Riskified’s most recent analysis of the travel fraud landscape underscores its evolution beyond stolen-card transactions. One threat that has emerged over the past few years is triangulation fraud, a scheme that can leave travelers with a legitimate-looking reservation while shifting the financial risk to the airline, hotel or other travel provider.

It’s just one of the topics Riskified experts explored during the latest Risk Rundown: Travel webinar.

How triangulation fraud works

The model is relatively simple:

  1. A fraudster advertises flights, hotels, or vacation packages through a fake website, a clone of an existing online travel agency (OTA)/travel brand, or a social-media offer — typically at a significant discount.
  2. An unsuspecting traveler pays for the deal, unaware they’re dealing with a fraudster, and the scammer keeps the proceeds (and sometimes the traveler’s payment details).
  3. The fraudster purchases the booking through a legitimate airline, hotel or booking platform using stolen value: often a stolen credit card from a different consumer, a compromised loyalty account, or other fraudulent funding source like a stolen gift card.
  4. The traveler receives a real reservation with a confirmation that may contain a legitimate booking number, the traveler’s real name, and a genuine reservation in the airline or hotel’s system. Sometimes they even travel before a chargeback is initiated, meaning the merchant absorbs the cost.

A Wall Street Journal investigation documented the emergence of dark web travel agencies that use this three-way model. The operators advertise on the open web, direct consumers to fake travel sites, collect their payments and then use stolen credit-card or loyalty credentials to book travel through legitimate reservation systems.

The consequences can extend beyond the travel provider. If the stolen payment method is eventually identified, the legitimate booking may be canceled before travel takes place. And the traveler can become another victim down the line, given that the fraudsters have collected their payment information.

Loyalty points can be triangular currency

As outlined above, triangulation fraud doesn’t always require a stolen credit card. Stolen airline loyalty accounts and miles can serve the same purpose.

A July 2026 analysis describes this type of triangulation fraud, in which miles are used as a stand-in for a stolen card. In this version of the scheme, a criminal takes over an airline loyalty account, converts the stolen miles into travel value with an intermediary and ultimately produces a legitimate ticket for another traveler. Again, the passenger may have a completely valid-looking reservation, even though the value used to purchase the ticket was stolen from someone else’s loyalty account.

For travel companies, this creates a particularly difficult challenge: by the time a stolen loyalty account is used to issue a ticket, the booking itself can look perfectly legit. The compromise may have happened much earlier when the criminal took over the account. As such, stopping this type of fraud is easiest upstream with stronger account security. 

Triangulation is just one trend taking shape

Learn more about triangulation fraud and other emerging threats targeting airlines, hotels and OTAs in Riskified’s latest Risk Rundown: Travel webinar.