Articles /Trends & Hacks / Photography

How Scammers Can Use AI and Your Vacation Photos to Rip You Off

AI can pinpoint the location of a vacation pic posted to social media with more than 90% accuracy. Scammers can use that against you—unless you follow these tips.

  Published: Sep 08, 2026

  Updated: Sep 08, 2026

Vacation Selfie

Every time there's an advance in technology, you can bet scammers will find new and exciting ways to rip you off.

The latest tool to be wielded by these diligent criminals is of course artificial intelligence.

AI can be deployed in a variety of nefarious ways to defraud travelers, from the creation of ever more convincing websites for fake deals to the fabrication of evidence for nonexistent damage to a vacation rental.

Recent research from the cybersecurity pros at McAfee Labs has unearthed yet another reason for concern.

In tests of publicly available AI models, McAfee found that AI tools can accurately detect the location where a photo was taken 91% of the time.

What's more, the technology can make these remarkably accurate guesses by relying solely on visual clues in the photo—"the background, the architecture, the signage, the light." No GPS data or location tags needed.

And the AI models tested don't require "special access, proprietary data, or advanced technical expertise to run," according to McAfee. They're publicly available and free to use via ChatGPT, Claude, and Copilot.

The photos don't have to contain tons of recognizable landmarks, either.

In an example cited by McAfee, ChatGPT was easily able to identify a pic of Hastings-on-Hudson, New York, that shows merely a wooded ridge and some water.

Why is AI's capacity to pinpoint the location of vacation pics a problem for travelers?

Because if you post your vacation photos publicly, such as on social media, scammers can use their knowledge of your location against you.

“Location adds context, and context builds trust,” Steve Grobman, McAfee's chief technology officer, told Forbes. “Instead of casting a wide net with generic phishing messages, scammers can create one that’s tailored to your trip and timed to arrive when you’re most likely to believe it.”

So, for example, if you're at a resort in Playa del Carmen, Mexico, and post a beach selfie on Instagram, a scammer could run that publicly shared image through a freely available AI vision model and discover where you are.

Then the fraudster might send you a message like this one, which Grobman invented for Forbes:

"Welcome to Playa del Carmen! We hope you're enjoying your stay. We noticed an issue with the payment method on file for your hotel. Please verify your details here to avoid any interruptions to your stay: [link]."

And because you are, after all, in Playa del Carmen when you receive the message, you might be more likely to fall for the scheme and share your personal data.

McAfee's report lists further examples of deceptive messages you might receive after AI-assisted con artists deduce your current or recent vacation spot:

  • “We detected unusual account activity while you were traveling in [city].”
  • “Your card was flagged for a transaction in [country] — please verify immediately.”
  • “Hi, we’re reaching out regarding your recent stay at a hotel in [destination].”
  • “Hi, it’s [your name], I’m in Mexico and all my cards are being declined. Could you send me $$?” (a message targeting your friends or loved ones)
  • “We noticed a login attempt from your location in [destination] — please confirm your identity.”
  • “Your reservation in [city] requires reconfirmation — click here to secure your booking.”

An unsolicited email or text message like any of those becomes far more credible when the destination cited is a place where you currently are or have recently returned from. And you make that information publicly available when you share your vacation pics on social media.

Not to mention the fact that when you post a vacation pic, it's obvious to every burglar in the entire world that you aren't in your home.

So does this mean you should no longer post vacation pics?

McAfee's security experts don't go as far as to say that, but you should be more careful than ever before when it comes to sharing your out-of-town location on social media. Here's what the experts recommend.

Don't post until you get back home. Putting your vacation pics on social media while you're actually in the location "gives scammers a live signal," McAfee warns. Instead, wait to upload images until you're back home. Even better, wait a few days after your return.

As you can see from the sample scam messages above, though, the bad guys could still target you after your trip is over. So there are some other steps to take.

Limit who can see your posts. Obviously, publicly shared content is the most vulnerable. Check your privacy settings and, if possible, share stuff only with people you know rather than strangers.

If an urgent message refers to your location, be more skeptical, not less. Because scammers mention location precisely to reassure you, you should treat a message tied to where you are (or have recently been) as a "red flag, not a credibility signal," McAfee advises.

Don't click links in unsolicited texts or emails. When you get messages claiming to be from your bank, airline, hotel, or credit card provider, no matter how convincing they may look, ignore the links included. Instead, go to the company's official mobile app or open a new browser tab and go directly to the company’s official website. For credit card assistance, call the number on the back of your card and never call a number that has been sent to you.

Consider creating a separate email address for travel-related transactions. If you use a different email address for stuff like bookings and reservations, you can limit the "cross-referencing scammers can do between your social media presence and your financial accounts," McAfee advises.