afootwego-03-the-rise-of-the-hi-tech-scammer

afootwego Travel Sense Post

…for people who love to walk…

Supporting Mindful and Responsible Travel

The Rise, and Rise, of the Hi-Tech Scammer

Image showing a "closed" sign at the entrance to a complex in Bamban, north of Manila, which had operated as a 'scam farm' - Credit: UN Office on Drugs and Crime
A raided gang-run internet ‘scam farm’ in Bamban, north of Manila, the Philippines, March 2024 – the UN Office on Drugs and Crime (UNODC) has been collaborating with national authorities to disrupt and dismantle scam farms in Southeast Asia countries, including the Philippines, Cambodia, Lao PDR, Myanmar and Thailand
Credit: UNODC, CC BY 2.0, via Wikimedia Commons

What You Need to Know About the Rise of the Hi-Tech Scammer…

15

It seems that we are living in the golden age of scamming, with the media bringing reports of new threats almost daily.

We’ll begin with a story that was very close to home for me.

A Quick Look at What’s Inside

In this Post, we shall explore:

When It Sounds Too Good to be True, It Is!

It was early 2025 when I took the ’phone-call. My Brother-in-Law’s words of greeting were: “We’ve been scammed!”.

The Hook. He went on to describe how his wife had received a ’phone call from a law firm, advising that a large sum of money had been found in an old bank deposit in her name, apparently the result of a long-forgotten childhood school post office savings bank investment account.


Image showing a page from a Post Office Savings Bank deposit book from 1869 - Credit: UK General Post Office
A scan of the first entries of a Post Office Savings Bank deposit book from 1869, later known as National Savings and Investments. Issued in Loughton, but probably similar to deposit books issued by Post Office Savings Bank throughout the UK
Credit: UK General Post Office, Public domain, via Wikimedia Commons

Excitement. The sum involved was almost $NZ 20,000, which had grown through various investments, from around $100 in the early 1970s.

The situation was that the government tax department was about to transfer all these ‘abandoned’ deposits into a consolidated fund, which would forever close the old account.

Urgency. The caller advised that my Sister-in-Law had until ‘close of business’ the following day to register her claim, before the tax department swooped!

Because the matter would require expedited processing, an up-front fee of $2,500 was required, although part of this, probably at least half, should be refundable.

Assurance. My Sister-in-Law had no recollection of any such account, although she did recall school banking days with her post office savings bank account. The caller told her the account had been opened by her mother, and used her name.


Image showing a New Zealand Post Office Savings Bank Passbook, issued at Kilbirnie in 1953 - Credit: Wainuiomartian
New Zealand Post Office Savings Bank Passbook issued in 1953. The Post Office Savings Bank was created by the New Zealand Government as a postal savings system in 1867. It briefly became PostBank in 1987, before it was disestablished after it was acquired by Australia and New Zealand Banking Group (ANZ) in 1989
Credit: Wainuiomartian, CC BY-SA 4.0, via Wikimedia Commons

Now convinced, my two in-Laws took the necessary details of what to do, wrote out an email registering their claim, made a bank payment, and waited. And waited. And waited!

Desperation. After a week, they got an email saying that there was a backlog with the tax department, but a result was expected very soon.

After about another week, my Sister-in-Law got another ’phone call, but from a different caller. This time it was a senior partner, who apologised for the delay, and advised that there was a bit of bad news.

Pressure. The tax department was requiring verification of my Sister-in-Law’s particulars from when she was at school. And that was the easy part!

The hard part was that the $2,500 fee had all been consumed in administrative costs, so another $2.5K would be needed to progress the matter.

The good news was that when the matter was cleared, this should all be fully refundable, along with most of the original up-front fee.

Withdrawal. “That’s when we pulled the pin”, my Brother-in-Law said, “We were done – $2½K – but it could’a been worse!”

He then added that in mid-2024, they had both been warned that their data may have been compromised in the Ticketmaster data breach, asking if I thought there was a connection.


Scams are Older than the Pyramids

In history, scams can be traced back over 5000 years, with records showing how ancient Egyptians tried to cheat on their livestock taxes.


Image of an ancient Egyptian agricultural mural painting from the tomb of Ounsou (circa 1450 BCE) - Credit: Louvre Museum
An ancient Egyptian agricultural mural painting from the tomb of Ounsou, a grain accounting scribe during the 18th Dynasty, around the reign of Thutmose III (circa 1450 BCE), showing workers harvesting grain. (Louvre Museum – Department of Egyptian Antiquities)
Credit: Louvre Museum, CC BY-SA 3.0, via Wikimedia Commons

By 1300 BC, Pharaoh Horemheb, who was once an advisor to Tutankhamun, passed a law punishing tax evasion when he was dealing with rampart corruption, bribery, and fraud.

In ancient Greece, around 300 BC, two shipping merchants, Hegestratos and Zenothemis, when attempting an insurance scam by sinking empty ships after storing the cargo elsewhere, were caught in the act.

During the Middle Ages, religious fraudsters sold fake holy relics, fake healing potions, and even staged false miracles.

And, across the almost 4000 years of Chinese Dynasties, from Xia to Qing (2070 BC to 1912 AD), records show numerous scams and frauds in play, ranging from the quality of goods, to counterfeiting, and even to faking silver (with copper and lead).


Image showing an example of a Get Rich Quick scam leaflet, sent via postal mail, 2007 - Credit: Scott Zeid
Example of a Get Rich Quick scam leaflet, sent via postal mail, 2007
Credit: Scott Zeid, CC BY-SA 2.0, via Wikimedia Commons

In Australia, an investigation by ABC News in July 2026 revealed that Australian supermarkets were selling Chinese-grown tomato products that had been deliberately mislabelled as being Australian or Italian. With denials of wrongdoing from suppliers and supermarkets, products remain  on sale while the government regulator is conducting an inquiry?!

Organised cybercrime operations can be traced back to 16-year-old Kevin Mitnick, who later became a security consultant, after he hacked into a computer known as The Ark, at the Digital Equipment Corporation, in 1979. By the mid-1980s, computer viruses were multiplying rapidly. Into the 1990s, new virus and malware numbers exploded.

The growth of the internet during the early 2000s saw crimal organizations start to fund professional cyberattacks. By the 2010s, numerous high-profile breaches and attacks were beginning to impact the national security of countries, and cost businesses millions.


Image of a screenshot showing a suspect program impersonating an antivirus warning, 2014 - Credit: Packer1028
Screenshot showing a suspect program impersonating an antivirus warning on a Compaq laptop [2014]
Credit: Packer1028, CC0, via Wikimedia Commons

The 21st Century is the Golden Age of Scamming

As our 21st Century continues, today scamming is BIG business on a global scale. Aided by modern technology, and super-charged by artificial intelligence, scammers, fraudsters, and con-artists are enjoying a ‘golden age’.

While much of the online scamming and hacking activities are conducted by cyber-criminals, using the internet, several nations are also involved in state-sponsored cyber-attacks, including China, Russia, North Korea, and Iran (Note: criminal hacking is sometimes known as ‘cracking’).


Image show a conceptual anonymous hacker - Credit: בר
Anonymous Hacker
Credit: בר, CC BY-SA 3.0, via Wikimedia Commons

Elsewhere, cyber-criminal activities are tolerated by governments, national and local. Scam ‘farms’ contribute to GDP in three nations of South-East Asia: Cambodia = 50-60%; Myanmar = 20-30%; Laos = ±66%. Further north, around 13% of North Korea’s total GDP is derived from state-sponsored hacking.

Other nations known to be responsible for significant portions of malicious cyber activity around the globe include: Nigeria, Ukraine, United States, Romania, and Brazil. /p>

In 2025, the most targeted countries for global cyber-attacks and scam operations were: United States, Ukraine, Israel, Japan, United Kingdom, Saudi Arabia, Brazil, India, Germany, and Poland.


Scamming and Hacking are Partners in Crime

In my Brother and Sister-in-Laws’ story, both had been affected by the 2024 Ticketmaster data breach, which was attributed to a decentralized, multinational cybercrime group known as ShinyHunters.

In this attack, data stolen included names, addresses, phone numbers, and partial payment information, belonging to an estimated 560 million customers. The stolen database was subsequently advertised, for a reported ransom of $US 500,000 (±$AUD 700,000), on the dark web forum called BreachForums.


An image representing the Dark Web, showing how it has no identity and how it's an unknown space - Credit: geralt
An image representing the Dark Web, showing how the dark web has no identity and how it’s an unknown space
Credit: geralt, CC0, via Wikimedia Commons

In 2025, ShinyHunters were responsible for a cyberattack that exposed data of approximately 5.7 million customers of Australian airline Qantas. This breach started when a vishing (voice phishing) attack tricked a contact centre agent into granting access to a third-party platform.

After a ransom deadline had passed, the data was apparently released on both the dark web and the clear web, in October 2025.

Cyber security advisors warned that from this breach, it was likely leaked personal details, such as names, emails, phone numbers, dates of birth, home addresses, and frequent flyer numbers, would be used to send unsolicited text messages, emails, and phone calls that appeared to be completely genuine.


Image showing Qantas headquarters in Mascot - Credit: MDRX
Qantas headquarters in Mascot, Sydney, Australia
Credit: MDRX, CC BY-SA 4.0, via Wikimedia Commons

Media reports in September 2026 advised that Qantas was investigating reports of phishing attempts and WhatsApp messages, targeting Qantas Hotels customers: “The issue relates to guests who booked through Qantas Hotels and comes after data belonging to 5.12 million customers was compromised in a major cyberattack on the airline last year, …”.

A mid-2026 hack at Origin Energy, apparently by a disgruntled employee, resulted in a breach which compromised personal data, including names, phone numbers, and addresses, of over 900,000 current and former customers. To date, no specific scams or fraudulent transactions linked to this data have been officially confirmed or identified by authorities.


An image representing a data security breach - Credit: Blogtrepreneur
An image representing a Data Security Breach
Credit: Blogtrepreneur, CC BY 2.0, via Wikimedia Commons

However, after I recently gave a short presentation “Hackers are after you – how can you stop them ?” at a conference, a fellow attendee told me that her data was compromised, and in the few weeks since, she had been receiving various phishing emails.


Special Note: ShinyHunters hack FBI

In mid-September 2026, hacking group ShinyHunters apparently claimed to have stolen data for current and former FBI employees, as a response to an agency announcement about the group in May. On 29 September, the FBI made a public request for the group to “get in touch”, noting “we know how to find you…”

Research shows that FBI data has been hacked at least 13 times previously, from 2011 to March 2026. While most of these attacks were by cyber-criminal groups, at least three are attributed to state-sponsored Chinese groups, Russia’s Foreign Intelligence Service, and Iranian government proxies.


Scamming Operations are Highly Sophisticated

Whether state-sponsored or otherwise, today’s cyber-crime operations are usually particularly sophisticated and well-organised.

Along with other technology tools such as robo-dialling, voice over internet (VoIP), and caller ID ‘spoofing’, AI has enabled scammers to significantly extend their capabilities. This includes: voice cloning (from social media); deepfake images and videos (also from social media); carefully crafted text, free of spelling and grammatical errors; mirrored fake sites and portals; and AI chatbots.


A concept image of a hacker at work in a dark room - Credit: Microbiz Mag
A concept image of a hacker at work in a dark room
Credit: Microbiz Mag, CC BY 2.0, via Wikimedia Commons

Cyber-criminals also employ psychological manipulation techniques and strategies, to bypass rational thought and force quick, emotional reactions. Sometimes called “social engineering”, three core strategies are:

  • impersonation – scammers pretend to be authority figures, such as the tax office, a bank, the police, a city council, or else someone that you trust (including family)
  • urgency and FOMO – scammers claim an opportunity will pass unless you act quickly, or a fine payment is due immediately: the resulting panic shuts down logical thinking
  • emotional manipulation – such as fear and relief, or greed and hope: scammers invent a crisis, such as a hacked account, then offer an immediate fix if you give them your details; or else they promise huge rewards or easy investment profits to tempt victims

Many scammers are also adept at building trust by using friendly chat and fake favours (like romance or crypto fraud) over weeks to lower your guard. They may also employ a herd mentality approach, using fake reviews, or claims of “everyone else is doing it”, to make an investment or offer seem safe.

And for the ‘start-up’ scammer, help is readily available. A 2024 report from Time Magazine revealed that:
“AI has also given rise to online marketplaces selling hacker services, scam scripts, and other tools of deception.”
“Cybercriminals can buy and sell tutorials and scripts for scamming people, as well as victims’ personal information. For $US 500, you can purchase a live scamming class, 25,000 U.S. phone numbers, and instructions for sending spam links…”.


The Covid Pandemic was THE Big Catalyst


Image showing a corona cartoon from the covid pandemic – Credit: Sabrytoon
Corona cartoon – who doesn’t remember the early ‘20s lockdowns?
Credit: Sabrytoon, CC BY-SA 4.0, via Wikimedia Commons

It appears that cyber-scamming activities began to increase significantly following the onset of the 2019 covid pandemic.

Research shows that the pandemic made people lonelier and more isolated, which also made them more susceptible to fraud, particularly as more personal transactions were pushed online.

As almost the entire global population shifted their daily routines to the internet, the pool of potential victims was expanded. Amongst their targets, scammers were attracted to recipients of the economic stimulus packages and relief funds offered by numerous governments.


Image showing a view of Shwe Kokko Scam City, Myawaddy, Myanmar - Credit: Angshu2193
Shwe Kokko Scam City, Myawaddy, Myanmar – Shwe Kokko is a town on the Thailand border, in Myanmar’s Kayin State, that has been transformed into a massive, multi-billion-dollar hub for international cyber scams, illegal gambling, and human trafficking, which was built as part of China’s Belt-and-Road Initiative. A US Government release claims “Beijing has selectively cracked down on scam centers that target Chinese victims, leading Chinese criminal organizations to conclude that they can make greater profits with lower risk by targeting citizens of wealthy countries such as the United States.”
Credit: Angshu2193, CC BY-SA 4.0, via Wikimedia Commons

One of the post-covid outcomes in many parts of the world has been a growing distrust of and dissatisfaction with governments and authorities, for many reasons (including covid lockdowns). Evidence shows that people who are sceptical of authorities can often be ready to trust someone else – including a seemingly genuine stranger, who turns out to be a scammer.


Let’s Take a Look Inside a Scam Farm

Scam ‘farms’, or compounds, are nothing new. A UN News report of May 2025 noted that “…a Philippines scam farm that was shut down by the authorities in March 2024 ”. The farm had housed 700 workers, the majority of whom were ‘trafficked’, and were “…basically fenced off from the outside world ”.

The report also noted “It’s believed that hundreds of thousands of trafficked individuals of various nationalities are forced to carry out fraud in the centres located across Cambodia, Myanmar, Laos, the Philippines and Malaysia.” According to the UN Office on Drugs and Crime [UNODC]: “Southeast Asia is the ground zero for the global scamming industry.”


An image from inside a Ukrainian fraud call centre, shut down in 2021 by the National Police of Ukraine - Credit: National Police of Ukraine
Image from a Ukrainian fraud call centre, shut down in 2021 – according to the National Police of Ukraine, operators called citizens under the guise of bank employees and police officers. During the conversations, they extracted financial data and transferred the victims’ funds to controlled accounts. The monthly profit amounted to 1.5 million hryvnias ($AUD 48K, $US 34K).
Credit: National Police of Ukraine, CC BY 4.0, via Wikimedia Commons

From around the same time, a report by the 'Global Initiative Against Transnational Organised Crime' revealed how “Repurposed hotels, casinos, and private compounds across Cambodia, Laos, Myanmar and the Philippines have become centres of global fraud. These compounds are operated by organized criminal networks that exploit hundreds of thousands of people, many of whom are trafficked and forced to perpetrate online scams.”

A curious side-effect of the border conflict between Thailand and Cambodia of July-December 2025 was that it revealed a number of so-called scam compounds or ‘farms’. Following a visit to a scam compound in O’Smach (a small town in northern Cambodia, on the Thai border), in September 2026 Malaysia’s The Star newspaper reported:

  • the site contained 157 buildings, including 29 used for scam operations
  • the compound’s hospital was used to treat Chinese nationals holding senior positions in the scam operations
  • there were suspicions the hospital operating theatre had been used to remove organs from scam workers who failed to meet targets
  • there were mock police stations designed to impersonate law-enforcement agencies in several countries, including China, Indonesia, Brazil, Australia, Singapore and Vietnam
  • items viewed included scam scripts, police uniforms from different countries, replica interrogation rooms, and photographs depicting arrests, all intended to make the settings resemble genuine police premises

An image showing US President, Malaysian Prime Minister, Cambodian Prime Minister, and Thailand Prime Minister at the signing of the Kuala Lumpur Accord, 26 October 2025 - Credit: The White House
President Donald Trump, Malaysian Prime Minister Seri Anwar Ibrahim, Cambodian Prime Minister Hun Manet, and Thailand’s Prime Minister Anutin Charnvirakul at the signing of the Kuala Lumpur Accord, 26 October 2025 – the following month fighting resumed, until another ceasefire in December 2025
Credit: The White House, Public domain, via Wikimedia Commons

Separately, a 2024 UN video [10min 40sec], Scam Artist or Human Trafficking Victim? – Inside a Scam Farm, tells the story of a young Filipino woman, “Susan”, who went to work in Thailand, but was trafficked to a scam farm in Myanmar. The video also gives the viewer a tour of a scam farm in the Philippines, which had been raided by authorities, noting that there were [then] 402 known scam farms in the Republic.

Another UNODC report, from late 2025, noted: “But human trafficking into scam centres is no longer confined to one region. …while Southeast Asia remains a major hub, the model is increasingly spreading to the Middle East, Africa, Eastern and Southeastern Europe, South Asia, the Pacific and Latin America and the Caribbean.”


Meet With a Trafficked Scam Farm Worker

In an April 2026 report, a journalist from The Conversation records a meeting with a former scam farm worker, Akshit. From India, Akshit was well educated, spoke excellent English, and had worked in banks and call-centres. A high-paying job led him to Sihanoukville, a coastal city in southwest Cambodia.


Image showing a panorama view of Sihanoukville from Otres Beach - Credit: Kiensvay
A panorama view of Sihanoukville from Otres Beach
Credit: Kiensvay, CC BY-SA 3, via Wikimedia Commons

On arrival he was given a nice room in an apartment block, and a welcome bag. However, he soon found that he was now in a compound where, along with hundreds of other workers, his job was to sit at a computer, and convince ‘victims’ to invest in fake schemes or love interests. His recruiter had sold him for US$5,000 (±$AUD 7,000).

Controlled by a Chinese crime syndicate, workers operated in teams of eight, each led by a team leader, with a manager overseeing several teams. Akshit worked 15-hour days, seven days a week, texting victims in English and Hindi, targeting southern Indians. Work started at 10:30 AM and ended at 2 AM.

Workers followed a script: a “developer” sent texts to multiple prospects. When one became engaged, they were passed to a “chatter.” The chatter would exchange texts with the victim for three to four days, determining whether they’re interested in love or financial gain. They then passed the victim on to the “killer,” who sealed the deal, instructing the victim on how to transfer their funds.

Akshit’s team each had a target of $US 10,000 (±$AUD 14,000) per month. Those who made the target received $800; for more, the earnings grew on an increasing scale. Those who failed got less, or no, pay. Akshit estimated that 40 per cent [of the workers] in his compound were earning around $US 5,000 per month. The figure may be exaggerated, but some clearly had an interest in the scamming continuing.


Image showing a satellite view of countries of South East Asia - Credit: Google Earth
Satellite view of countries of South East Asia Credit: Google Earth

Since January 2026, hundreds of scam centres across Cambodia have been closed, leaving thousands of Chinese, South Asian, African and Indonesian workers on the streets of Phnom Penh, struggling to get home. Akshit was interviewed while waiting outside the Indian Embassy in Phnom Penh.


From Dream Paradise to Ghost City – a Scammer’s Delight

In 2016, China’s largest property developer, Country Garden, announced Forest City – a $US 100bn (±$AUD 140bn) mega-project that could house some 700,000 residents, under the Belt and Road Initiative. The location for this was a 14-sq-km (3,400-acre) artificial island in the southeast of Malaysia’s Johor State, on Singapore’s doorstep.


Image showing a map view of the location of Forest City - Credit: Google Maps
Map view showing the location of Forest City Credit: Google Maps

But a decade later, only 15% of the entire project had been built and, according to estimates, just over 1% of the total development was occupied, earning its local nickname “Ghost City”. However, while potential investors and tenants may have been put off by its isolated location, it has become a “golden city” for some people (but perhaps not the ones developers had hoped to attract!).

According to BBC reports: “In mid-July [2026], Malaysian police raided two alleged scam operations spread across 32 premises in Forest City, arresting 335 people and seizing assets worth about one million ringgit ($US 245,000/±$AUD 344,000), including 313 computers, 1,557 mobile phones, 17 laptops and 10 modems.”


Image of satellite view of Forest City artificial island - Credit: Google Earth
Satellite view of Forest City artificial island Credit: Google Earth

“From these two call centre hubs …. cryptocurrency syndicates ran investment and love scams targeting victims abroad, according to police.” The BBC also noted that one hub occupied 27 apartments across five storeys of a residential tower, while the other was spread between five bungalows.

Other details revealed in the report suggested these did not appear to have been scam “compounds” in the traditional sense. Rather, they were: “….almost white collar, reportedly staffed by local residents and sitting wall-to-wall with the homes of unsuspecting neighbours.” There was a likelihood they were probably staffed by criminals who had been driven out of Cambodia.

One local resident spoken to by BBC journalist Gavin Butler suggested the reason the scammers had set up in Forest City was because: “They have their own privacy…. Nobody comes here.”


Travel Scams are Rampant – Both on the Ground and Online

We all know that travellers face a multitude of scams, both as they plan and prepare for an adventure, and while they are adventuring along the way. Common travel conditions like jet lag, dehydration and fatigue, or a dose of illness, can seriously affect our “thinker”, making us vulnerable and quite susceptible to being scammed.


Image showing a Savings Bank Foundation Wi-Fi Hotspot (Germany) - Credit: Emes
Savings Bank Foundation Wi-Fi Hotspot (Germany) – Evil twin rogue wireless access points can mimic a legitimate public Wi-Fi network (such as official free Wi-Fi in transport hubs, cafes, or city squares) to intercept user data and steal login credentials
Credit: Emes, CC BY-SA 3.0, via Wikimedia Commons

Credit card fraud, hacked wi-fi, and dodgy taxi fares can happen at almost any destination, while pick-pockets and confidence tricksters can also make their play, especially at transport terminals and hubs. Even market-place vendors can get in on the act, surreptitiously swapping our purchased item/s for something bogus.

Other popular travel scams include: reservation hijacking, phoney flight cancellations, and fake QR codes. A more recent phenomenon has been the rise of fake travel websites, including fake listings on trusted sites like Booking.com. Along with ‘evil twin’ fake wi-fi access points, these lead to phishing messages and other inbound traffic that looks completely genuine.

Perhaps the most recent fake listing on Booking.com is the 10 Downing Street “Test”, made in September 2026 by the UK consumer group Which?. However, this is not an isolated event, with numerous similar instances on record. In July 2025, unsuspecting travellers had arrived at addresses on Australia’s Sunshine Coast, and in New Zealand’s Queenstown, after making bookings through Booking.com, only to find the real homeowners had never listed the property.


Image of Booking.com Campus Amsterdam - Credit: Mohamed Osama AlNagdy
Booking.com Campus Amsterdam Credit: Mohamed Osama AlNagdy, CC BY-SA 4.0, via Wikimedia Commons

In both instances, victims lost thousands of dollars after apparently paying money into a bank account provided by the “property owner” via the Booking.com app. There are no media reports to suggest a happy ending for either of the victims. Rather, from the New Zealand victims, a Stuff Newspaper Headline in May 2026 tells the story: ‘It’s just a lottery’: Couple’s long battle for Booking.com refund continues.


Other Security Breaches for Booking.com

Separately, in April 2026 Booking.com was subject to a data hacking breach. As Booking.com notified affected users, the compromised data included names, email addresses, phone numbers and details about past and present bookings, plus some messages about bookings.

This is not Booking.com’s first security incident. In 2018, criminals phished hotel employees and accessed data belonging to Booking.com customers. And in 2021, a breach exposed personal data from over 4,000 customers, along with hotel staff login credentials, which were used to access reservation systems, and to contact guests directly with fraudulent payment requests (reservation hijacking).


Image of Forest City by day featuring the very large prominent Carnelian Tower - Credit: YankeeHo
Forest City day view – the very large prominent tower at Forest City in Johor, Malaysia, is the Carnelian Tower. It stands approximately 198 meters (650 feet) tall with 45 floors. Unlike the uniform residential high-rises surrounding it, the tower features a distinct architectural design and was the centerpiece of the development.
Credit: YankeeHo, CC BY-SA 4.0, via Wikimedia Commons

While Booking.com has refused to disclose details, the 2026 breach appears to be larger in scope. For cyber security advisors, the new attack raises questions about whether lessons were learned from the earlier incidents. For a platform with over 100 million active mobile app users, and 500 million monthly website visits, the silence from Booking.com has been concerning for many.

Booking.com did warn affected users to watch for phishing attempts. Coincidentally, in the days following the breach, users of Reddit apparently reported receiving scam messages about specific bookings, including hotel names, dates, and reservation numbers. While there is no confirmation that any of these scams were directly connected to this breach, the pattern is definitely familiar.


Inside the Mind of the Cyber-Criminal


A 1920s image of various criminal brains - Credit: Pennsylvania State University Libraries
A 1920s image attempting to associate brain types to criminal behaviour – Credit: Pennsylvania State University Libraries, Public domain, via Wikimedia Commons

The majority of cyber-criminals are intelligent, highly skilled and very resourceful, making it difficult, but not impossible, to catch or anticipate them.

While most cyber-criminals are driven by financial gain as the primary incentive to launch a cyber-attack, some are driven by ideological motives. Many also relish the opportunity to outsmart cyber-defences, so they can brag about their exploits in dark web forums, as a form of self-advertising. Research suggests that around 30% of cyber-criminals are women.


Image showing a 3D view of Forest City residential towers - Credit: Google Earth
3D view of Forest City residential towers Credit: Google Earth

In acts of cyber-crime, the inherent physical and digital distance in online crime creates a psychological disconnect for the cyber-criminal, minimizing the inhuman impact of their actions. This enables the cyber-criminal to justify their actions in ways they might not if they had to face their victims in person.

The mind of the cyber-criminal is deeply calculating, with high awareness of human weakness, and yet entirely lacking in true emotional empathy. They view interaction with their victims as a game, such as chess, and are especially capable of exploiting psychological triggers like urgency, trust, emotions, and even curiosity.

Cyber-criminals are keenly aware that they do not want to be discovered or draw attention from the law. To that end, remaining anonymous is very important to the cyber-criminal; when no one knows who they are, they are emboldened to commit cyber-crime acts of all kinds.


Image showing a satellite view of Forest City beach complex - Credit: Google Earth
Satellite view of Forest City beach complex Credit: Google Earth

Cyber security researchers advise that many scammers operate with patience and precision, conducting deep research into a potential high-value mark, including using information scraped from social media to personalise attacks.

During this time, the scammer will exploit any human weaknesses they can detect in their victim to get as much information as possible, and to create an environment of trust. From there, they can deceive the victim, and then carry out their attack. The more personalised the scam, the more likely it is that the scammer’s attack will be successful.

However, in spite of the personalised nature of any exchanges with their victim, even when the scammer is also a victim (of human trafficking), they will rarely show any empathy towards their victims, as their safety (and survival) depends on their scam being successful.


Image showing 3D view of Forest City, including the prominent Carnelian Tower and the high-rise residential towers - Credit: Google Earth
3D view of Forest City showing both the prominent Carnelian Tower and the high-rise residential towers Credit: Google Earth

Recognising and Avoiding Scams vs Human Nature

Anyone can easily become a victim of an online crime.

The majority of scams are built on four basic qualities inherent in most human beings:

  • we want to help
  • we tend to trust people
  • it’s hard to say no
  • we like to be flattered

The common ‘give-aways’ that you are being scammed are:

  • requests or offers that have a sense of urgency
  • messages that trigger fear, hope, excitement
  • unexpected messages asking you to click a link
  • ‘out of the blue’ contact claiming authority (bank, police, tax office, utility provider)

The Australian National Anti-Scam Centre (NASC) advises to Stop. Check. Protect. to stay safe from scams:

  • Stop: don’t rush to make decisions about money or sharing personal details
  • Check: make sure the person or organisation you’re dealing with is real (search for independent contact details via official websites or apps)
  • Protect: if something feels wrong, the sooner you act, the better you can protect yourself

Image showing managers' accomodation at the raided scam farm in Bamban, north of the Filipino capital, Manila - Credit: UN Office of Drugs and Crime
Managers’ accomodation at the raided scam farm in Bamban, north of the Filipino capital, Manila. The scam farms have dormitories and cafeterias, but also a barber shop, medical clinic, massage spa, gambling room as well as a VIP karaoke bar for senior managers, where they could drink, sing and socialize in private rooms
Credit: UNODC, CC BY 2.0, via Wikimedia Commons

What to do If SH!T Does Happen

If you are scammed while travelling abroad:

  • call your bank immediately to freeze accounts or dispute transactions
  • make a report to local police, and ask for a copy of the report
  • call your travel insurer’s assistance line to register a claim
  • contact your nearest national embassy or consulate, to seek advice and ask if they can help
  • report the incident to your national scamwatch authorities to help track international scam trends
  • collect and retain all messages, receipts, and photos from the incident

UNODC video [11 min]:
Scam Artist or Human Trafficking Victim? – Inside a Scam Farm | Feature by the United Nations

https://webtv.un.org/en/asset/k1f/k1fvenmbg2



Good Luck –
Safe Travels – and
Be SMaRT out there!



NOTE:
This site is specifically designed for responsive display on a mobile device
On devices with wider screens, it will appear as a single, center-aligned column