travel fraud risk is becoming harder to detect as organized fraud networks and AI-assisted attackers increasingly imitate the behavior of legitimate travelers, weakening many of the signals airlines, hotels and online travel platforms have traditionally relied on to identify suspicious transactions.
New analysis from ecommerce fraud and risk intelligence company Riskified found that airline fraud risk increased during the first five months of 2026, with May recording the sharpest year-over-year increase. According to the company’s Travel Industry Insights research, airline fraud risk in May was 32% higher than in the same month of 2025.
The findings point to a larger challenge emerging across digital travel.
Fraudsters are no longer relying only on obviously suspicious behavior. They are increasingly attempting to look like ordinary customers, using compromised identities, legitimate-looking accounts and familiar booking patterns to avoid detection.
For airlines, hotels and travel platforms, this makes fraud prevention more complicated.
Blocking unusual transactions is relatively straightforward.
Identifying fraud that deliberately looks normal is much harder.
Travel Fraud Risk Is Becoming Less Predictable
Travel fraud has traditionally been associated with certain recognizable patterns.
An unusually expensive ticket purchased shortly before departure could attract additional scrutiny.
A mismatch between the person paying for a flight and the passenger traveling might increase risk.
A new account making a high-value purchase could also appear suspicious.
These indicators remain useful, but Riskified’s analysis suggests criminals are adapting to them.
The company analyzed hundreds of millions of transactions across flights, hotels and ground transportation and found that fraud patterns are becoming less dependent on predictable seasonal or behavioral signals.
That creates a significant challenge for automated fraud systems.
If criminals understand which behaviors trigger additional verification, they can change those behaviors.
Fraud detection therefore becomes a continuous contest between attackers and risk-management systems.
May Airline Fraud Risk Rose 32%
The most striking number in the report concerns airline transactions.
Riskified found that airline fraud risk increased during January through May 2026, with May recording a 32% year-over-year increase compared with May 2025.
The increase matters because it suggests travel fraud is not confined to one predictable booking season.
Fraud networks can change tactics throughout the year based on demand, available accounts, pricing and weaknesses in merchant systems.
Airlines are particularly attractive targets because airline tickets combine several characteristics fraudsters value.
They can be expensive.
They are delivered digitally.
They can often be purchased quickly.
And once a flight departs, recovering losses can become difficult.
International travel also introduces complicated payment patterns that can make legitimate and fraudulent activity harder to distinguish.
Last-Minute Flights Remain Higher Risk
Booking timing continues to be one useful indicator.
Riskified found that airline tickets purchased less than seven days before departure were 2.3 times riskier than other flight bookings.
There is an obvious reason criminals may prefer short booking windows.
Fraud prevention systems and payment providers have less time to identify suspicious activity before the service is consumed.
But airlines cannot simply block last-minute bookings.
Many legitimate customers purchase flights shortly before departure.
Business travelers may need to attend unexpected meetings.
Families may travel because of emergencies.
Flexible travelers may find last-minute deals.
This creates one of the central problems in fraud prevention: reducing fraud without creating unnecessary friction for legitimate customers.
Payment and Passenger Names Are Changing as Signals
One particularly interesting finding involves the relationship between payment names and passenger names.
Historically, a ticket purchased by one person for another could appear riskier because stolen payment credentials might be used to purchase travel for a different passenger.
Riskified says transactions where the payer and passenger names did not match remained approximately 2.5 times riskier in 2025.
However, the opposite category is becoming more complicated.
Airline transactions where the payer and passenger names matched experienced a significant increase in risk beginning in November 2025. Riskified says risk for these apparently normal transactions climbed more than 30% compared with its January 2025 baseline.
That development illustrates how fraudsters can undermine conventional risk indicators.
If matching names are considered safer, attackers have an incentive to create transactions where the information matches.
A signal that once represented trust can gradually become less reliable.
Fraudsters Are Learning What Normal Looks Like
Modern fraud increasingly depends on imitation.
Instead of creating obviously unusual transactions, sophisticated attackers try to reproduce the characteristics of legitimate customers.
That can involve using stolen identity information alongside compromised payment credentials.
Attackers may also take control of existing customer accounts.
An established travel account can be particularly valuable because it already contains behavioral history.
The account may have completed legitimate transactions in the past.
It may contain saved traveler details.
It may have stored payment methods.
It may also hold loyalty points.
From the perspective of a conventional fraud system, activity from such an account can initially look more trustworthy than activity from a completely new customer.
This is why account takeover has become such an important security problem across ecommerce and travel.
Loyalty Accounts Have Become Financial Assets
Airline and hotel loyalty accounts are particularly attractive targets because points increasingly function like digital currency.
A frequent flyer account can contain significant value.
Points may be redeemed for flights, hotel stays, upgrades, merchandise or other benefits.
In some programs, they can also be transferred or converted through partner ecosystems.
Riskified identifies loyalty programs, reward points and stored customer information as continuing targets for fraud networks.
Criminals can compromise an account and redeem points before the legitimate customer realizes what happened.
Stolen accounts may also be used to support fraudulent bookings.
This changes how travel companies need to think about cybersecurity.
Protecting the payment transaction alone is no longer enough.
The customer account itself has become a financial asset.
Account Takeover Creates a Different Fraud Problem
Traditional payment fraud and account takeover are related but distinct problems.
In payment fraud, an attacker might use stolen card information to make a purchase.
With account takeover, the attacker gains access to an existing customer’s digital identity.
That can be more dangerous because the account already has trust.
A long-time hotel customer might have years of booking history.
A frequent flyer may regularly purchase expensive international flights.
Those behaviors would normally make the account appear legitimate.
If an attacker takes control of that account, the same history can help disguise fraud.
Fraud systems therefore increasingly need to evaluate not only what is being purchased but also whether the person using the account is actually the legitimate account owner.
Device Intelligence Becomes More Important
One way fraud systems attempt to solve this problem is through device intelligence.
A transaction contains much more information than a name and payment number.
Systems can analyze device characteristics, network information, account history, geographic patterns and interaction behavior.
The objective is not simply to identify whether one characteristic looks suspicious.
Instead, modern fraud detection attempts to understand the relationship between many signals.
A familiar customer suddenly logging in from an unusual device might deserve additional scrutiny.
But that alone cannot prove fraud.
The customer may simply have purchased a new phone.
Risk systems therefore need to evaluate combinations of signals rather than relying on rigid rules.
This is one reason machine learning has become important in fraud detection.
AI Is Changing Both Sides of Fraud
Artificial intelligence creates a particularly complicated dynamic.
Travel companies can use AI to detect unusual patterns across enormous numbers of transactions.
But fraudsters can also use AI.
Generative AI can potentially help criminals create more convincing messages, automate social engineering and rapidly modify attack strategies.
It can also lower the skill required to produce realistic content.
This creates an asymmetric problem.
A legitimate travel business needs to protect millions of transactions consistently.
A fraudster needs to find only one weakness that works.
Once a successful method becomes widely detected, attackers can change tactics.
AI can potentially accelerate that experimentation.
Fraud prevention therefore needs to become adaptive rather than relying on a static collection of rules.
Fraud Detection Is Becoming a Behavioral Problem
The travel fraud risk highlighted by Riskified’s research demonstrates why behavior is becoming increasingly important.
A payment card may be legitimate.
A customer name may be legitimate.
An account may have existed for years.
But the current behavior could still be fraudulent.
This shifts fraud analysis toward questions such as:
Does this purchase fit the account’s normal behavior?
Is the device familiar?
Does the booking pattern make sense?
Has the customer’s interaction behavior suddenly changed?
Are multiple accounts showing related patterns?
Do seemingly unrelated transactions share hidden infrastructure?
No individual answer necessarily proves fraud.
But patterns across many signals can provide stronger evidence.
Fraud Networks Can Operate Across Travel Categories
Travel fraud is also not confined to airlines.
The same identities, accounts and payment methods can potentially be used across multiple services.
A compromised account may help criminals purchase flights.
Another account can be used for hotel bookings.
Ground transportation can become another target.
Riskified says its travel network includes more than 60 travel merchants and had processed a cumulative $828 billion in travel transactions across flights, hotels and ground transportation as of June 2026.
The scale of that network gives the company visibility across different types of travel transactions.
Cross-merchant intelligence can potentially reveal patterns that would be difficult for a single company to identify.
Hotels Face Their Own Fraud Patterns
Hotels have different economics from airlines.
Riskified’s analysis found that July and August generated the highest hotel revenue but also produced the greatest potential exposure to fraud losses.
However, the highest-risk period was not necessarily the obvious peak season.
The company identified April 2025 as the year’s riskiest month for hotels, with fraud risk approximately 20% above the annual average.
That reinforces the report’s broader argument.
Fraud does not always follow predictable seasonal assumptions.
Businesses that dramatically increase fraud controls only during obvious holiday periods could miss significant activity at other times of the year.
Continuous risk monitoring becomes more important when criminals actively search for periods where defenses may be weaker.
Luxury Hotels Are Attractive Targets
Five-star hotels showed the highest fraud risk among hotel categories analyzed by Riskified.
High-end accommodation is an attractive target for the same reason luxury goods attract ecommerce fraud.
The transaction value is high.
A successful fraudulent booking can therefore generate greater value for the attacker.
Luxury travel can also involve legitimate customer behavior that appears unusual.
Guests may make expensive international bookings.
One person may pay for another guest.
Corporate assistants may arrange travel for executives.
Customers may use multiple payment methods.
That diversity makes simplistic fraud rules difficult to apply without blocking legitimate bookings.
Travel Companies Cannot Add Friction Everywhere
The easiest way to reduce some forms of fraud would be to introduce more verification to every transaction.
But that creates a commercial problem.
Travel customers expect fast checkout.
Someone purchasing a flight does not want to complete multiple unnecessary security steps.
A customer booking a hotel on a smartphone may abandon the purchase if verification becomes too complicated.
Travel companies therefore need to balance two objectives that can conflict.
They need to block criminals.
And they need to approve legitimate customers quickly.
This is sometimes described as the tension between fraud prevention and customer experience.
Overly permissive systems create financial losses.
Overly aggressive systems create false declines.
Both can be expensive.
False Declines Can Cost Real Revenue
A false decline occurs when a legitimate transaction is incorrectly rejected as fraud.
For a travel company, that can mean losing more than one booking.
A customer whose card is incorrectly rejected may immediately book through a competitor.
The customer may also lose trust in the platform.
This is particularly problematic for high-value travel.
A legitimate international booking can contain many characteristics that look unusual compared with ordinary ecommerce.
The purchase may be expensive.
The customer may be abroad.
The booking may involve multiple passengers.
The payer may differ from the traveler.
A rigid fraud system could interpret several of these characteristics as suspicious.
Modern risk systems therefore need to determine which combinations actually indicate fraud.
Identity Signals Alone Are No Longer Enough
The changing payer-passenger relationship demonstrates why identity information alone cannot solve the problem.
Fraudsters can obtain enormous quantities of stolen personal data through breaches, phishing and account compromise.
If an attacker possesses enough legitimate information, filling out a booking form correctly is not difficult.
Names can match.
Addresses can match.
Phone numbers can appear valid.
Even a legitimate customer account may be used.
This means identity needs to be evaluated in context.
The question becomes not only “Is this information correct?” but “Does this transaction make sense for this customer right now?”
That requires a much richer understanding of behavior.
Real-Time Decisions Are Critical in Travel
Travel also creates unusually tight decision windows.
A physical ecommerce merchant can sometimes delay shipping while investigating a suspicious purchase.
An airline selling a flight departing tomorrow has much less time.
A hotel reservation for the same evening may need an immediate decision.
This makes real-time fraud detection particularly important.
Risk systems need to analyze large numbers of signals within milliseconds or seconds.
The customer expects the booking confirmation immediately.
That is why AI and machine learning are attractive technologies for the sector.
They can evaluate patterns across enormous transaction datasets faster than manual fraud teams.
Human investigators remain important, particularly for unusual cases, but they cannot manually review every booking.
Fraud Intelligence Needs Network Effects
Large fraud networks can have an advantage over individual merchants because they can observe activity across multiple businesses.
A suspicious device may appear completely new to one airline.
But the same device might already have been associated with fraudulent activity elsewhere.
Similarly, an identity pattern could appear across hotels, airlines and other ecommerce merchants.
Shared intelligence can therefore reveal relationships that are invisible inside one company’s transaction history.
This creates a network effect in fraud prevention.
The more transactions a risk platform can analyze, the more context it may have when evaluating a new transaction.
Riskified’s travel dataset is built around this principle, covering hundreds of millions of transactions across multiple travel categories.
Fraud Prevention Is Becoming Continuous
The most important implication of the report may be that fraud rules cannot remain static.
A rule that works today can become less useful once attackers understand it.
A trusted signal can eventually become a target for imitation.
A seasonal pattern can change.
A new payment method can create new attack opportunities.
A new AI tool can make social engineering easier.
Fraud prevention therefore becomes a continuous learning process.
Models need updated data.
Risk teams need to investigate new patterns.
Authentication methods need to evolve.
Travel companies need to share intelligence across payment, account security and customer-service teams.
Customer Accounts Need Stronger Protection
Travel companies can also reduce risk before a transaction begins.
Account security is increasingly important.
Multi-factor authentication can make some account-takeover attacks harder.
Customers can be notified when unusual devices access their accounts.
Password reuse can be discouraged.
Sensitive actions such as transferring loyalty points can require additional verification.
Suspicious changes to account information can trigger alerts.
None of these controls eliminates fraud.
But they increase the number of barriers an attacker needs to overcome.
That matters because loyalty accounts now contain enough value to justify sophisticated attacks.
Travel Fraud Is Becoming a Cybersecurity Issue
Historically, fraud management and cybersecurity were often treated as separate disciplines.
Cybersecurity teams protected systems and accounts.
Fraud teams evaluated transactions.
Those boundaries are becoming less useful.
An account takeover begins as a cybersecurity problem.
It can end as payment fraud.
Phishing can lead to credential theft.
Credential theft can lead to loyalty-point theft.
A compromised identity can then be used for fraudulent bookings.
The attack crosses multiple systems.
Travel businesses therefore increasingly need integrated approaches connecting account security, payments, fraud detection and customer identity.
AI Agents Could Complicate the Picture Further
The rise of AI agents could introduce another layer.
Consumers may increasingly use AI assistants to search for flights, compare hotels and eventually make bookings.
That could change what legitimate customer behavior looks like.
Instead of a human manually browsing several pages, an automated agent might generate unusual but completely legitimate interaction patterns.
Fraud systems will need to distinguish authorized automation from malicious automation.
This will be difficult.
If legitimate customers increasingly delegate transactions to software agents, behavioral signals that currently indicate bots may become less reliable.
The same pattern seen with payer and passenger names could repeat in another form.
A signal associated with fraud today could become normal customer behavior tomorrow.
Travel Platforms Need Adaptive Risk Models
The solution is unlikely to be one new fraud rule.
Adaptive models will become more important.
A modern system needs to evaluate how signals change over time.
If matching names suddenly become riskier, the model needs to adjust.
If a particular booking window becomes a target, risk weighting needs to change.
If fraud moves between destinations or payment methods, the system needs to detect the shift.
This is where large-scale machine learning can provide an advantage.
Models can potentially identify emerging relationships before analysts would notice them manually.
But human oversight remains important.
Statistical correlation does not automatically explain why a pattern is changing.
Fraud analysts still need to understand the underlying attack.
Riskified Travel Fraud Data Shows a Moving Target
Riskified CMO Jeff Otto described the speed at which fraud pathways are evolving as one of the most notable findings from the company’s annual travel analysis.
According to Otto, behaviors that previously indicated trustworthy customers can become exploitable once organized fraud groups learn how to reproduce them.
That observation captures the fundamental challenge.
Fraud detection is adversarial.
The people being detected are actively trying to understand the system and defeat it.
This makes fraud fundamentally different from many ordinary prediction problems.
Tomorrow’s fraud may intentionally look different from yesterday’s fraud.
Travel Fraud Risk Could Rise With Digitalization
The travel industry continues to become more digital.
Consumers increasingly book flights, hotels and transportation through websites and mobile applications.
Digital wallets make payments faster.
Loyalty programs are accessible through apps.
Customers expect instant confirmation.
These improvements make travel more convenient.
They also create more digital surfaces for attackers.
Every customer account can become a target.
Every stored payment credential has potential value.
Every loyalty balance can attract criminals.
The industry therefore faces a paradox.
The smoother the digital travel experience becomes, the more important invisible fraud protection becomes behind it.
Customers want less friction.
Fraud teams need more information.
The challenge is achieving both simultaneously.
Travel Fraud Risk Is Forcing a New Security Model
The travel fraud risk highlighted by Riskified’s 2026 analysis suggests airlines, hotels and travel platforms can no longer depend heavily on a small set of familiar fraud indicators.
Airline fraud risk rose 32% year over year in May.
Last-minute flights remained 2.3 times riskier.
Transactions where payer and passenger names matched — traditionally a more reassuring signal — have also become significantly riskier.
Loyalty accounts continue to attract attackers.
And luxury hotels remain particularly exposed.
The common thread is adaptation.
Fraudsters observe defenses and change behavior.
As AI makes automation and imitation easier, that cycle could accelerate.
Travel companies will therefore need fraud systems capable of learning continuously across transactions, accounts, devices and behavioral patterns.
The objective is no longer simply finding transactions that look suspicious.
The harder challenge is finding fraud that has learned how to look legitimate.
That distinction could define the next phase of digital travel security.







