Current fraud landscape

Travel runs on trust, and fraudsters are testing it harder than ever.

Riskified analysts monitoring dark web channels are tracking a sharp rise in travel fraud activity and interest. AI-enabled fraudsters have found new ways into an industry that’s both valuable and exposed. For travel brands, that activity translates directly into lost revenue, disrupted operations, and damaged reputations.

Growth explains part of the surge. Travel and tourism was the world’s fastest-growing sector in 2025, outpacing the global economy by a wide margin. U.S. travel spending has held steady despite economic headwinds. Forecasts put total spending at $1.37 trillion in 2026 and $1.42 trillion in 2027. Riskified’s 2026 global Summer Travel Survey found that 69 percent of consumers expect to spend more on travel this summer.

Loyalty programs (a favorite fraud target) are also growing rapidly. Industry research estimates that 60% of active travelers belong to two or more loyalty programs, and major airlines reported record enrollment and loyalty revenue growth in 2025. Points and miles have become a currency in their own right, and fraudsters are already spending them.

Key challenges

To conduct this industry analysis, Riskified’s research team examined transaction data from airlines, online travel agencies (OTAs), hotels, and land transportation. Their analysis revealed a number of distinct challenges facing this market.

  • Global expansion: Adding new routes, destinations, and accommodation markets drives growth by attracting new travelers. It also introduces localized purchasing behaviors, payment preferences, and fraud patterns that require more adaptive risk strategies.
  • Loyalty program risk: Loyalty programs are a powerful tool for increasing customer lifetime value, but points-based currency also attracts fraudsters. Stolen rewards can be quickly monetized, and customers often discover account compromise before airlines do, eroding trust.
  • Low authorization rates: The travel industry’s elevated fraud risk often leads to stricter payment decisions, increasing false declines that reduce revenue and negatively impact customer experience.
  • Thin margins: High operating costs, volatile fuel prices, intense competition, and demand fluctuations make it essential for travel companies to maximize conversion while controlling fraud losses.

Riskified’s research team has identified increases and received reports of two primary fraud vectors impacting travel merchants:

Fraudulent OTA services

Fraudulent OTAs are illegitimate booking services operated by organized fraud networks. They advertise heavily discounted travel across social media, messaging apps, and other online channels. These deals are funded through stolen payment cards, compromised loyalty accounts, stolen gift cards, or other illicit methods, and in some cases, travelers believe they have found an exclusive bargain. In other cases, they knowingly purchase from a fraudulent OTA to access prices well below market value. Either way, the fraudster profits while the travel merchant is left with chargebacks, lost revenue, lost loyalty, or other financial losses.

Two fraudulent OTA models Riskified analysts are tracking are buy-for-you (B4U) services and triangular fraud.

  • Buy-for-You (B4U) services operate as a fraud-for-hire model: the customer knowingly pays a fraudster to book their trip, and the fraudster uses stolen payment credentials, compromised loyalty points, or fraudulently obtained gift cards to complete the booking. The traveler often receives a valid reservation and travels at a significant discount, while the merchant absorbs the financial loss. Criminals, meanwhile, can see margins as high as 1000%.
  • Triangular fraud occurs when a fraudster advertises travel through an OTA, a third-party platform, or a fake website, often at a discounted price, to lure real consumers. The scammer collects the payment at the advertised price, and then fulfills the booking by purchasing it from the legitimate travel provider using stolen payment credentials or another fraudulent funding source. The unsuspecting customer is sent what appears to be a valid reservation. In many cases, the chargeback lands before the travel date: the real cardholder disputes the charge, the legitimate provider cancels the booking, and only then does the customer discover that the trip is gone and their payment details have been compromised. By that point, the scammer is long gone with the cash, and unlike B4U-style booking services, has no stake in whether the trip ultimately goes through. The merchant bears the resulting chargebacks and fraud losses.

Loyalty points are criminal currency

With liquid monetary value, travel loyalty points are an attractive currency for fraudsters. Airline loyalty programs alone are estimated to generate more than $25 billion in annual revenue, making them attractive targets for theft and fraud. Using stolen credentials, bots, and phishing tactics, fraudsters can take over accounts, transfer miles to their own accounts, sell them for cash, redeem rewards, or use them for personal travel and B4U schemes. Because customers often discover the theft before airlines do, this type of fraud also poses a reputational risk to merchants.

Attackers refine tactics for specific travel businesses

Dark web activity shows that fraudsters are studying individual OTAs and developing platform-specific playbooks. Criminal communities hone and exchange methods tailored to specific merchants and their vulnerabilities, such as tested BINs and payment methods, step-by-step booking techniques, checkout-specific intelligence, refund-abuse tactics, and account-exploitation tutorials.

This section examines specific risks Riskified sees within segments of travel transactions and how fraudsters exploit high-value markets.

Flight bookings

Based on Riskified’s analysis of travel transaction data through the first five months of 2026, airline ticket transactions are becoming riskier.

  • May 2026 saw the largest YoY increase in risk, with fraud levels rising 32% compared to May 2025.
  • Fraud activity peaked during high-demand travel periods in 2025, with July seeing the highest concentration of attacks, followed by elevated fraud volume in October and November.
  • Flights departing in July and December were among the most targeted, as fraudsters sought to blend into the high volume of summer and holiday travel activity and take advantage of the peak flight demand.
  • Fraud rings focus on specific routes and regions, then shift locations once exposed.
Riskiest flight routes of 2025
Departure country
Arrival country
Risk-level from average
Source: Riskified
  • Last-minute bookings are high-stakes, especially in First Class. Throughout 2025, last-minute airline bookings were 2.3× riskier than other bookings, with July accounting for the highest share of both legitimate and fraudulent last-minute purchases. While these bookings represent significant fraud risk, there’s also a higher risk of false declines, which can damage customer loyalty.
  • Business and First Class travelers spend nearly 4× more per transaction on average and expect a fast, reliable booking experience, which makes false declines particularly costly. But fraud is also more costly in First Class. Although premium seats account for less than 2% of airlines’ annual ticket volume, they generate outsized profitability, strengthen retention among high-value travelers, and play a vital role in an airline's status.

Flight schemes gaining altitude

  • From planes to trains: Fraudsters adapt when flight attacks fail, shifting to train ticket purchases and changing payment methods from credit cards to Apple Pay. Recent examples of these attacks include newly created accounts, repeated use of German BINs, and generic German domains.
  • Post-purchase manipulation: Fraudsters increasingly buy flights months in advance and use order details they believe will help them bypass fraud reviews. Then they contact the provider or OTA to change travel dates, passenger names, or routes.
  • Long-haul DTO: Criminals are taking a long-term approach by compromising devices and identities, then spreading high-value travel booking attacks over weeks or months to avoid detection. After gaining access via malware, remote access tools, SIM swapping, phishing, or other social engineering tactics, they take over a device but may remain dormant between transactions, making fraudulent activity appear more like legitimate customer behavior. 
  • Burying the mismatch: Billing, passenger name, and IP location matches were once considered signals of low risk. But fraudsters are increasingly using compromised accounts to make bookings appear legitimate by listing the victim among the passengers to match the billing and passenger names. Some schemes also involve a post-purchase passenger name change. The risk of transactions with a name match has increased significantly in 2025. In November 2025, the risk was 30% higher than at the beginning of the year.
  • Gift cards fly under the radar: The supply of stolen travel gift cards issued directly by airlines, hotels, and OTAs on underground secondary markets is virtually endless, providing a reliable way for fraudsters to place orders or conduct B4U with near-anonymous payment and fewer protections. Travel-branded gift cards bypass the card network entirely, so there's no chargeback to force a cancellation, giving these bookings a far better chance of holding up undetected all the way to departure.

Hotel bookings

  • Sophisticated fraud is now a year-round threat: Hospitality is a seasonal business, but there are no longer any “safer” months when it comes to these threats. Organized fraudsters now launch attacks whenever they have the tools and data ready to exploit, and AI tools equip them to execute large-scale attacks quickly.
  • Time-to-check-in is no longer a reliable signal: Hotel bookings break the pattern seen in flights: legitimate and fraudulent bookings show almost the same gap between purchase and check-in, 12 days for legitimate bookings and 15 for fraudulent ones, on average. This makes accurate risk decisions at checkout crucial to avoid unnecessary friction for legitimate guests. 
  • Luxury hotels are a prime target: Five-star hotels ranked as the riskiest segment in 2025 (2.6× riskier than other hotel categories). High-end properties attract more fraud in part because premium experiences create opportunities for dark web sellers to market steeply discounted, highly profitable luxury stays. Luxury hotels also prioritize customer experience, making them more vulnerable to social engineering tactics that are widely shared on the dark web.

    While 5-star hotels are the riskiest, the 4-star segment can be a bigger profit drain. Four-star hotels are riskier by +20% compared to other categories and comprise the highest share of potential fraud costs.
  • Fraud rings target by destination: Our analysts have found that fraud MOs and rings often focus on specific product regions (e.g., hotel locations).
Riskiest hotel locations of 2025
Source: Riskified

A new way fraud is checking in: Host account abuse

Fraudsters are increasingly exploiting host accounts through insider access, which flows in both directions. Dark web activity shows fraudsters recruiting OTA employees directly, not just hotel staff, and in other cases, hotel owners seeking out scammers to collude with and split the proceeds. However the access is gained, attackers can view guest communications and reservation details, use the hotel's legitimate profile to phish guests directly by citing their own order and personal details to earn trust, and process stolen payment cards through seemingly valid bookings. The result is a fraudulent operation that leverages the OTA’s own infrastructure while leaving the platform vulnerable to chargebacks, financial losses, and reputational damage.

The next frontier: agentic checkout fraud

Agentic commerce is arriving fast: McKinsey projects it could drive $5 trillion in global retail revenue by 2030, and 48% of consumers say an AI search result has already influenced a purchase. But the shift removes the signals fraud models rely on most. When OpenAI's Instant Checkout in ChatGPT went live, Riskified's own testing found 34 percent of the data used to make fraud decisions was missing from those transactions, and orders that should have been declined got approved. The stakes are rising fast: Visa's PERC found dark web mentions of "AI agent" grew 450% in six months, and 69% of merchants report facing AI-enabled fraud in the past year, per Deloitte.

"Security against fraud is not an afterthought. It should be first principles," said Assaf Feldman, Riskified's co-founder and Chief Strategy Officer - Technology. Merchants that build risk into agentic checkout from day one, rather than waiting to see how the protocols shake out, will be the ones who capture this growth safely.

Proven strategies

Automate chargebacks

Applying automation to some or all of the travel booking chargeback management process increases efficiency more effectively than any other action. Automation can be applied in a tiered strategy, with lower-value or more straightforward chargebacks automated, while more complex, sensitive, and higher-value cases are handled by agents. Automation also frees teams to focus on more strategic and challenging disputes that might have previously gone uncontested.

Follow the full journey

A typical consumer’s summer holiday or business trip can involve multiple vendors across multiple borders, and travel merchants need visibility into data across the entire journey to properly assess risk. Context is essential, from pre-planned, advance bookings of flight and train tickets to more ‘suspicious’ last-minute purchases.

Why is this important? Because the complexity of the travel industry can be deceptive, making good travelers look suspicious. For example, consider the travel opportunity created by the World Cup, which brought millions of fans and dollars to North America. Those travelers booked complex purchase journeys that span the entire travel ecosystem—from international flights and hotels to transportation, dining, entertainment, and match-day experiences. A single fan may book expensive trips, travel between multiple cities, make last-minute changes, and use different devices, locations, and payment methods along the way.

To traditional fraud systems, this behavior can resemble account takeover, stolen payment activity, or synthetic identity fraud. In reality, it may simply reflect the behavior of a passionate traveler following their team. While these patterns create challenges for merchants, they also highlight the need to distinguish legitimate event-driven travel behavior from true fraud.

In a scenario like this, Riskified's network can provide that context across a fan's full journey - from pre-planned, advanced bookings of flight and train tickets to changing IP locations to the more ‘suspicious’ last-minute purchases or itinerary changes.

Spotlight Mexico: Payment friction eases for ground transport

Ground transportation is digitizing fast. A Reserhub study of Mexico's digital bus-ticket market found that payment acceptance climbed from 88% to 96% between H1 2025 and H1 2026, while failed payments declined by 26%. But friction moved, not disappeared: operator-to-departure conversion fell from 41% to 34%. Apple Pay reached 4% of sales within weeks, and match-day demand during World Cup matches rose 40% — the same fast adoption and event-driven surge that is fueling fraud exposure across other travel bookings.

Optimize approvals with identity-based solutions

Travel merchants can counter low bank authorization rates by maximizing approvals. Leverage intelligent automation and machine learning to accurately address risk and calibrate friction order-by-order and within the context of the whole journey to maximize profitability and customer satisfaction. Use detailed market intelligence or a network to link orders and more easily distinguish between trustworthy travelers and abusive bad actors.

Riskified’s dynamic technology examines patterns at a network-wide scale. By using machine learning to gauge which checkout pathway is right for each booking’s risk level — whether to authorize, decline, or judiciously deploy additional verification where it’s absolutely necessary — travel merchants can more precisely filter out bad orders and maximize good bookings.

Partner with Riskified

Riskified's travel network includes more than 60 travel merchants and has processed $828 billion in cumulative travel transactions as of June 2026. Travel merchants trust Riskified to manage the high level of fraud risk in their industry without jeopardizing their business growth.

Speak with an expert

About this Risk Rundown

Across industries, Riskified captures and analyzes data related to orders processed through our vast merchant network. Findings are combined with exclusive research and intelligence from online fraud forums to provide merchants with the most relevant category-specific insights available.

Lev Gal

Senior Data Analyst, Data Insights team