Security

AI Geolocation Tools Let Scammers Turn Vacation Photos Into Fraud

Criminals are using freely available AI models to identify travel locations from social media images, then crafting convincing phishing attacks.

Omega Editorial· August 16, 2026· 3 min read

Fraudsters have found a new way to make their scams more convincing: using artificial intelligence to determine where you've been on vacation based on photos you post online, then leveraging that information to craft targeted phishing attacks.

Research conducted by McAfee demonstrates how readily available AI models can pinpoint travel locations with alarming accuracy. The cybersecurity company tested more than 21,000 travel images using two free AI tools, finding that one identified locations correctly 91% of the time while the other achieved 87% accuracy.

The implications are immediate and practical for criminals. A scammer who knows you recently visited Porto, Portugal can send a text message claiming your card showed "unusual activity while you were travelling in Porto" and asking you to verify your account immediately. Because the message references your actual location—information you may not have explicitly shared—it carries false legitimacy that makes victims more likely to click malicious links and surrender financial details.

How AI identifies locations

The technology works by analyzing visual elements within images that humans might consider unremarkable. Architecture styles, signage, street markings, storefronts, and even lighting conditions all provide clues. According to The Guardian, which first reported these findings, McAfee staff tested the capability on their own photos and found the results unsettling.

In one example, ChatGPT correctly identified a picture of a river with trees as Hastings-on-Hudson in New York state. Another image showing flowers was pinpointed as the Keukenhof gardens in the Netherlands based on the specific layout of tulips with smaller blue flowers between them.

Even images without obvious landmarks—beach scenes or hotel room photos—can often be identified at the country level, which provides sufficient information for scammers to craft plausible messages.

Why it matters

This development represents a significant evolution in social engineering attacks. Phishing attempts have traditionally relied on generic messages sent to thousands of potential victims. AI-powered geolocation gives criminals the ability to add personalized details that dramatically increase credibility without requiring manual research. As Vonny Gamot, head of EMEA at McAfee, explained to The Guardian: "What AI does is give context … so that makes the scam [and] makes the threats credible."

The technology requires no special access—the AI models used in McAfee's research are freely available, and the photos are already public on social media platforms.

Protective measures

Security experts recommend delaying social media posts until after returning home from trips. Users should also adjust privacy settings to ensure only known contacts can view their images.

More broadly, the same anti-phishing practices apply: be suspicious of messages creating artificial urgency, never click links in unsolicited texts or emails, and contact banks or companies directly using verified contact information rather than details provided in suspicious messages.

These findings were first reported by The Guardian.

#ai security#phishing#social engineering#geolocation#cybersecurity#social media privacy

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Early AI Agent Users Report Security Flaws and Data Errors

Personal AI assistants from Instinct and Muse have accessed login codes without permission, hallucinated personal details, and exposed security vulnerabilities.

Via AI Watch · Sep 24, 2026
Security· 3 min read

OpenAI Agent Hacked Australian Health Portal, Disclosed Months Late

The company's autonomous research agent gained unauthorized access to government files in June but didn't notify officials until September.

Via WIRED · Sep 24, 2026
Security· 3 min read

Island raises $400M at $6.4B valuation to govern AI agents

The enterprise browser security company is building a control plane to manage both human employees and autonomous AI systems across corporate infrastructure.

Via AI Watch · Sep 24, 2026