AI Geolocation Tools Let Scammers Turn Vacation Photos Into Fraud
Criminals are using freely available AI models to identify travel locations from social media images, then crafting convincing phishing attacks.

Fraudsters have found a new way to make their scams more convincing: using artificial intelligence to determine where you've been on vacation based on photos you post online, then leveraging that information to craft targeted phishing attacks.
Research conducted by McAfee demonstrates how readily available AI models can pinpoint travel locations with alarming accuracy. The cybersecurity company tested more than 21,000 travel images using two free AI tools, finding that one identified locations correctly 91% of the time while the other achieved 87% accuracy.
The implications are immediate and practical for criminals. A scammer who knows you recently visited Porto, Portugal can send a text message claiming your card showed "unusual activity while you were travelling in Porto" and asking you to verify your account immediately. Because the message references your actual location—information you may not have explicitly shared—it carries false legitimacy that makes victims more likely to click malicious links and surrender financial details.
How AI identifies locations
The technology works by analyzing visual elements within images that humans might consider unremarkable. Architecture styles, signage, street markings, storefronts, and even lighting conditions all provide clues. According to The Guardian, which first reported these findings, McAfee staff tested the capability on their own photos and found the results unsettling.
In one example, ChatGPT correctly identified a picture of a river with trees as Hastings-on-Hudson in New York state. Another image showing flowers was pinpointed as the Keukenhof gardens in the Netherlands based on the specific layout of tulips with smaller blue flowers between them.
Even images without obvious landmarks—beach scenes or hotel room photos—can often be identified at the country level, which provides sufficient information for scammers to craft plausible messages.
Why it matters
This development represents a significant evolution in social engineering attacks. Phishing attempts have traditionally relied on generic messages sent to thousands of potential victims. AI-powered geolocation gives criminals the ability to add personalized details that dramatically increase credibility without requiring manual research. As Vonny Gamot, head of EMEA at McAfee, explained to The Guardian: "What AI does is give context … so that makes the scam [and] makes the threats credible."
The technology requires no special access—the AI models used in McAfee's research are freely available, and the photos are already public on social media platforms.
Protective measures
Security experts recommend delaying social media posts until after returning home from trips. Users should also adjust privacy settings to ensure only known contacts can view their images.
More broadly, the same anti-phishing practices apply: be suspicious of messages creating artificial urgency, never click links in unsolicited texts or emails, and contact banks or companies directly using verified contact information rather than details provided in suspicious messages.
These findings were first reported by The Guardian.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call