TL;DR
Fraudsters are using widely available AI models to work out where holiday photos were taken, then citing that location in scam messages to make them believable. McAfee ran more than 21,000 travel images through two free models: one placed 91% correctly, the other 87%. No geotag or metadata is required — the image alone is enough.
How the con works
The message arrives days after the photos go up. Unusual activity was detected on your card during your time in Porto, it says, so please verify. Because you never posted where you were going — only some indistinct pictures with a sliver of river behind the family — the specificity reads as proof the message is genuine. It is not, and the link harvests your banking details.
What the model works from is mundane: architecture, street signage, the quality of the light, road markings, a food stall or a shopfront. Vonny Gamot, who heads EMEA at McAfee, frames the shift as AI supplying context, and context is what makes the threat credible.
Two examples from the testing show how little is needed. A river with trees in the foreground was correctly placed at Hastings-on-Hudson in New York state. A floral close-up came back as Keukenhof, the Dutch tulip gardens, the model reasoning from how the tulips were laid out and the smaller blue blooms set between them. McAfee’s own staff, repeating the exercise on their own pictures, were unsettled by how readily their movements were traced.
Beach and hotel-room shots defeat precise identification, but the model can usually still name the country. For a scam text, the country is enough.
Why the usual advice falls short
Guidance on holiday photos has for years centred on stripping geotags and locking down metadata. That advice is now largely beside the point — the model does not read the file, it reads the picture. The one control that still works is timing: post after returning home, and restrict visibility to people you actually know.
Looking forward
For UK businesses, the read-across is to social engineering against staff. The same technique applied to a team photo on a company page, or a conference picture on a personal account, gives an attacker the specific, checkable detail that makes a pretext hold. The defences remain the dull ones — treat urgency as a warning sign, and reach the bank or supplier through the number on the card or the website, never the link you were sent.