The Rising Threat of Cybercrime Targeting Travelers
As international tourism surges, so too does the alarming risk of cybercrime aimed at individuals exploring the globe. Recent findings from a study involving NordVPN and Saily shed light on the expanding market for stolen travel documents lurking within the dark web.
Valuable Stolen Documents
The research highlights a troubling trend: sensitive travel information, including passports and loyalty accounts, can be purchased for surprisingly low prices. Scanned copies of global passports can sell for as little as $10, while more validated EU passports can command upwards of $5,000. Other items of interest include fake bank statements and hacked airline loyalty accounts, often trading for hundreds of dollars. Even hotel reservations from sites like Booking.com can be resold at significant discounts, priced around $250 or more.
Marijus Briedis, the Chief Technology Officer at NordVPN, emphasizes the concerning implications of these figures, stating that the prices displayed on the dark web underscore the vulnerability of travelers’ personal information, turning it into a profitable asset for cybercriminals.
How Travel Data is Compromised
Cybercriminals typically obtain travel documents through various straightforward but effective methods. Techniques such as malware implantation allow them to scan devises and cloud storage for sensitive information. Breaches that occur within airlines, visa agencies, and travel organizations further exacerbate the problem, leaking personal data that can be exploited.
Additionally, phishing schemes thrive as cybercriminals mimic official websites to trick unsuspecting users into uploading their passports and other personal documentation. Publicly accessible cloud folders with inadequate security settings also present easy targets for exploitation. Notably, physical documents like boarding passes, when lost or discarded at airports, can emerge as another source of risk.
Vykintas Maknickas, CEO of Saily, notes that travelers have reported increasingly sophisticated, AI-driven phishing scams. Examples include fake check-in sites that request selfies alongside ID documents, as well as fraudulent airport lounge and WiFi sign-in pages. As technology continues to evolve, the potential for convincing phishing attempts has grown, making it increasingly challenging for individuals to discern the genuine from the fraudulent.
The Golmine of Travel Documents
Travel documents possess unique value due to their high resale potential and ease of use. Many online platforms require merely a passport scan and selfie for identity verification—an obstacle that criminals can bypass using advanced deepfake technology.
Moreover, stolen passenger records often contain extensive personal details, including full names, dates of birth, passport numbers, and contact information. This trove of data enables a wide range of fraudulent activities, from identity theft to the opening of unauthorized accounts and social engineering attacks, where criminals leverage personal and travel specifics to deceive victims.
Briedis asserts that the accessible nature of stolen travel data makes it particularly attractive to hackers, as it allows for direct identity access with minimal barriers, amplifying both its value and risk.
Essential Digital Defense for Travelers
In light of these findings, both NordVPN and Saily advocate for immediate measures travelers can instigate to protect their data. Key recommendations include storing sensitive travel documents in encrypted digital vaults rather than on weakened cloud services. Additionally, vigilance against phishing attempts is crucial: users should meticulously verify website URLs before sharing any sensitive information.
Maknickas insists that maintaining a healthy skepticism serves as the best defense against modern social engineering tactics. By practicing critical thinking before responding to digital requests, travelers can fortify their personal security. If something raises suspicions, he encourages individuals to seek verification through alternate channels.
Briedis further recommends that travelers keep their devices regularly updated with antivirus software and utilize VPNs, especially when accessing public WiFi networks, to safeguard their online activities and impede malware attacks. Monitoring financial and loyalty accounts for unusual activity is equally essential. In the unfortunate event of lost or stolen documents, immediate reporting can help mitigate exposure.
Research Methodology
The invaluable insights provided in this study stem from data analyzed between June 10 and June 20, 2025, through NordStellar, a threat exposure management platform. Researchers meticulously examined dark web marketplaces and hacker forums where stolen travel documents and correlated data are published for sale. This analysis focused on the availability, pricing, and risks associated with travel document trafficking to help raise awareness, enabling travelers to take proactive steps in safeguarding their personal information.


