mail fraud and privacy protection

Most of the travel safety questions we get are really money questions - is this booking site legitimate, is it safe to hand it a card, and what happens if it is not. The stories that come back are almost never about a sketchy operator in a country you would struggle to find on a map. An analysis of Federal Trade Commission complaint data counted 14,263 vacation and travel fraud reports filed between July and September of 2025, worth roughly $40 million in losses in those three months alone, up 18 percent over the quarter before.

In my home state of California, travelers reported the largest dollar losses of any state that quarter, about $6.3 million. Nevada residents filed at the highest rate per capita, which tracks given how many bachelor parties and long weekends with the guys land in Las Vegas every week. Fraud follows the traveler, and a lot of it gets reported from inside the United States and Canada.

These are the tips I have picked up that still hold up in 2026 - along with the standbys that no longer do.

Scammers Prey On You Through Sites You Already Trust

The most effective travel fraud running right now arrives through a real website, not a fake one.

On April 13, 2026, Booking.com emailed customers to tell them unauthorized third parties had reached reservation data - names, email addresses, physical addresses, phone numbers, and booking details - by compromising hotel partner accounts rather than Booking.com itself. Staff were phished with fake CAPTCHA pages that installed remote access malware.

What that buys a scammer is credibility. They log into the hotel's account, pull up your reservation, and message you through the platform or over WhatsApp with your real check-in date, room type, and confirmation number, asking you to re-verify your card before the booking cancels. Nothing in the message looks off to the person receiving it.

Checking whether the site looks legitimate does not help here. The site is legitimate.

Locking Things Down Before You Book

The planning phase is where you hand your card number to the most strangers in the shortest span of time.

The Padlock Stopped Meaning Anything

The old advice was to look for https:// and the padlock before entering a card number. All that tells you now is that a fraudster's site is encrypted. The Anti-Phishing Working Group has found more than 90 percent of phishing sites carrying a valid HTTPS padlock, and free certificate authorities hand a criminal a trusted certificate for a near-miss domain in about five minutes. Google pulled the padlock out of Chrome in September 2023 for that reason.

Read the domain instead - the characters between "https://" and the first single slash. The string booking.com-reservations.net is not Booking.com. If a link arrived by email or text, type the domain yourself rather than tapping it.

Use a Virtual Card Number for Anything Unfamiliar

A virtual card number is a throwaway 16-digit number tied to your real account that you can lock to one merchant, cap at a dollar amount, or kill after a single charge. If it leaks it is worthless, and your real card never gets reissued mid-trip.

Capital One's Eno extension generates them free for any cardholder. Citi offers virtual account numbers on many of its cards, and Bank of America lets you set your own spending limit on single-use and multi-use numbers. If your issuer has nothing, Privacy.com gives you 12 cards a month on its free tier.

Pay on the Platform or Do Not Pay

One rule would have stopped most of the Booking.com losses. If a hotel, host, or tour operator contacts you after booking and asks you to pay by bank transfer, wire, Zelle, gift card, or a link they sent, the answer is no - even when the message arrives inside the app you booked in and quotes your confirmation number back to you.

Call the property on the number listed on its own website, never the number in the message. The call takes two minutes and costs nothing when the request is genuine.

Watch for the Test Charge

Card thieves routinely run a small charge, a dollar or two, to confirm a stolen number is live. Set your card app to alert on every transaction, so the test charge reaches you in seconds instead of on next month's statement.

Move your passport scans and booking confirmations into a password manager while you are in there. Unencrypted passport photos in your camera roll leak when the phone does.

What Changes Once You Are on the Road

Once you land, the risk moves off the booking form and onto the hardware and networks around you.

Set Up Two-Factor Authentication That Survives the Trip

Two-factor authentication protects accounts, not devices, and the version most people switched on breaks the moment they land. Text-message codes need your number reachable, which it may not be on an eSIM, a local SIM, or a plan that does not roam where you are going.

Move the accounts that matter onto an authenticator app or a passkey before you leave, and print the backup codes. Start with email, because whoever controls your inbox can reset everything else.

What a VPN Does and Does Not Do

A VPN encrypts traffic between your device and the VPN provider, which mattered in 2016, when plenty of sites still sent data in the clear. Nearly every site you would put a card into now encrypts on its own, so the VPN is no longer what stands between a stranger on the hotel wifi and your bank login.

Run one anyway on public networks. But the threat on hotel and airport wifi has shifted to the network itself - a hotspot named after the property that belongs to the guy two tables over, or a login page asking for a card number to "verify" you. Confirm the network name with the front desk, and treat any wifi portal that wants payment details as fake, because the legitimate ones do not ask for them.

Skip the RFID Wallet and Watch the Card Reader

RFID-blocking wallets and passport sleeves sell well against a threat that never materialized. Contactless cards issued from roughly 2018 on answer a tap with a one-time cryptogram that expires in seconds and cannot be replayed, and they never transmit your name or the code printed on the back. Researchers have demonstrated skimming in lab conditions for close to twenty years, but documented cases of travelers losing money to a scanner in a crowd remain close to nonexistent.

Passport sleeves miss by even more. An e-passport chip releases nothing until a reader has optically scanned the printed text on the photo page, so the passport has to be open in someone's hands first - at which point the chip is the least of your problems.

The theft that does reach travelers happens at the reader. Skimmers were still being pulled off fuel dispensers in the summer of 2026, and the pattern holds steady: the pumps that get hit are the ones without chip readers. Use the pump closest to the attendant's window or pay inside, pick ATMs attached to a bank branch over the freestanding one in a bar, pull on the card slot before inserting, and cover the keypad every time.

Split the Cards Up

Carry one card and the cash you need for the day. The backup card and the passport stay in the room safe. If the wallet goes, the trip does not go with it, and you are not spending an afternoon of a long weekend with the guys on hold with a fraud department instead of on the water.

Contact Your Bank Before You Travel Internationally

All of that covers the cards already in your wallet. The larger exposure is someone using your stolen details to open something new while you are ten time zones from your mailbox. While most folks will ignore this step, freezing your credit accounts and also alerting your bank that you will be traveling can help avoid false fraud flags as well as prevent someone from acting on information that they may have stolen about your identity.

A credit freeze at all three bureaus - Equifax, Experian, and TransUnion - has been free by federal law since 2018. It takes about ten minutes online, blocks new accounts in your name, and thaws temporarily when you need credit pulled. It does nothing about fraudulent charges on the cards you already carry, which is what the alerts and virtual numbers are for, but it keeps working while you are asleep on a plane.

If you would rather not manage any of this yourself, booking through a travel advisor is a fair answer. An advisor gives you a person with a phone number and an independent record of what you booked, so when a message lands at 2 a.m. demanding card re-verification, someone can confirm in thirty seconds whether it is real. That beats any regulatory difference between a domestic booking site and a foreign one.