Holiday scams and how to beat them

School’s out for the summer and the heatwave has hit! As we start to think about holidaying, many of us will turn to online travel agents (OTA) to book that last-minute deal. As OTAs have grown in popularity, so too has the opportunity for scammers to target a new breed of online consumers. We should all be aware of the wave of digital scams that will accompany this trend.

In 2018, more than 5,000 tourists fell victim to holiday scams, resulting in average losses of £1,380 and a total of £7 million, according to Action Fraud. And of course, it’s not just down to financial strain. The emotional distress travelers experience at the hands of fraudsters can be equally damaging. 

From fake plane tickets to accommodation spoofs, online holiday booking has become both incredibly convenient and risky at the same time as fraudsters become increasingly more sophisticated.

Let’s take a look at a few of the biggest scams and how to avoid them:

1. Watch out for fake websites

It won’t surprise you that over half of reported online holidays scams were down to fake airline ticket sales. ABTA’s 2018 report noted that 53% of tourists were lured into booking a flight on a fake website for a nonexistent flight.

If you stumble across a website that offers you too-good-to-be-true flights, there’s probably a reason, so do your due diligence and learn to spot these fake sites. They may be previously unknown domains such as ‘www.theflightdealofyourlife.com’ – an OTA you probably haven’t heard of before so check whether it uses ‘https’ which offers more validity than ‘http’, or if it’s a more popular OTA such as Expedia, use your search engine if you’re not sure whether ‘www.expediaholidays.org’ is the real site. 

To avoid booking accommodation via a fake site, consider calling the owner or agent directly, and asking for the full address of the property to cross-reference with Google Maps.

Research, research, and research again – the key to online research lies in both the quality and quantity of the reviews. Look for the quality of images on the sites, and check if the companies are members of professional associations such as ABTA or ATOL. 

2. Beware the airport WiFi

With free WiFi pretty much a modern essential, it’s easy for tourists to connect when travelling whether it’s at the airport, hotel or local cafe. But, tourists need to look out for those unsecured networks that allow you to connect without a login and with no stated user terms. The problem with these networks is that your personal and private data can be easily exposed and thus, sharing bank details, financial information or any other sensitive data over these networks is incredibly risky.

If you really need to connect to unsecured wifi networks, make sure you keep your browsing to very dull searches – don’t check work email, don’t bank online, don’t purchase anything using your credit card details! If you’re travelling and need to work, speak to your IT teams about VPNs and logging into corporate networks securely. 

3. Double-check those deals

Let’s be honest, we all love a deal! However, as fraudsters increasingly look for new ways to con tourists out of money, we need to be extra cautious of those unsolicited emails that all too often seem perfectly legitimate but that may in fact harbor fake scams.

Phishing emails are in abundance, especially in the financial services, retail and travel sectors, so be aware that hackers can easily impersonate a brand’s primary domain. You may click on a link in an email that says you’re visiting “www.trailfinders.com” assuming it’s a legitimate site, but that domain may well have been hijacked and then used to harvest your data. As a user, there’s not much you can do about this apart from to avoid clicking these links.

Check the site’s authenticity and use trusted websites rather than clicking on links that take you through to competitions and last-minute deals or that redirect you to a new website altogether. 

We all work hard year-round and our holidays are there to enjoy stress-free with family and friends. But with so much fraud clouding our every day, it’s often hard to make that a reality. Yet, with a few simple steps, you can ensure you’re on your way to out-scamming the scammers before they’ve had a chance to make your holiday a washout.

If you work within the travel industry and want to ensure you’re protecting your customers from email scams being carried out in your name, then get in touch with the Red Sift team or check your DMARC status online, for free.

Check email DMARC setup

PUBLISHED BY

Red Sift

31 Jul. 2019

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
News

Introducing DNS Guardian: Stop impersonation and spam caused by domain takeovers 

Rahul Powar

tl;dr: We’re thrilled to announce DNS Guardian — a new feature in Red Sift OnDMARC that can swiftly identify and stop domain takeovers that lead to malicious mail. Back in February, we shared updates with the community about SubdoMailing – an attack discovered by Guardio Labs. The attack was a form of subdomain takeover,…

Read more
Email

“What’s Next for DMARC”: Red Sift & Inbox Monster Webinar Recap

Red Sift

The recent webinar hosted by Inbox Monster, “What’s Next for DMARC: Data & Predictions for a New Era in Email Authentication,” featured insights from Red Sift and examined the significant changes brought by Yahoo and Google’s bulk sender requirements earlier this year.  It also offered a forward-looking perspective on the future of email authentication.…

Read more
Security

Navigating the Information Security Landscape: ISO 27001 vs. SOC 2

Red Sift

As cyber threats evolve, so do the standards and frameworks designed to combat them. Two of the most recognized standards in information security are ISO 27001 and SOC 2. What sets them apart, and which one is right for your organization? Let’s delve into the key differences. Purpose and Scope: Global Framework vs. Client-Centric…

Read more
News

G2 Summer 2024 Report: Red Sift OnDMARC’s Winning Streak Continues

Francesca Rünger-Field

We’re delighted to announce that Red Sift OnDMARC has again been named a Leader in G2’s DMARC category for Summer 2024. This recognition is based on our high Customer Satisfaction scores and strong market presence. Red Sift appeared in 11 reports – 5 new ones since Spring 2024! – earning 5 badges: A few…

Read more
News

Google will no longer trust Entrust certificates from October 2024

Red Sift

Tl;dr: Google has announced that as of October 31, 2024, Chrome will no longer trust certificates signed by Entrust root certificates. While there is no immediate impact on existing certificates or those issued before 31st October 2024, organizations should start reviewing their estate now. On Thursday 27th June 2024, Google announced that it had…

Read more