Skip to main content
  1. Home
  2. Emerging Tech
  3. News

Your holiday photos could help scammers figure out exactly where you are

AI can extract surprisingly precise location clues from innocent-looking Instagram and Facebook posts, making phishing scams much more convincing.

Add as a preferred source on Google
Photo on a holiday during sunset
Roberto Nickson / Unsplash

That innocent holiday snap might be doing more than showing everyone how good the weather is. A new scam highlighted by The Guardian shows how criminals can use AI to analyse photos posted on Instagram and Facebook, work out where they were taken, and then use that information to make phishing messages look frighteningly legitimate.

The trick is surprisingly simple. Imagine posting a few family photos from Porto without mentioning the city anywhere. A few days later, a text arrives claiming that your bank detected unusual card activity while you were travelling in Porto and asking you to verify your details through a link. Because the message contains a detail that only someone who knows about the trip should know, it suddenly feels much more convincing. Except the scammer may never have known about the trip at all. The photo told them.

AI doesn’t need your location tag

Research from McAfee tested more than 21,000 travel images using two freely available AI models. One correctly identified the location in 91% of cases, while the other reached 87%. Crucially, the images didn’t need location tags or embedded metadata for the AI to work out where they were taken.

The obvious giveaways are things such as famous landmarks, street signs, storefronts, road markings and recognisable skylines. But AI can apparently dig much deeper than that. McAfee found that even seemingly generic images could reveal useful clues. A beach or hotel room might only give away the country, but that could still be enough information for a scammer to make a message sound credible.

Recommended Videos

In one test, ChatGPT correctly identified a seemingly ordinary river scene as Hastings-on-Hudson in New York. Another image showing flowers was traced to the Keukenhof gardens in the Netherlands, based partly on the arrangement and combination of flowers in the image.

The scam gets convincing very quickly

Once scammers know where someone has been, they can use that context to make phishing messages far more convincing, whether it’s a fake bank alert about card activity, a suspicious login from the country visited, or even a hotel asking for verification. As McAfee’s head of EMEA, Vonny Gamot, told The Guardian, AI can provide the extra context that makes otherwise generic scams feel much more credible.

The simplest precaution is also the most annoying: consider waiting until the trip is over before posting holiday photos publicly, or at least limit them to friends and family. And if a message claims that a bank account or card has been compromised, don’t click its link, no matter how convincing it looks. Contact the bank directly through its official app, website, or the number on the back of the card instead.

The unsettling part is that scammers don’t need a photo with a famous landmark or location tag anymore. A seemingly ordinary picture can contain enough visual clues for AI to work out where it was taken, turning a harmless holiday snap into useful intelligence. Your photos may be memories to you, but to a scammer with the right AI tools, they can be a surprisingly detailed map of where you’ve been.

Varun Mirchandani
Varun is an experienced technology journalist and editor with over eight years in consumer tech media. His work spans…
The best tech of IFA 2026: a repairable laptop, liquid-cooled power bank, AI toothbrush, and more
From an AI toothbrush to a liquid-cooled battery, this is the best tech of IFA 2026
Best Of IFA 2026

IFA Berlin brought innovation from across the globe into one giant exhibition, and we got the chance to experience the new-gen "tech" firsthand. Walking through Messe Berlin, we saw a laptop designed to be repaired at home to a power bank with visible liquid coolant, an AI-powered toothbrush with a camera inside your mouth, and a robot vacuum carrying another.

The variety is what makes IFA one of the best tech shows. IFA 2026 runs from September 4 through 8, and we've spent our time in Berlin chasing down the products that caught our eyes. Some of these are clever ideas that may change how we use tech every day, while others solve a problem that I didn't realize existed.

Read more
OpenAI admits it needs to rethink what happens when AI goes rogue
As increasingly capable AI agents move beyond controlled tests, OpenAI is confronting a difficult question: When does strange model behavior become an incident the public deserves to know about?
OpenAI logo on blurred background

OpenAI has spent plenty of time explaining how it plans to stop increasingly capable AI agents from doing things they shouldn't. Now, the company says it needs to get better at telling everyone when those things have already happened. The admission follows reports of another previously undisclosed incident involving OpenAI's AI agents, this time affecting a German-language programming wiki. According to Reuters, agents made more than 15,000 unauthorized edits to DseWiki, using the site to communicate and share ways to bypass restrictions, cheat on tasks, and avoid detection.

OpenAI has now acknowledged what it calls the "wiki incident" and says the episode exposed a larger problem with how AI companies disclose unexpected model behavior. The company says it is developing a framework for deciding when and how to make incidents involving misaligned AI public.

Read more
AI has a safety problem nobody is ready for
AI safety efforts are ramping up, but their protections don’t work equally well everywhere. In developing countries, language gaps and cultural blind spots can turn everyday AI mistakes into serious real-world consequences.
Logo, Hockey, Ice Hockey

AI companies are spending an enormous amount of time worrying about what happens when their models become too capable. OpenAI even took the unusual step of temporarily pausing training on a model last month over safety concerns, as the industry grapples with risks ranging from autonomous behavior to increasingly sophisticated cyber capabilities.

But there’s another AI safety problem that is much easier to overlook: the protections already being built into these systems don’t necessarily work equally well for everyone. A new report from Rest of World highlights how AI safety efforts remain heavily centered around the needs of wealthier, English-speaking countries. That can leave people in parts of Asia, Africa, and other developing regions dealing with problems as basic and potentially dangerous as a chatbot misunderstanding their language.

Read more