As travellers increasingly rely on digital platforms to book flights, accommodation and transport, cybercriminals are exploiting the urgency and trust built into the modern travel journey.
Travel planning has become increasingly digital. Flights are booked through airline websites and apps, accommodation is reserved online, payments are made electronically and travellers often manage their entire journey from a smartphone.
That convenience also creates opportunities for cybercriminals.
According to research shared by Kaspersky, its security solutions recorded 262,663 detections associated with major transport brands between Q2 2025 and Q1 2026. The activity involved cyberthreats distributed under the guise of well-known airlines, ride-hailing services and other transport companies.
Emirates accounted for 61% of the detections associated with the transport brands analysed by Kaspersky, while Uber represented 37%. Trojans were the most common threat type among files and objects associated with transport brands, accounting for 30.5% of detections, followed by Trojan-Bankers at 22.5%.
The findings illustrate a broader problem: criminals do not necessarily need to compromise a genuine airline or booking platform. Instead, they can exploit the reputation of a trusted brand to persuade travellers to disclose credentials, payment information or other sensitive data.
Why travel is an attractive target
Travel creates a particularly effective environment for social engineering.
People often make bookings under time pressure, compare prices across multiple websites and respond quickly to messages about reservations, flight changes or special offers. A message claiming that a booking has been cancelled or that a traveller is entitled to compensation can therefore appear credible at precisely the moment when the recipient is most likely to click.
Kaspersky researchers identified, for example, a phishing scheme impersonating Ryanair in which victims were told they were eligible for flight compensation. They were then directed towards a process requiring account information or a small payment.
Image credit: Kaspersky
The apparent urgency was part of the deception.
A similar scheme identified by researchers impersonated Booking.com. Victims were directed to a fraudulent booking page designed to resemble a legitimate checkout process and were asked to provide personal and payment information. The supposed reservation did not exist.

Image credit: Kaspersky
These techniques are not limited to one airline, booking service or country. They exploit a common weakness across the travel ecosystem: trust combined with urgency.
Africa faces a wider cybercrime challenge
For African travellers and tourism businesses, the issue needs to be viewed against a broader increase in cyber-enabled crime across the continent.
INTERPOL’s 2025 Africa Cyberthreat Assessment Report found that two-thirds of surveyed African member countries reported that cyber-related offences represented a medium-to-high share of all crime. In Western and Eastern Africa, cybercrime accounted for more than 30% of reported crime, according to the assessment. Online scams, phishing, ransomware and business email compromise were among the most frequently reported threats.
The report also highlights the growing use of social engineering, artificial intelligence and instant messaging platforms by criminal networks. This is particularly relevant to travel because many interactions between travellers and service providers now take place through digital channels.
Africa’s cybersecurity capacity is also developing, although significant differences remain between countries.
The International Telecommunication Union’s Global Cybersecurity Index 2024 reported that Africa’s average cybersecurity score increased to 57, a 22-point improvement compared with the previous edition. The index assesses countries across legal, technical, organisational, capacity-development and cooperation measures.
The ITU assessment also places several African countries among its highest-performing cybersecurity group, including Ghana, Kenya, Mauritius, Rwanda and Tanzania, while other countries remain at earlier stages of cybersecurity development. This variation matters for businesses operating across borders because digital risks and national capabilities are not uniform across the continent.
The risk extends beyond travellers
The implications are not limited to individual tourists.
Travel companies hold valuable information including customer names, contact details, booking histories, payment information and communications. Airlines, hotels, online travel agencies, tour operators and transport companies are therefore attractive targets for criminals seeking either direct financial gain or access to customer accounts.
For businesses, a fraudulent booking page can also damage something that is difficult to rebuild: customer trust.
INTERPOL has repeatedly stressed the importance of cross-border cooperation because cybercrime does not stop at national borders. In an Africa-wide operation in 2025, authorities in 18 African countries and the UK arrested 1,209 suspected cybercriminals, identified nearly 88,000 victims and dismantled more than 11,000 malicious infrastructures.
The scale of such operations demonstrates why cybersecurity should increasingly be treated as part of business resilience rather than solely as an IT function.
What travellers should do
The most effective protection often starts with simple decisions.
Book through official websites and applications. Travellers should avoid accessing booking or payment pages through unsolicited links in emails, text messages or social media posts. Instead, they should open the official website or app independently.
Check the web address carefully. Fraudulent websites can imitate legitimate travel platforms, sometimes with only small differences in the domain name or page design.
Treat urgent offers with caution. Messages demanding immediate payment, threatening cancellation or promising unusually large compensation should be independently verified.
Use unique passwords and multi-factor authentication. Travel accounts can contain personal information and payment details, making them valuable targets.
Download applications only from trusted sources. Users should check the publisher, reviews and requested permissions before installing an unfamiliar travel application.
Monitor payment accounts after making bookings. Unrecognised transactions should be reported to the relevant financial institution as soon as possible.
Be careful with QR codes. A QR code can direct a traveller to a malicious website just as easily as a conventional link. The destination should be checked before credentials or payment information are entered.
What tourism businesses should do
Businesses can reduce the risk by making secure digital practices part of the customer experience.
Travel companies should clearly communicate their official payment channels and domains, provide customers with a reliable way to verify booking messages and train employees to recognise phishing and impersonation attempts.
They should also protect customer accounts with strong authentication, monitor unusual activity and maintain clear procedures for responding to fraudulent bookings or compromised accounts.
For businesses operating across African markets, cybersecurity awareness is particularly important because travellers may move between countries with different digital infrastructures, regulatory environments and levels of cybersecurity maturity.
The objective should not simply be to prevent every fraudulent message from reaching a customer. It should also be to make it difficult for a customer to mistake a fraudulent communication for a legitimate one.
Digital trust is becoming part of the travel experience
The growth of online travel has made journeys easier to plan, but it has also moved more of the traveller’s relationship with airlines, hotels, transport providers and tour operators into the digital environment.
Kaspersky’s travel research shows how criminals are exploiting familiar brands and the pressure surrounding bookings and payments. INTERPOL’s assessment demonstrates that phishing and online scams are already among Africa’s most significant cyberthreats.
For African tourism businesses, the lesson is broader than simply warning customers about phishing.
As travel becomes more digital, cybersecurity is increasingly part of customer service, business continuity and brand reputation. Protecting travellers’ information and helping them recognise legitimate communications can therefore become an important part of maintaining trust in Africa’s growing digital travel economy.
Sources
Kaspersky — Safe Travel Insights: Kaspersky research cited in this article covers cyberthreat detections associated with transport and travel-service brands from Q2 2025 to Q1 2026.
INTERPOL — 2025 Africa Cyberthreat Assessment
INTERPOL — New report warns of sharp rise in cybercrime in Africa
ITU — Global Cybersecurity Index 2024
ITU — Measuring Digital Development: Africa 2025
Crédito: Link de origem