As the holiday travel season peaks, a new cybersecurity report highlights a significant rise in scams targeting the travel sector. Cybercriminals are increasingly exploiting airline loyalty accounts and hotel customer data through phishing and data breaches, which are then sold on dark web forums for profit.
Major airlines such as American Airlines, Southwest Airlines, Emirates, United Airlines, Alaska Airlines, and Delta Airlines are prominent in dark web discussions about airline cybercrime, representing over half of the dark web conversations. Hotels like Marriott, which accounts for 35% of dark web hotel mentions, along with Accor, Hilton, and IHG, are similarly targeted for data theft.
Cybercriminals leverage stolen information like passport details, email addresses, and loyalty points to carry out fraudulent activities, including booking free flights and transferring miles. Expert analysis indicates that the high value of sensitive data—like passport numbers—fuels increased attacks, as such information commands higher prices on illegal markets.
"The travel industry is a lucrative target for hackers due to the sensitive personal and financial data they handle. Our research shows that airlines continue to face data breaches, and this stolen information has a thriving market on the dark web,"said Marijus Briedis, CTO of NordVPN.
Travelers are urged to strengthen account security, regularly update passwords, activate multi-factor authentication, and consider using travel eSIMs to prevent cyber theft during busy periods.
Vykintas Maknickas, CEO of Saily, stresses increased vigilance: "Check your accounts before and after travel. Using a travel eSIM helps reduce exposure on untrusted networks."
These findings demonstrate the critical need for cybersecurity awareness and proactive safety measures to safeguard personal data within the travel industry amid evolving cyber threats.

