Holidays are when we let our guard down. Scammers have known this for years.
There’s a statistic that should appear in travel agency brochures, right below the flight price: over 4.3 million Italians have been victims of a scam or fraud attempt when booking their holidays, with total financial damage exceeding 195 million euros, according to a survey by Facile.it conducted by the EMG institute. This isn’t your typical street vendor rip-off: it’s a seasonal criminal sector, as productive as the tourism industry it exploits.
The reason is simple and not at all mysterious: anyone booking a trip is already in a psychological state favorable to the scammer. They’re excited, in a hurry, want to close the deal before the price goes up, and above all, they’re about to leave their usual environment, where mental and digital checks are more relaxed. From the perspective of someone planning a scam, the tourist is the ideal target: motivated, distracted, and temporarily without a safety net.
The vacation rental that doesn’t exist
The most common type of scam remains the non-existent accommodation, which has affected more than 3.4 million Italians in the last 12 months. The mechanism is almost always the same: an attractive listing, a price that’s a bit too good, a request for an advance bank transfer to secure the date. The scam isn’t always discovered in time: 31% of victims manage to identify the deception before leaving, but over a million Italians only discover it after reaching their destination, with all the consequences that entails in terms of luggage in hand and nowhere to sleep. About 440,000 travelers found themselves in accommodation completely different from what was shown in the listing, while nearly 389,000 found the property already occupied by other guests, a sign that the same scam is often resold to multiple victims in parallel.
It works particularly well with cruises and packages that require a deposit and subsequent balance: the time between the two payments is exactly the window in which the scammer has time to disappear. No sophisticated technology needed, just social engineering applied to installment payment logistics.
The channels scammers prefer
Holiday booking portals, real or counterfeit, remain the most exploited channel: over 1.7 million vacationers have fallen into the trap through these tools. Next come scams spread through social networks, which account for 39.3% of cases, and those on real estate or general classified portals, at 23.2%. Even the good old sign posted on the street continues to claim victims, albeit on a smaller scale.
There’s also a detail that overturns a common prejudice: the elderly are not the most frequent target. According to the Postal Police, the most affected age group is 18 to 24 years old, while those over 65 represent only a small portion of victims, around 5% of the total. The explanation isn’t age-related naivety but habit: those who grew up booking everything from their smartphone tend to skip checks, precisely because the gesture has become too familiar to seem risky.
The SIM card you shouldn’t buy at the station
Those traveling abroad who want to avoid roaming often buy a local SIM, perhaps right outside the airport or near the station. And that’s exactly where SIM cards circulate that are almost out of data, close to expiration or, in the worst cases, stolen or registered to someone else. The most sensible solution, when the phone allows it, is an eSIM from a reliable operator, which can be activated before you even leave: it eliminates the physical step and with it much of the risk.
The wallet in the wrong pocket
Then there’s the oldest risk of all, one that doesn’t need a computer: pickpocketing. Crowded stations, baggage areas, boarding queues: these are environments where casual physical contact is the norm, therefore also the perfect pretext for those who work by pocket. Wallet in front pocket, shoulder bag closed: trivial precautions that remain incredibly effective precisely because almost no one applies them consistently.
The key copied while you were at the beach
The last scenario is perhaps the most disturbing because it touches the space that should be the safest: the rental home. Cases have been documented of people who rent a property through vacation rental platforms, copy the physical key, and re-enter the apartment when the next guests are out visiting the city. The countermeasure isn’t generalized distrust of short-term rentals, but a precise technical choice: favor properties with digital locks or codes that change with each booking.
Why it pays to train even those who don’t work in an office
There’s a point that often escapes those dealing with IT security in companies: risk training almost always stops at the desk, and technology is treated as a problem separate from people’s behavior. But the employee who recognizes a phishing email during work hours is the same person who, on vacation, can fall for a booking scam, because no one has ever explained that the same dynamics (urgency, misplaced trust, distraction) work identically outside the office.
This is the reasoning on which we build our approach: we believe that technology blocks malware, but that the human factor remains the main risk vector, and that the two levels (technical protection and people’s behavior) must work together, not in parallel. That’s why our platform combines multi-level email protection, capable of intercepting phishing attempts before they reach the inbox, with continuous training that doesn’t end with an isolated course, adaptive phishing simulations, and a risk score that brings together what happens in the email inbox with what people learn to recognize. It’s not awareness on one side and technical security on the other; it’s a single infrastructure that trains the defense reflex, both in the office and at the airport.
The operational takeaway
Before leaving, three concrete things: activate an eSIM instead of buying a physical SIM on the street, verify that the booked accommodation has a digital lock or at least a non-reusable code, and treat every deposit request for events or cruises with the same suspicion you’d reserve for an email from the “boss” asking for an urgent bank transfer.
Vacation is meant to unplug mentally, not to turn off critical judgment: that needs to stay on, especially when the suitcases are already packed.







