A hotel photo, tagged restaurant, and boarding pass on the table are sufficient for a stranger to determine where you are, how long you will be gone, who you are traveling with, and which bank you use. A few days later, the phone rings: the bank's security department has detected a suspicious transaction at your hotel in Rome. The hotel name matches, the city matches, the date matches. And that’s why it works.
What a Scammer Can Learn from a Vacation Photo
From a single post, one can usually determine the country and city of stay, the name of the hotel or restaurant, an approximate return date, accompanying persons, the airline, and – if a card or receipt is in the frame – the bank and type of payment card. Additionally, data from other older posts can be used: a phone number once provided in an ad, an email address, children's names, and the maiden name of the mother.
A location can be recognized not only by the location tag. A distinctive building, license plate, language on signs, view from the window, carrier logo, Wi-Fi network name, menu, receipt, or hotel wristband can also provide clues.
OSINT, Spear Phishing, and Pretexting
OSINT (Open Source Intelligence) is the collection of publicly available information: from social media, search engines, registries, old ads, and photos. Simply browsing public information is not a crime. The problem arises when it is used to impersonate someone, steal identity, or take over an account.
Spear phishing differs from regular phishing in that it is tailored to a specific person. A mass message speaks generally about a blocked account. Spear phishing knows your name, hotel, city, and travel date.
Pretexting is a scenario designed to prompt action: erroneous charges on a hotel card, a halted transaction, reservation verification, damage to a rental car, or a customs package.
A Boarding Pass Reveals More Than Just a Name
This is the most underrated element of vacation photos. Brian Krebs' analyses revealed a specific mechanism:
- The reservation code (PNR) and name – both visible on the front of the card – were sufficient to log into the airline's reservation website, view and edit passport details, citizenship, and date of birth, as well as cancel future flights.
- The barcode contains the full number in the loyalty program. The number along with the name allowed for a password reset by answering multiple-choice security questions.
- A search for the term "boarding pass" on Instagram returned over 91,000 photos, many with readable codes.
Blurring part of the number is not enough. The barcode and QR code remain readable even from a blurry photo.
Sources: What's in a Boarding Pass Barcode? A Lot and Why It's Still A Bad Idea to Post or Trash Your Airline Boarding Pass.
How Such an Attack Looks Step by Step
- The victim posts a photo from a hotel in Rome, tags the location, and includes a boarding pass and an envelope with the room number in the frame.
- The scammer reviews older posts: a phone number from an ad years ago, an email address, names of family members, and the bank visible on the card.
- The victim receives a message: "The security department detected an attempt to charge your card for 780 euros at the Roma Palace hotel. Please verify urgently." The hotel name is real.
- A request to click a link, log in, provide a code from an SMS, install an app "for secure handling," or transfer money to a "technical account."
The Number on the Phone Screen Proves Nothing
The Federal Communications Commission (FCC) describes spoofing as the deliberate falsification of information transmitted to the display. The key takeaway: the number alone cannot indicate whether the call is genuine, even if the number of your bank appears on the screen.
The FCC's recommendation is clear: hang up and call the number from your statement, the official website, or the back of your card. Not the one that called you.
Sources: FCC: Caller ID Spoofing, FTC: Scammers can fake caller ID info.
Never Give Your SMS Code to Anyone
The FTC states this without exceptions:
Never give your verification code to anyone. No caller – especially someone from your bank's fraud prevention department – will ever ask for your verification code. It is always a scam.
The code authorizes login, transfer, adding a device, changing a phone number, or adding a card to a digital wallet. Whoever receives it will perform that operation on your behalf.
Source: FTC: What's a verification code and why would someone ask me for it.
Technical Accounts and Secure Accounts Do Not Exist
The Polish police describe this scheme directly: a fake bank employee informs about alleged suspicious transfers and offers to "secure" savings. Methods include transferring to a specified account, BLIK codes, cash withdrawals, and deposits at ATMs or installing remote access apps.
Technical accounts, substitute accounts, and secure accounts do not exist. The police recommend hanging up, calling the hotline from the official website or card, and reporting the attempted fraud to 112.
The FTC has an alert titled that is worth remembering: Never move your money to "protect it." That's a scam.
Sources: KPP Pruszków, KPP Bełchatów, FTC: Got a call about fraud activity on your bank account.
Fake Booking Sites Look Identical to Real Ones
CERT Polska documented an attack impersonating Booking.com: personalized emails about an unpaid invoice for a non-existent reservation. The team points out a fact that invalidates most advice about "recognizing by appearance":
Modern phishing uses exact visual copies of known services, so recognizing fraud by the appearance of the site is impossible. The only reliable source of information is the address in the browser's address bar, and the answer lies in the domain name.
A padlock next to the address only indicates an encrypted connection. A fake site also uses HTTPS.
Sources: CERT Polska: Attack on Allegro.pl and Booking.com Customers, CERT Polska: How to Recognize Fake Websites, Warning List.
Vacation Photos and Break-Ins: What Is Documented and What Is Not
This thesis circulates on the internet in a stronger version than the data allows, so it is worth separating one from the other.
Documented cases: in 2015 in Orange County, California, an offender tracked at least 33 women using GPS data stored in the metadata of photos published on Facebook and Instagram; losses exceeded $250,000. In 2019, a group was arrested in London that tracked posts about trips and luxury items, robbing over 12 homes in four months.
What is unknown: the popular statistic stating that 78 percent of burglars monitor social media comes from a survey conducted on 50 former burglars and commissioned by the security industry. The sample is small and self-selecting. Police officers quoted in American materials admit they have heard of such cases but have not made arrests where the perpetrator confirmed this method.
A fair conclusion is: individual cases are confirmed, the scale of the phenomenon is not studied. This is still a sufficient reason not to publicly announce that your home will be empty for the next ten days.
How to Remove Location from a Photo on iPhone
Apple describes three different actions, and the most important is the first one, as it acts preventively.
Turning Off Location Saving for the Future
Settings, then Privacy and Security, then Location Services, then Camera, and set Never.
Removing Location from a Specific Photo
- Open the Photos app and select the photograph.
- Tap the info button or three dots.
- Select Adjust Location.
- Set No Location.
Sharing Without Location
In the Photos app, select the photos, tap Share, then Options and turn off Location.
The Places album shows all photos with saved locations. It is worth checking there to see the scale on your end.
Setting names may vary slightly between system versions. Source: Apple: Manage location metadata in Photos.
Social media usually processes uploaded files, but do not assume that metadata will always be removed. A photo sent via email, messenger, cloud, or public link may retain more information. Regardless of metadata, the location is often revealed by what is visible in the frame.
What to Check Before Posting a Photo
The most effective rule is one: post after returning. Memories do not lose value after a week’s delay, and live reporting directly informs that you are not home.
Before uploading a photo, zoom in on the entire frame and check if any documents, payment cards, boarding passes, receipts, reservation confirmations, QR codes or barcodes, room numbers, identifiers, or screens of other devices are visible. Also, check if you are not publishing images of other people's children.
Warning Signs in Messages and Calls
- Unexpected contact combined with time pressure.
- Threat of account blocking or funds being held.
- Request for a password, PIN, CVV, full card number, or SMS code.
- Login link sent in a message.
- Request to install an app or share your screen.
- Demand for a transfer to a "secure account," payment in cryptocurrency, or gift card.
- Urging not to discuss the matter with family or branch employees.
The last point is the most characteristic. Isolating the victim from people who could recognize the fraud is an element of the scenario, not a banking procedure.
Lack of language errors is no longer proof of authenticity. The FBI indicates that generative artificial intelligence removes typical signs of fraud, including grammatical errors, and allows for cloning the voice and image of loved ones.
Family Security Password
The FBI directly recommends, in a public warning regarding AI-related fraud:
Establish a secret word or phrase within the family for identity verification.
This same warning includes two recommendations that directly confirm the theme of this text: verify the identity of the caller by hanging up and dialing the institution's number yourself, and limit publicly available recordings of your voice and image, set social media accounts to private, and restrict followers to people you know.
The family password should not be a pet's name or anything that appears in posts.
Source: FBI IC3: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud.
What to Do After Receiving a Suspicious Message
- Do not click the link and do not respond – responding confirms that the number is active.
- Do not provide the SMS code, app code, BLIK code, password, PIN, or CVV.
- Hang up completely. Do not allow being switched to the so-called security department.
- Call yourself using the number from the back of the card, from the official app, or from your statement.
- Check the official app for recent transactions, device lists, transfer recipients, and cards added to digital wallets.
- Take screenshots, but do not prolong the conversation just to gather evidence.
What to Do If Data Has Already Been Provided
Act immediately, without waiting for unauthorized transactions to appear.
Login or password: go to the real site or app, change your password, log out of remaining sessions, enable multi-factor authentication, change the same password everywhere else, and check if the email address for account recovery has been altered.
Card data: immediately contact the bank, block the card, inquire about the complaint procedure, and monitor the account for the following weeks.
SMS code or approved operation: tell the bank exactly what you approved. The code may have authorized a transfer, adding a device, changing a phone number, or adding a card to the wallet.
Installed remote access app: disconnect the device from the internet, do not log into the bank on it, call the bank from another phone, delete the app, check accessibility and screen recording permissions, change passwords from another device, and consider restoring factory settings.
Sent money: immediately ask the bank to attempt to stop the transaction. There are no guarantees, but time is of the essence here.
Scammers Come Back a Second Time
People who have already lost money are attacked again. The FTC describes the mechanism: scammers buy victim lists, so-called "sucker lists," containing names, addresses, phone numbers, types of scams, and amounts lost. They then impersonate an agency, consumer organization, law firm, or even the original scammer offering a refund.
The rule without exceptions: no agency or legitimate organization asks for an upfront fee to help recover money.
Sources: FTC: Refund and Recovery Scams, FTC: What To Do if You Were Scammed.
PESEL Registration: What It Blocks and What It Doesn’t
If a scammer has obtained your PESEL number, a photo of your ID, or a broader set of data, it is worth registering the number. The service is free, available in the mObywatel app (works immediately) and at the municipal office (on the spot).
As of June 1, 2024, financial institutions will be required to check if a PESEL is registered when entering into contracts such as loans or credits.
The most common concern is unfounded. Registering does not block registration with a doctor, filling prescriptions, ATM withdrawals, transfers, traveling abroad, or administrative matters.
Source: gov.pl: Register Your PESEL Number.
Where to Report Fraud in Poland
First and foremost, contact your bank if financial data has been disclosed, a transfer has occurred, or an operation has been approved.
CERT Polska accepts reports through four channels:
- SMS to number 8080 – free, operational since November 22, 2023. It is best to use the command Forward or Share; if that is not possible, copy the content. Forward the entire message in its original form, do not cut the link. SMSs without links can also be reported. Outside Poland, costs are according to the operator's tariff.
- incydent.cert.pl – incident reporting form.
- incydent.cert.pl/phishing – a separate form for data phishing sites.
- mObywatel app – function for reporting suspicious messages.
Police: report if there has been a loss of money, identity theft, account takeover, or extortion. Bring screenshots, phone numbers, website addresses, transfer confirmations, and recipient account data. Emergency number: 112.
Social media platform: report fake profiles, hijacked accounts, and ads leading to fake sites. If your account has been hijacked, warn friends through another channel.
Sources: gov.pl: Report SMS or email to CERT Polska, CERT Polska: Fake SMSs.
Where to Report Fraud in the USA
- Bank or card issuer – first and foremost.
- ReportFraud.ftc.gov – Federal Trade Commission.
- IC3.gov – FBI Internet Crime Complaint Center, including phishing and spoofing.
- IdentityTheft.gov – identity theft.
- Local police.
Common Mistakes When Assessing the Credibility of Messages
"I have a private profile, so I am safe." Privacy helps, but a friend's account can be hijacked, a friend can forward a photo, and older posts may still be public.
"It knows my recent transactions, so it must be the bank." The location could have been determined from your posts, and the payment at that location could simply be guessed.
"The number matches the bank's number." The number on the display can be spoofed. Hang up and call yourself.
"The site has a padlock." A padlock only indicates an encrypted connection. Check the domain name, and preferably do not open the bank from a link.
"It knows my data, so it works at the bank." Data could have come from social media, a leak, an old ad, or a hijacked friend's account.
A Rule to Remember
A true detail in a message does not mean that the entire message is true. A scammer may know the name of your hotel because you published it yourself.
When someone unexpectedly contacts you about money, cards, reservations, or accounts: break contact, do not click the link, do not provide the code, do not install the app, and contact the institution yourself using a known number.
Sources
- FTC – verification code
- FTC – "move money to protect it" is a scam
- FTC – call about fraud on your account
- FTC – caller ID spoofing
- FTC – refund and recovery scams
- FTC – what to do after being scammed
- FTC – impersonating airline customer service
- FTC – travel website scams
- FCC – Caller ID Spoofing
- FBI IC3 – generative AI fraud
- gov.pl – register your PESEL number
- gov.pl – report SMS or email to CERT Polska
- CERT Polska – fake SMSs
- CERT Polska – attack on Booking.com customers
- CERT Polska – how to recognize fake websites
- CERT Polska – Warning List
- Police – bank employee fraud
- Apple – managing location in Photos
- Krebs on Security – what's in a boarding pass barcode
- Krebs on Security – boarding pass, continued
Comments (0)
No comments yet. Be the first!