Your holiday photos can now fund a scam against you
Fraudsters are using AI to turn Instagram and Facebook posts into eerily personalised phishing messages. Here is how the trick works and what to watch for.

Key points
- Scammers use publicly visible holiday photos on Instagram and Facebook to craft targeted text and email scams.
- AI tools can read location clues from a photo, including landmarks, signage and river backgrounds, without needing GPS data embedded in the image.
- The scam message mimics your bank and names the exact city you visited, making it feel legitimate.
- Anyone who posts travel photos publicly is a potential target, regardless of how ordinary or vague the image seems.
You post a photo from Porto. The Douro river is just a sliver in the background. You think nothing of it.
A few days later, a text arrives. "We detected unusual activity while you were travelling in Porto," it reads. "Please verify your card immediately."
It feels real because it knows where you were.
How does the scam actually work?
The message did not come from your bank. It came from a fraudster who read your Instagram or Facebook post, used AI image-recognition tools to confirm your location, and then wrote a phishing message, a fake alert designed to trick you into handing over your account details, timed to your trip.
This is not guesswork on the scammer's part. Modern AI can identify cities, landmarks and even specific neighbourhoods from background details most people would never notice. A bridge arch, a tram line, a particular style of tiled building: all of it is readable by the same kind of technology used in Google Lens or Apple's photo search.
Once the location is confirmed, generating a convincing bank alert takes seconds. Large language models, the technology behind chatbots like ChatGPT, can produce fluent, bank-branded text that matches the tone and layout of genuine fraud warnings.
The Guardian first reported on this pattern of geo-targeted fraud emerging from social media posts.
Why does knowing your location make the scam so dangerous?
Most people already ignore generic "unusual activity" texts. But add one real, personal detail and the brain's alarm system quiets down.
You were in Porto. The message says Porto. That coincidence feels like proof.
From there, the scammer needs only one thing: for you to tap the link and enter your card number, sort code or online banking password. The link leads to a fake bank page built to look identical to the real one.
What should you watch for?
Four things signal this kind of attack:
- The message names a specific place you recently visited and creates urgency around it.
- It asks you to click a link rather than log in through your bank's official app.
- The sender's number or email address does not match your bank's official contact.
- The request is for card details, passwords or one-time codes, information your real bank will never ask for over text.
If a message like this lands while you are travelling, go directly to your bank's official app or call the number on the back of your card. Do not tap anything in the message itself.
The simplest prevention is setting Instagram and Facebook posts to friends-only before you travel, or waiting until you are home to share photos publicly. A delay of 48 hours removes almost all of the scammer's timing advantage.



