 210 sequentially registered hotel-lure domains, industrializing the production of fake hotel booking pages.
  • Booking.com lookalikes such as booking-cn.com, booking-jp.com, and bookingni.com, each targeting travelers in a specific region.
  • Copycats of other major brands, including airbnb-ca.com and skyscanners.shop.
  • The travel agency Fora Travel impersonated across 108 different domain extensions - the same trusted name replicated across nearly every TLD an unwary victim might accept.

The psychology is straightforward. A traveler who booked a hotel last week is primed to open anything that says 'your reservation'. A message claiming a payment failed or a booking needs re-confirmation lands with built-in urgency, and on a phone screen the lookalike domain is one squint away from the real thing.

Why Vacation Phishing Is a Workplace Problem

It is tempting for IT teams to file travel scams under private life. Three realities argue otherwise:

  • The device is shared. Under BYOD arrangements, the personal phone that receives the fake booking confirmation also holds corporate mailboxes, chat apps, and - critically - the authenticator app protecting company accounts. A compromised personal device is a corporate incident waiting for working hours.
  • The credentials are recycled. A password harvested by a fake booking portal has a fair chance of matching a work account somewhere.
  • The absence itself is intelligence. As the BSI notes, out-of-office replies and public vacation posts feed social engineering. An attacker who knows the finance lead is hiking in the Alps until the 24th knows exactly whose name to spoof and which deputy to pressure with an urgent payment request.

Summer phishing does not respect the boundary between private and professional - it exploits it.

What This Means for Your Organization

A short, well-timed intervention before the vacation wave beats any amount of after-the-fact cleanup:

  • Send a pre-vacation security briefing. A concise note covering fake booking confirmations, lookalike domains, public Wi-Fi caution, and 2FA on travel and payment accounts - essentially the BSI checklist, translated into your house style.
  • Teach the golden rule for bookings: never act on a confirmation or payment link in a message. Open the booking app or type the known site address directly and check there.
  • Tighten out-of-office hygiene. Keep OOO replies minimal - no travel dates framed as an empty-house advert, no full org charts of deputies to external senders. Consider internal-only detail and a generic external reply.
  • Revisit BYOD guardrails before the season: mobile OS updates enforced, work profiles separated, and a clear path for employees to report a compromised personal device without fear of blame.
  • Make the season part of your training calendar. A summer-themed phishing simulation - a fake booking confirmation or refund notice - is one of the most realistic tests you can run, because it mirrors precisely what employees will see in their inboxes. Platforms like empowsec let you schedule such seasonal campaigns and follow up automatically with short training for whoever clicks.

Attackers plan around the calendar. The BSI advisory and Check Point's numbers are a reminder that defenders should too - ideally a few weeks before the out-of-office replies switch on.

Key Takeaways

  • The BSI formally warns of fake booking confirmations, public Wi-Fi and USB charging risks, and urges 2FA on travel and payment accounts - and flags OOO notes and vacation posts as social engineering fuel.
  • Travel sector attacks are up 122 percent in three years: 2,291 weekly attacks per organization in May 2026, growing 24 percent year over year versus 2 percent globally.
  • 47,318 new travel domains appeared in May 2026 alone; about 1 in 112 was malicious or suspicious, with lookalikes of Booking.com, Airbnb, Skyscanner, and Fora Travel.
  • Vacation phishing reaches corporate data through BYOD devices, recycled passwords, and OOO-based reconnaissance - treat it as a workplace risk, not a private one.
  • Act before the season: brief travelers, minimize out-of-office detail, and run a summer-themed phishing simulation to build the verify-first reflex.
Share: