TL;DR: Travel fraud is becoming more targeted and operationally sophisticated, with Riskified reporting rising dark web activity, fake OTA schemes, and attackers using social channels, fake sites, and platform-specific playbooks to make fraudulent bookings look legitimate. The pressure on merchants is shifting from seasonal fraud spikes to continuous verification and stronger account governance.
NHIMG editorial — based on content published by Riskified: “Booking scams are taking off.”
Questions worth separating out
Q: What breaks when travel fraud teams rely on a single trusted booking signal?
A: Single-signal trust fails because fraudsters learn which field or match is being used as a proxy for legitimacy and then manufacture that condition.
Q: Why do stolen host accounts make travel fraud harder to detect?
A: Stolen host accounts move the abuse inside a trusted workflow.
Q: What do merchants get wrong about AI-assisted travel fraud?
A: They often assume AI mainly increases volume.
Practitioner guidance
- Harden trusted booking signals Review where your fraud stack treats field matches, loyalty data, or booking attributes as proof of legitimacy.
- Treat partner and host accounts as fraud infrastructure Map which external or shared accounts can send messages, change reservations, or view booking data, then apply stronger authentication, session monitoring, and lifecycle reviews to those accounts.
- Build merchant-specific fraud playbooks Use abuse patterns unique to your booking flow, loyalty programme, and customer support channels to tune detection rules and escalation paths, rather than relying only on generic fraud thresholds.
What's in the full report
Riskified's full report covers the operational detail this post intentionally leaves for the source:
- Region-by-region fraud patterns across travel merchants, useful for comparing exposure by market.
- Specific examples of buy-for-you, triangular sales, and platform-specific booking abuse.
- Dark web monitoring indicators that help teams spot emerging fraud playbooks earlier.
- Practical strategies for protecting revenue without increasing customer friction.
👉 Read Riskified’s analysis of rising travel booking scams and fraud tactics →
Booking scams and travel fraud: what merchants need to watch?
Explore further
Travel fraud is now a trust orchestration problem, not just a payment problem. The article shows that attackers are exploiting the full booking journey, including account signals, platform messaging, and merchant workflows. That means fraud teams and identity teams need to coordinate around trust boundaries, not hand off responsibility after checkout. The practical conclusion is that identity assurance must extend into the operational channels where travel bookings are confirmed, changed, and fulfilled.
A question worth separating out:
Q: Who is accountable when travel fraud exploits trusted platform access?
A: Accountability usually spans fraud operations, IAM, and the business owner of the platform or partner workflow. If a verified account can be abused to create fraudulent bookings, the control failure sits in authentication, access governance, and monitoring together. Organisations should define shared ownership before incidents occur.
👉 Read our full editorial: Travel booking scams are evolving beyond fake OTA tactics