Cybercriminals Never Take a Vacation
Prague, June 29, 2026
Summer holidays are increasingly planned and paid for online. People book accommodation, purchase motorway vignettes, pay for parking via QR codes, connect to public Wi-Fi networks, and often handle work emails while abroad. According to experts from axelum, the combination of rushing, unfamiliar surroundings, and reduced vigilance significantly increases the risk of cyber fraud.
Growing interest from cybercriminals in the travel sector is also reflected in data from Check Point Research. In May 2026, the travel, hospitality, and leisure sector faced an average of 2,291 cyberattacks per organization per week, representing a 24% year-over-year increase. Since May 2023, the volume of attacks targeting the travel sector has more than doubled.
This trend also increases the risk for travelers themselves. In May alone, more than 47,000 new travel-related domains were registered, according to the same research. One in every 112 domains was classified as malicious or suspicious at the time of analysis. Fake websites, unverified payment links, and fraudulent copies of well-known services are therefore among the most significant cyber risks of the summer travel season. “When traveling, people often do things they would think twice about at home. They quickly click a link in an email, pay a deposit through an unverified website, connect to public Wi-Fi, or open a work document in a hotel lobby. Cybercriminals count on this behavior. The greatest risk is not a specific technology, but rather the combination of haste, fatigue, and trust in communications that appear legitimate at first glance,” says Filip Štolle, Managing Director at axelum.
Growing interest from cybercriminals in the travel sector is also reflected in data from Check Point Research. In May 2026, the travel, hospitality, and leisure sector faced an average of 2,291 cyberattacks per organization per week, representing a 24% year-over-year increase. Since May 2023, the volume of attacks targeting the travel sector has more than doubled.
This trend also increases the risk for travelers themselves. In May alone, more than 47,000 new travel-related domains were registered, according to the same research. One in every 112 domains was classified as malicious or suspicious at the time of analysis. Fake websites, unverified payment links, and fraudulent copies of well-known services are therefore among the most significant cyber risks of the summer travel season. “When traveling, people often do things they would think twice about at home. They quickly click a link in an email, pay a deposit through an unverified website, connect to public Wi-Fi, or open a work document in a hotel lobby. Cybercriminals count on this behavior. The greatest risk is not a specific technology, but rather the combination of haste, fatigue, and trust in communications that appear legitimate at first glance,” says Filip Štolle, Managing Director at axelum.
A summer holiday can therefore be disrupted by compromised accounts, misuse of payment information, or the leakage of sensitive data. Experts from axelum highlight ten situations in which travelers commonly expose themselves to cyber risks.
1. Be Cautious with QR Codes at Parking Lots, Airports, and Restaurants
Travelers frequently use QR codes to pay for parking, access restaurant menus, or download maps. However, cybercriminals can replace legitimate QR codes with fraudulent ones that redirect users to fake websites. Before entering any information, always verify the web address to which the QR code directs you.
2. Verify Unusual Phone Calls and Voice Messages
While on holiday, people often respond to messages and phone calls more quickly than usual. Scammers may exploit this by impersonating family members, banks, or public institutions. Thanks to AI, fraudulent texts, voice messages, and phone calls can appear highly convincing. If someone asks for money or sensitive information, verify the request through another communication channel, such as calling a trusted number directly.
3. Do Not Enter Sensitive Information into Public AI Tools
Before or during a holiday, people often look for ways to complete work tasks as quickly as possible. Public AI tools can be useful for summarization or translation, but company documents, contracts, personal data, and business information should never be uploaded to them. If an organization allows the use of AI, employees should receive clear guidance on which tools are approved and what types of information may be processed.
4. Enable Multi-Factor Authentication
Multi-factor authentication (MFA) provides a simple but highly effective additional layer of protection. Even if a cybercriminal obtains your password, they cannot access your account without the second verification step. This is particularly important for email accounts, online banking, travel platforms, social media accounts, and corporate systems.
5. Purchase Motorway Vignettes and Book Services Only Through Official Websites
When planning a holiday, people often pay online for accommodation, motorway vignettes, event tickets, parking, or car rentals. These services are frequently imitated by fraudulent websites designed to steal payment information or charge hidden fees. Before making a payment, always verify the website address and be cautious if someone asks you to pay outside the official platform or pressures you to complete the payment quickly.
6. Protect Your Work Laptop and Phone While Traveling
Many people take work devices with them on holiday. However, work laptops and smartphones often contain sensitive corporate information and provide access to email accounts, internal systems, and cloud services. Devices should never be left unattended in cars, hotel lobbies, or on the beach. Essential security measures include screen locking, strong passwords or biometric authentication, and caution when working in public spaces where others may be able to view your screen.
7. Be Careful When Using Public Wi-Fi Networks
Free Wi-Fi in hotels, cafés, or airports may be convenient, but it poses unnecessary risks when handling sensitive activities. Travelers should avoid accessing online banking, corporate systems, or accounts containing personal or business data through public networks. Mobile data, a personal hotspot, or a VPN are much safer alternatives. If public Wi-Fi must be used, avoid making payments, entering passwords, or working with sensitive documents.
8. Enable Device Tracking and Remote Data Wipe Features
Modern smartphones and laptops contain large amounts of personal and business information. Before traveling, make sure that device tracking and remote wipe capabilities are enabled. In the event of loss or theft, these features can significantly reduce the risk of unauthorized access to photos, messages, stored passwords, emails, and work files.
9. Do Not Forward Work Documents to Personal Accounts
Work documents do not belong in personal email accounts or private cloud storage, even if it seems like a quick solution while traveling. Doing so places corporate data outside the organization’s controlled environment. When remote work is necessary, employees should use only approved company tools and procedures.