TL;DR: Fraudsters are increasingly mimicking legitimate traveller behaviour, with flight fraud risk up 32% in May 2026 and billing-name matches becoming more risky than they were earlier in the year, according to Riskified travel analysis. For identity and fraud teams, the lesson is that static trust signals and legacy review rules are losing predictive value as attackers learn to blend in.
NHIMG editorial — based on content published by Riskified: Travel fraudsters are adapting faster than traditional signals can keep up
By the numbers:
- Flight fraud risk increased by 32% in May 2026 compared with May 2025.
- Billing-name-to-passenger-name mismatches remained 2.5x riskier in 2025.
- Riskified’s travel network includes more than 60 travel merchants.
Questions worth separating out
Q: How should travel merchants adapt fraud controls when attackers mimic legitimate customer behaviour?
A: They should move from single-signal rules to contextual scoring that combines booking timing, device continuity, loyalty behaviour, account age, and identity history.
Q: When do identity signals become too weak to rely on for travel fraud detection?
A: They become too weak when attackers can learn and reproduce the same indicators the merchant uses for trust decisions, such as name matching, account history, or routine booking patterns.
Q: What do security teams get wrong about loyal customer accounts and fraud risk?
A: They often assume a verified or long-standing account is inherently trustworthy.
Practitioner guidance
- Rebuild trust scoring around multi-signal context Combine booking timing, device continuity, account age, loyalty activity, payment history, and identity consistency into one decision layer instead of relying on a single pass or fail signal.
- Harden verified-account workflows Apply step-up checks to consumer and provider accounts when loyalty redemptions, reservation edits, or guest communications diverge from established behaviour, because those are the workflows fraudsters monetize.
- Separate high-risk travel behaviour from ordinary peak demand Model last-minute bookings, luxury-property reservations, and rapid loyalty usage as distinct risk clusters so fraud teams do not confuse seasonal traffic with adversarial activity.
What's in the full report
Riskified's full analysis covers the operational detail this post intentionally leaves for the source:
- Breakdowns of how fraud risk shifts across flights, hotels, and land transportation during different booking windows
- Methodology notes on the travel network sample, transaction coverage, and risk-level benchmarking used in the analysis
- Category-specific patterns for luxury hotels, loyalty abuse, and provider-account compromise that inform operational tuning
- Behavioural examples that show how fraud rings adapt faster than static trust signals can be refreshed
👉 Read Riskified's travel fraud analysis on shifting booking scams and traveller behaviour →
Travel fraud is outpacing legacy signals, what should teams change?
Explore further
Travel fraud is now an identity governance problem, not just a payment problem. The article shows fraudsters are exploiting trusted customer behaviour rather than only obvious payment anomalies. That matters because account recovery, loyalty systems, and reservation workflows all depend on identity assumptions that can be learned and impersonated. Practitioners should treat fraud detection as a trust-governance discipline, not a single-score exercise.
A question worth separating out:
Q: How can fraud and IAM teams work together to reduce travel account abuse?
A: They should connect authentication policy, account recovery, device intelligence, and fraud case handling into one operating model. IAM teams provide identity assurance and recovery controls, while fraud teams detect monetisation behaviour and transaction abuse. When those functions share signals, compromised identities are easier to contain before loyalty theft or fraudulent booking completion.
👉 Read our full editorial: Travel fraud is adapting faster than legacy identity signals can track