A family posts a few holiday snapshots on Instagram or Facebook, showing them relaxing beside a river with no landmark clearly visible. Days later, a text arrives claiming their bank card was compromised while they were travelling, naming the exact city they had just visited. The Guardian described this scenario from a trip to Porto, Portugal, where a message read: "We detected unusual activity while you were travelling in Porto, please verify immediately."

The detail is what makes the message convincing. The traveller had not tagged their location or written the city's name anywhere online, yet the text named it precisely. According to the Guardian, fraudsters are now using artificial intelligence to analyse background details in shared photos, extracting location clues that most people would assume were impossible to trace.

How AI reads the background of a holiday snapshot

Research from the cybersecurity firm McAfee Labs helps explain how this works. Testing freely available AI vision models, the company found they could identify where a photo was taken with up to 91 per cent accuracy using visual clues such as signage, architecture, local surroundings, landmarks and food. One model, Gemma3 27B, correctly identified the city and country of a travel photo 87% of the time, while a newer model reached 91% accuracy on the same set of images, according to the report cited by the tech blog KnowBe4.

"Knowing where someone is or where they've recently been is one of the oldest tricks in a scammer's playbook." — McAfee Labs researchers

Once a scammer knows a target's recent travel destination, building a plausible fraud message becomes far easier. McAfee's head for the Asia-Pacific region, Tyler McGee, has warned that criminals only need photos shared publicly on social media to construct phishing messages impersonating a bank, claiming a card was used fraudulently abroad, in the very country the victim had just visited. The specificity is designed to override the scepticism most people now bring to generic scam texts.

An old fraud tactic with a new layer of credibility

The underlying fraud is a well-established one known as smishing, a form of phishing carried out by text message. Action Fraud, the UK's national reporting centre for fraud and cybercrime, notes that smishing scams often exploit familiar brands and urgent demands, with attackers impersonating trusted organisations to lower a victim's guard and push for rapid responses. Bank account alert messages are among the most common variants, typically claiming an account has been compromised and directing recipients to click a link or call a number.

HSBC UK describes the same pattern in its own customer guidance, explaining that text message scams, known as smishing, occur when a fraudster sends a text that appears to be from a bank or another trusted organisation, with the goal of extracting personal or financial details. What AI adds is not a new type of scam, but a more convincing disguise for an old one, making a generic template feel personally targeted.

What travellers can do

Security researchers and consumer banks broadly agree on the same defences. Reviewing privacy settings so holiday photos are visible only to approved followers reduces the pool of images scammers can scan. Turning off automatic geotagging on phones removes one obvious clue, though as McAfee's research shows, AI can still infer location from background details alone.

The more reliable safeguard sits on the banking side. No genuine bank alert should require a customer to click a link in a text message to "verify" their account; legitimate concerns are raised through a bank's official app or by calling the number printed on a card. Reporting suspected UK smishing texts by forwarding them to 7726, a free service run with mobile networks, helps providers block similar messages at scale. Readers elsewhere in Europe can typically report suspicious texts to their national telecoms regulator or directly to their bank's fraud team, several of which, including major EU and UK institutions, publish dedicated phishing report addresses on their websites.

As AI image analysis becomes cheaper and more accurate, the line between a harmless holiday post and exploitable personal data is thinning. The practical advice has not changed much, treat unsolicited urgent bank messages with suspicion, verify independently, and never share banking details through a link. What has changed is how much a photograph alone can now give away.

This article is free to read. It always will be — no paywall, no account, no tracking.