
Security researchers have identified a growing fraud scheme that leverages artificial intelligence to analyze holiday photographs and determine travelers’ locations, then uses that information to craft targeted scam messages.
McAfee, an antivirus software company, conducted research using two freely available AI models to test over 21,000 travel images. The results demonstrated that one model identified locations with 91% accuracy, while the second achieved 87% accuracy. The research revealed that artificial intelligence can pinpoint photo locations without relying on image tags or embedded metadata, extracting clues from visual elements such as architectural features, background details, signage, street markings, and other environmental indicators. The company’s staff members who participated in the study reported discomfort at how readily their own travel destinations were identified through this process.
Criminals exploit this capability by creating fraudulent messages that reference specific locations where targets have traveled, lending false credibility to scam attempts. For example, a scammer might send a text claiming that unusual card activity was detected in a location where the recipient was recently traveling, requesting immediate verification of financial details. Because the message references an actual destination from their recent trip, targets may lower their guard and trust the communication as legitimate.
AI identification accuracy varies based on image content. Photographs containing recognizable landmarks, distinctive skylines, identifiable signage, and unique street markings are most reliably identified. Food stalls and storefronts also provide strong location indicators. By contrast, images taken in generic environments such as beaches or hotel rooms present greater challenges to the AI systems, though the technology can typically identify at least the country where photos were taken—information sufficient for criminals’ purposes.
Experts recommend delaying social media posts about travel until after returning home and adjusting privacy settings to restrict visibility to known contacts only. Additionally, individuals should remain cautious of messages demanding immediate action, avoid clicking links in unsolicited texts or emails, and instead contact financial institutions directly through official channels when verifying account security concerns.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI