Monday 31 Aug, 2026

Have you booked a trip? Hackers may have already stolen your identity

Photo:NordVPN

Remove

From boarding passes to the dark web, travel documents are finding their way onto the black market. It’s not just your vacation that’s being fixed – cybercriminals are making money off of your travel data, according to a new joint study from NordVPN and Saily.

As international travel hits new records, cybercrime targeting travelers is also increasing. A joint investigation by NordVPN and Saily reveals the growing market for stolen travel documents on the dark web – from scanned passport copies to bonus accounts – and shows how cheap it is for criminals to buy your identity.

Scanned international passports can be sold for as little as $10 and up to $200, while verified EU passports can sell for over $5,000. Fake bank statements, visa stickers, and hacked airline loyalty accounts with millions of bonus points are sold for hundreds of dollars. Even Booking.com reservations are resold at deep discounts, often for $250 or more.

”The breathtaking prices we see on the dark web show how valuable and vulnerable travelers” personal data has become,” said Marijus Briedis, Chief Technology Officer (CTO) at NordVPN.

Travel data turns into quick cash for cybercriminals

Travel documents can fall into the wrong hands in a number of ways. Cybercriminals use malware to scan devices and cloud storage for sensitive files. Breaches of airlines, visa platforms, and travel agencies result in the disclosure of passenger information. 

Additionally, phishing sites that pretend to be official portals trick users into uploading passports and visas. Even publicly shared cloud folders with inadequate permissions can be easily found and misused. Physical documents such as boarding passes lost or discarded at airports also end up on the dark web.

”Travelers are reporting AI-powered phishing attacks, ranging from fake check-in platforms that request selfies with IDs, to scam sites that sign up for airport lounges and Wi-Fi,” said Vykintas Maknickas, CEO of Saily. ”Now that AI tools are easily accessible to criminals, it has become easy to carry out phishing attacks, which are also highly convincing and difficult to detect.”

Travel documents – a goldmine for hackers

Travel documents are valuable because they have both high resale value and are easy to use. Many online platforms only require a scanned copy of your passport and a selfie for identity verification – a process that criminals can circumvent using deepfake technology. Stolen passenger data often includes full names, dates of birth, passport numbers, email addresses, phone numbers and emergency contact details, enabling criminals to commit sophisticated, targeted fraud.

With this information, criminals can commit identity theft, open fake accounts, or apply for loans. They can also carry out phishing or social engineering attacks by using personal and travel information to deceive victims or their contacts.

”Travel documents are a goldmine for hackers because they provide direct access to your identity with almost no barriers,” Briedis says. ”This makes stolen travel data incredibly valuable and dangerous.”

Digital protection for travelers

NordVPN and Saily urge travelers to take immediate steps to protect their data. Sensitive travel documents should be stored in encrypted digital vaults rather than in publicly accessible cloud folders. Travelers should also be vigilant against phishing attempts and check URLs before providing information. 

Maknickas says the best defense against modern social engineering is a healthy skepticism. ”Since scammers use personal tactics that take the situation into account, the most effective defense is to pause for a moment and think critically before responding to a digital request. If something feels off, try to verify the information through other channels.”

”Travelers should ensure their devices are up-to-date with antivirus software and always use VPNs on public Wi-Fi networks to encrypt their online activity and block malware. They should also regularly monitor financial and bonus accounts to detect suspicious activity at an early stage and immediately report lost or stolen documents to limit risk,” says Briedis. 

Methodology. The research was conducted by NordVPN and Saily staff between June 10 and 20, 2025, using data analyzed through NordStellar, a threat management platform. The information was sourced from dark web marketplaces and hacker forums where stolen travel documents and related information are advertised for sale. The data examined included lists of passports, visas, bonus accounts, and booking details, along with their associated prices. The analysis focused on the availability, pricing, and risks of travel document trafficking to raise awareness and guide travelers.

According to the press release.

Remove

Related posts

July 2026 was the strongest month yet for Swedish tourism. A total of nearly 14.25 million...
Åre is the Swedish ski resort that has received the most snow on average over the last five...
Several hundred foreign tourists are missing in Nepal, which has been hit by dramatic floods and landslides...
The Malta Tourism Authority becomes the new Destination Partner of the World Travel & Tourism Council, WTTC. The partnership...

Popular posts

Our website uses cookies. Read more about our use of cookies: Privacy policy