Travel Scams 2026: How to Spot & Avoid Tourist Traps

How I Got Scammed at the Colosseum (And How You Won’t)

Twenty years behind a camera taught me to spot fake lighting, fake setups, fake performances.

But somehow, I missed the fake ticket vendor outside Rome’s Colosseum.

The guy had a booth. Professional-looking laminated badges. Even a printed rate card. The sun was brutal, the line to the official ticket office snaked around the block, and I was already mentally framing my shots of the ancient amphitheater.

“Skip the line,” he said. “Same tickets, no wait.”

I handed him 50 euros.

Five minutes later, security at the entrance informed me my ticket was worthless. The vendor? Gone. My money? Gone. My confidence in spotting scams? Obliterated.

That moment—standing there with a counterfeit ticket while a security guard looked at me with practiced pity—taught me more about travel fraud than any blog post ever could.

That $50 mistake cost me more than money—it forced me to rebuild how I approach every travel transaction. Here’s the framework I wish I’d had outside the Colosseum. If you want the broader planning discipline behind it, the trip planning guides hub is where the rest of it lives.

TL;DR: How to Outsmart 99% of Travel Scams

Already been scammed? Skip to the five-step recovery protocol.

  • Verify the URL: Never click links in travel alert texts; go to the official site manually.

  • Tug the ATM: If the card reader moves, it’s a skimmer.

  • The Payment Rule: If they won’t take a credit card (insisting on Zelle, Wire, or Crypto), it’s 100% a scam.

  • Three-Source Check: Before booking anything, verify on Google Reviews + Reddit + BBB.

  • Trust Your Gut: That uneasy feeling? That’s thousands of years of threat detection. Listen to it.

Quick note: Some links in this article are affiliate links. If you buy something through them, I get a small commission at no extra cost to you. I only recommend tools I actually use. If something’s garbage, I’ll tell you—commission or not.

The Problem: Travel Scams Are Evolving Faster Than Our Defenses

Travel scams are no longer run by street hustlers. Organized networks now use AI-generated booking sites, deepfake voice calls, and psychological pressure to hit travelers exactly when they’re most distracted. The industry cost consumers $1 trillion globally in 2024.

Here’s what nobody tells you: they’re no longer run by desperate street hustlers. They’re sophisticated operations using AI-generated websites, deepfake voice calls, and psychological manipulation that would make a filmmaker jealous.

Scams cost consumers $1 trillion globally in 2024, according to the Joint Economic Committee—and travel is a major target. That’s not a typo. One trillion.

Scam Reality: Travel fraud spikes 18% during summer peak season and 28% during winter holidays, according to the Mastercard Economics Institute. If you’re traveling in July or December, assume you’re a target—and act like it.

And here’s the kicker: one in five Americans has been scammed while booking travel. These aren’t just “unlucky” people. They’re regular travelers like you and me who made one small mistake.

The scams I encountered while filming documentaries across three continents aren’t the old-school pickpocket tricks. They’re refined, tested, and designed to exploit the exact psychology that makes us good travelers: trust in humanity, desire for authentic experiences, and willingness to take reasonable risks.

The Underlying Cause: Why Scammers Target Travelers

Scammers love tourists for three reasons:

  1. You’re in an unfamiliar environment. You don’t know what’s normal. That “standard taxi fare” or “typical tour price”? You have no baseline.

  2. You’re making decisions quickly. When you’re tired from a flight, overwhelmed by a new city, or rushing to catch a train, your decision-making quality drops. Scammers create urgency: “last seats,” “special today only,” “about to close.”

  3. You’re unlikely to pursue legal action. You’ll be gone in a week. Even if you report it, what’s going to happen? Nothing. Scammers know this.

While at a film festival in Bangkok where Going Home was screening, I fell for a classic: the “broken meter” tuk-tuk driver who quoted us 100 baht for a three-minute ride, then demanded 500 when we arrived. I paid because I was in a rush, exhausted, and arguing in broken Thai over $12 USD seemed pointless.

That’s exactly what they counted on.

Documentary-style photo of a location scout's hands spread across a folding table covered with printed photos of potential shoot locations. Several photos are visibly doctored — obvious sky replacements, unrealistic saturation. A red pen circles one. Morning light through a café window, coffee cup in the corner of the frame. Film set context — a light meter and notebook sit nearby.

The Solution: The Location Scout Protocol

The Location Scout Protocol is a five-step verification framework borrowed from film production, adapted for travel. Run each step before trusting any vendor, booking, or stranger with a “deal.”

After getting burned in Rome, I started approaching travel with the same scrutiny I use when scouting locations. On set, if something doesn’t look right, we investigate. Same principle applies here.

I call it the Location Scout Protocol—four checks, plus a fifth that ties them together, before I trust any vendor, booking, or stranger with a “deal.”

Common Tourist Mistake: Assuming that a professional-looking booth, uniform, or badge means the vendor is legitimate. Outside the Colosseum, the scam vendor had all three. The tell wasn’t what he had — it was that his booth sat ten feet from the official line, and his price was just low enough to feel like a shortcut.

Here’s what actually works:

1. The “Too Perfect” Test

If a travel deal looks flawless—perfect photos, perfect grammar, perfect reviews—that’s the tell. Real businesses have small imperfections. Fake ones are assembled from templates.

During pre-production, if a location scout shows me photos that look magazine-perfect with no visible flaws, I get suspicious. Same logic applies to travel deals.

AI-generated travel scams are now creating entire fake booking sites with stolen photos and fabricated reviews. McAfee reported a 900% surge in AI travel scams in 2025. These sites look flawless—perfect grammar, professional design, compelling testimonials.

What to check:

  • URL irregularities (Booklng.com instead of Boooking.com)

  • Domain age (use a WHOIS lookup—legit sites have years of history)

  • SSL certificate (click the padlock—it should be issued to the company you think you’re visiting)

  • Reverse image search the property photos (often stolen from real listings)

2. Payment Method as the Universal Tell

Legitimate businesses accept credit cards. Scammers push wire transfers, crypto, gift cards, Zelle, and Venmo because those payments can’t be reversed. If a vendor won’t take a card, that’s the scam identifying itself.

I’ve filmed in 15 countries. I’ve paid for permits, locations, crew meals, and equipment rentals in multiple currencies. Know what legitimate businesses always accept? Credit cards.

Know what scammers prefer? Wire transfers, cryptocurrency, gift cards, Venmo, or Zelle for large amounts.

Why? Credit cards have fraud protection and can be disputed. Wire transfers and crypto are irreversible.

Important note on contactless payment fraud: While tap-to-pay is generally secure, scammers have developed devices that can skim contactless card data in crowded areas. Keep cards in RFID-blocking wallets only if you use contactless payments frequently in high-risk environments. Otherwise, the bigger risk is the payment method itself.

If someone insists on payment methods that can’t be traced or reversed, that’s not a red flag. That’s a siren.

Tools I actually use:

  • Privacy.com virtual cards (Create one-time-use card numbers for sketchy bookings. If it’s a scam, they get a dead card number. The $10/month paid plan is worth it for peace of mind.)

  • Credit cards with travel fraud protection (I use the Chase Sapphire Reserve—yes, it has an annual fee, but when I had a fraudulent charge in Istanbul, they resolved it in one phone call)

Worth It?: Privacy.com pays for itself if you book through unfamiliar vendors more than a couple times a year. Skip it if you only book through Booking.com or Expedia — their platform-level buyer protection does most of the same work for free.

Keep it Real: Privacy.com‘s free tier limits you to 12 cards per month. If you’re booking a complex trip with multiple vendors, you’ll hit that limit fast. The UI is also clunky—it takes three clicks to generate a card when it should take one. But for sketchy bookings? Invaluable. Who shouldn’t buy it: People who only book through major platforms like Expedia.

I use the same kind of verification skepticism I developed testing travel gear for this site—if something seems off about the materials, construction, or marketing claims, I dig deeper until I’m satisfied.

Simple vertical ladder graphic, six rungs. Top rung green (credit card / disputed at bank), middle rungs amber (PayPal Goods & Services, Zelle/Venmo for small amounts), bottom rungs red (wire transfer, crypto, gift cards — no reversal possible). Each rung gets a one-line label. No brand logos.

3. The Three-Source Verification Rule

Before booking anything outside a major platform, verify across three independent sources: Google Reviews, Reddit, and the Better Business Bureau or TrustPilot. One good review means nothing. Three consistent sources mean something.

When I’m researching camera gear, I never trust one review. I check YouTube, Reddit, and specialty forums. Travel bookings deserve the same rigor.

Before booking anything outside major platforms:

  • Check Google Reviews (look for patterns, not individual 5-stars)

  • Search Reddit for “[company name] scam”

  • Verify on Better Business Bureau or TrustPilot

Real example: While prepping for The Camping Discovery shoot, I almost booked a “filmmaker-friendly” Airbnb in Joshua Tree that had glowing reviews and perfect photos. A Reddit search turned up multiple posts about bait-and-switch—people would arrive to find a different, worse property. The host would offer a “partial refund” to switch or tell them to cancel (losing their money). We booked elsewhere.

That same research discipline applies to trip planning generally — the 48-hour Seattle guide was built on repeated visits and repeated mistakes, not a single weekend turned into a blog post.

4. The Direct Contact Bypass

Never click a link in an unexpected travel email or text. Open a new browser window, type the official URL manually, and log in directly. Phishing works because the link looks right — bypassing it breaks the entire scam.

Got an email saying your hotel reservation was cancelled? A text about a flight delay?

Never click the link.

This is how phishing works. The email looks legitimate—correct logo, professional formatting, urgent language. But the link goes to a fake site that steals your credit card info.

Instead:

  1. Open a new browser window

  2. Type the company’s URL manually (or use a saved bookmark)

  3. Log into your account directly

  4. Check if the issue actually exists

I learned this the hard way when I got a text saying my credit card would be charged $500 unless I “verified” my reservation by clicking a link. The text looked like it came from Booking.com. It wasn’t. The link went to “boooking-verify.com“—notice the extra “o”.

5. Trust the Hesitation

If a deal requires you to decide right now or lose it, that’s the tell. Legitimate operators have inventory — they can hold a room or ticket while you verify. Manufactured urgency is the scammer’s primary weapon.

This is the step that ties the other four together, and it’s the hardest one to follow because it doesn’t feel like a rule—it feels like doubt.

Legitimate operators have inventory. They can hold a room, a ticket, a rental for another hour while you check three sources or call your bank. Urgency is manufactured because rushed decisions are bad decisions, and scammers know that better than anyone in sales.

When something feels off and you can’t articulate why, that feeling is the fifth check running in real time. Walk away, sleep on it, come back tomorrow. If the deal is gone, it was never real.

Implementing the Solution: Scam-by-Scam Defense Strategies

What follows is the specific scam, where it clusters, and the exact defense—organized so you can skip to the one that matters to your trip.

Taxi & Tuk-Tuk Overcharges

Taxi and tuk-tuk overcharges are the most common tourist scam in Bangkok, Rome, Paris, Istanbul, Mexico City, and Barcelona. The tell is a driver claiming the meter is broken and quoting a flat rate—legitimate taxis run the meter. Use a ride-hailing app, or insist on the meter and walk away if they refuse.

WHERE IT HAPPENS: Bangkok, Rome, Paris, Istanbul, Mexico City, Barcelona

THE DEFENSE:

  • Use ride-hailing apps (Grab in Southeast Asia, Uber elsewhere)

  • Before entering, screenshot the estimated fare

  • If the driver insists on cash-only or won’t use the meter, walk away

  • Pro tip: In Bangkok, I use the BTS Skytrain + taxi combo. Take the train to the nearest station, then grab a short taxi ride with the meter running. Saves money and reduces scam risk.

Tools that help:

  • Rome2Rio (Free app that shows realistic transport costs between locations—if your driver’s quote is 3x higher, you know something’s wrong)

  • Google Maps (Shows fare estimates for different transport options)

Keep it Real: Ride-hailing apps surge-price aggressively during peak hours. Sometimes the “scam” taxi is actually cheaper than a legitimate Uber at 2x surge. The difference is you know the Uber price upfront. Who shouldn’t use this: In cities where ride-hailing is banned or heavily restricted (parts of Italy, Germany), you’re stuck with traditional taxis—just ensure the meter runs.

ATM Skimming & Card Cloning

ATM skimming is a two-part scam: a reader overlay steals your card data, a hidden camera captures your PIN. The defense is physical—tug the card reader before inserting, cover the PIN pad, use only ATMs inside bank branches.

WHERE IT HAPPENS: Tourist-heavy areas worldwide—near Colosseum, Eiffel Tower, major train stations

THE DEFENSE:

  • Only use ATMs inside bank branches (not street-facing machines)

  • Physically tug on the card reader before inserting your card—genuine hardware is industrial-grade and won’t move

  • Cover the PIN pad with your other hand (blocks cameras)

  • Check your account daily via mobile app

  • Set up transaction alerts for any charge over $1

For general ATM habits beyond skimming — when to withdraw, how much, which networks to avoid — the travel safety tips that actually work guide covers the broader playbook.

The technical bit, in plain English: A chip card generates a brand-new, one-time code for every single transaction. Even if a scammer captures that code, it’s useless the second you walk away—it can’t be replayed. A magnetic stripe doesn’t do that. It stores your card data in the same static format every time, which means a skimmer can copy it once and clone it onto a blank card indefinitely. That’s the entire vulnerability: chip transactions expire on use, stripe transactions don’t. Many ATMs and overseas merchants still default to the stripe reader because it’s faster or the chip reader is broken—that’s the exact moment a skimmer gets what it needs.

Tools I use:

  • Charles Schwab Checking (No foreign transaction fees, unlimited ATM fee reimbursement worldwide. This has saved me hundreds in fees across Europe and Asia.)

  • Real-time transaction alerts via my banking app (Every charge over $1 sends a push notification)

Keep it Real: Schwab requires opening both checking and brokerage accounts, which means more paperwork and maintenance. Their customer service phone wait times can hit 20+ minutes. But for international travel? The fee reimbursement alone has saved me $400+ per year. Who shouldn’t use it: People who only travel domestically or twice a year—the setup hassle isn’t worth it.

Fake Booking Sites & Phishing

Fake booking sites clone the exact look of Booking.com, Expedia, and airline sites. They surface via sponsored Google ads and social media. The tell: the URL is off by one letter, or the deal is 50% below every other listing.

WHERE IT HAPPENS: Everywhere online, especially via sponsored Google ads and social media

THE DEFENSE:

  • Never click travel ads—go directly to the company website

  • Check the URL carefully (Booklng.com vs Boooking.com)

  • Look for HTTPS and verify the SSL certificate

  • If the deal is 50%+ cheaper than other sites, it’s fake

  • Use official apps, not mobile websites

  • Enable two-factor authentication (2FA) on all booking accounts

  • For digital nomads: Save verified booking sites as browser bookmarks to avoid typosquatting domains

Real example: A DP on one of my shoots got an email claiming his flight was cancelled. The email had Delta’s logo, fonts, color scheme. The link went to “delta-air-lines-helpdesk.com“—not delta.com. He clicked, entered his confirmation number and credit card to “rebook.” Two hours later, $1,200 in charges. Delta had no record of the email.

Keep it Real on booking platforms: Booking.com vs Expedia vs Direct: I’ve tested all three. Booking.com has better cancellation policies (free cancellation is standard). Expedia bundles hotel+flight for savings. Booking direct with chains gets you loyalty points. The “best” depends on your trip. None are scams, but prices vary by $30-100 for the same room.

I used this same comparison approach when researching hotels for trips I’ve covered—verified reviews matter more than star ratings.

The “Free Gift” / Friendship Bracelet Scam

The bracelet scam is a reciprocity play. Someone ties a bracelet on your wrist before you can refuse, then demands payment. The defense is physical: hands in pockets, no eye contact, keep walking. Don’t accept the “gift” at all.

WHERE IT HAPPENS: Paris (Sacré-Cœur, Eiffel Tower), Rome (Spanish Steps), New York (Times Square), Barcelona

THE DEFENSE:

  • Keep your hands in your pockets in touristy areas

  • Say “no” loudly and keep walking

  • Don’t make eye contact with street vendors

  • If they grab your wrist, shake it off immediately—do not engage

Behind the psychology: These scammers use the “reciprocity principle”—once they’ve “given” you something, you feel obligated to pay. That’s why they insist on tying it on you first. Break that chain by refusing the “gift” entirely.

While filming Elsa in Paris, I watched this happen to a couple at Sacré-Cœur. A man insisted on tying string bracelets on both their wrists while saying “friendship, good luck.” Then demanded 20 euros per bracelet. When they refused, two more men appeared. They paid to avoid confrontation.



Fake Tours & Travel Packages

Fake tour operators list real-looking packages on social media and Google sponsored results, take payment, and disappear—or deliver a tour that looks nothing like the listing. The defense is platform-based booking and license verification.

WHERE IT HAPPENS: Social media ads, Google search results (especially sponsored listings)

THE DEFENSE:

  • Book tours through established platforms (GetYourGuide, Viator)

  • Check Google Reviews for the specific tour, not just the company

  • Search “[tour name] scam” on Reddit

  • Look for refund policies and physical addresses

  • Verify business licenses (in the US, check Better Business Bureau)

Keep it Real on tour platforms: GetYourGuide: Better for European tours, easy cancellation, verified reviews. Commission structure means tour operators price 15-20% higher than direct booking. But the fraud protection is worth it. Viator (owned by Tripadvisor): More options in Asia and Latin America. Similar pricing to GetYourGuide. Interface is clunkier. Who shouldn’t use these: If you’re booking a major museum (Louvre, British Museum), buy directly from their official site—saves the platform fee.

The Distraction Theft Scam

Distraction theft is a two-person operation: one creates a scene (a spill, a bump, a fake argument), the other steals your bag or wallet while you’re looking the wrong way. The defense is bag placement and refusing to engage with the distraction.

WHERE IT HAPPENS: Barcelona, Buenos Aires, crowded markets and metros worldwide

THE DEFENSE:

  • Use a crossbody bag with the zipper facing your body

  • Keep phone and wallet in front pockets (not back pockets or backpack)

  • If someone spills on you, step away immediately and check your belongings

  • Be hypervigilant in crowded areas, especially metro stations

Gear I use: Pacsafe Metrosafe Crossbody (Anti-slash fabric, locking zippers, RFID protection. Has saved my gear in multiple sketchy situations. Around $80.)

Keep it Real: The Pacsafe bag screams “I’m a paranoid tourist with expensive stuff.” It’s bulky and you can’t access your phone quickly. But when I’m carrying camera equipment through crowds, that tradeoff is worth it. Who shouldn’t buy it: Solo travelers in low-risk areas where a regular bag works fine.

For longer trips where weight matters, I apply the same lightweight backpacking principles I use on film shoots—every item must justify its presence. If you’re building a gear kit that’s meant to survive real trips, the travel gear that survives real trips hub is where I keep the rest of the recommendations.

Fake Currency Exchange

Street currency exchange offers better rates than the bank because the bills are counterfeit or the count is short. The defense is exchanging only at banks or official airport counters, and counting every bill before leaving the window.

WHERE IT HAPPENS: Bali, Vietnam, Eastern Europe, tourist areas worldwide

THE DEFENSE:

  • Only exchange currency at banks or official exchange counters in airports

  • Count your money before leaving the counter

  • Learn what genuine local currency looks like (feel, security features)

  • Use ATMs instead of cash exchanges

  • Check the current exchange rate on XE.com before exchanging

Real example: During Dissociative Identity location scouting in Bali, a crew member exchanged $200 USD at a street vendor. Handed back what looked like 2.8 million rupiah. Except half the bills were counterfeit. By the time we realized, the vendor was gone. We ate that loss.

The “Closed Attraction” Redirect

A stranger near a major attraction claims it’s closed today and offers to take you somewhere “better.” The attraction is open. The alternative is a commission stop. The defense: walk to the entrance and verify yourself.

WHERE IT HAPPENS: Bangkok, New Delhi, Cairo, major tourist attractions worldwide

THE DEFENSE:

  • Check attraction hours on the official website before you go

  • If someone tells you it’s closed, walk to the entrance yourself and verify

  • Don’t accept recommendations from random people on the street

  • Ignore anyone who approaches you unsolicited near tourist sites

Vacation Rental Bait-and-Switch

A listing with perfect photos and glowing reviews turns out to be a different, worse property—or doesn’t exist at all. The defense is platform-based payment and video verification with the host before booking.

WHERE IT HAPPENS: Any city with vacation rentals, especially popular tourist destinations

THE DEFENSE:

  • Only book through established platforms with payment protection (Airbnb, VRBO)

  • Check that reviews mention specific property details from the photos

  • Be suspicious of “too good to be true” prices

  • Request a video call with the host to see the property

  • Pay through the platform, never via direct wire transfer

Red flags:

  • Host insists on moving payment off-platform “to save you fees”

  • Recently created account with few or no reviews

  • Property listed on multiple platforms at wildly different prices

  • Host can’t answer specific questions about the neighborhood

  • Photos look professionally staged with no “lived-in” elements

The “Police” Who Want to See Your Wallet

Fake police flash a badge and demand to inspect your cash for counterfeits or “verify” your ID. Real police don’t do this. The defense: ask to walk to a station together, and keep your wallet where it can’t be quickly handed over.

WHERE IT HAPPENS: Las Ramblas (Barcelona), near Termini Station (Rome), Zócalo (Mexico City)

THE DEFENSE:

  • Real police don’t ask to see your cash, ever—that’s not a verification procedure that exists

  • Ask to see their ID, then ask to walk together to the nearest police station

  • If they hesitate or back off, you have your answer

  • Keep your wallet in a front pocket or zipped bag so there’s nothing quick to hand over even under pressure

Documentary-style photo of a traveler photographing a mid-range sedan in a rental car lot at an airport in Southern Europe. Overcast morning, wet asphalt reflecting flat gray sky. The traveler is crouched at the front quarter panel, phone held up to capture the fuel gauge through the windshield. Rows of identical cars stretch behind. No visible brand names or license plates. Mid-frame composition, not centered.

Rental Car Scams

Rental car scams come in three flavors: fuel gauge manipulation, damage claim extortion, and mandatory “insurance” upsells not in your original booking. The defense is documentation before you drive off the lot—photograph everything, timestamps visible.

WHERE IT HAPPENS: Any rental counter, especially smaller local agencies at airports in Mexico, Southern Europe, and Southeast Asia

THE DEFENSE:

  • Photograph the car from every angle before driving off the lot—all four sides, the fuel gauge, the odometer—with your phone’s timestamp visible

  • Do the same walkaround again at return, before handing over the keys

  • Decline add-on insurance at the counter if your credit card already covers rental collision (check before you travel, not at the counter)

  • If “mandatory insurance” wasn’t in your original booking confirmation, it’s not mandatory—it’s a markup

Hotel Front Desk Phishing Calls

Your room phone rings. The caller claims to be the front desk, says your card was declined, and asks you to verify the number. It’s not the front desk. The defense: hang up and call the desk directly from the number on your key card or booking confirmation.

WHERE IT HAPPENS: Hotels worldwide—the call can come from inside the building, using the hotel’s actual internal phone system

Doorman Mirror: After enough hotel-door conversations, you learn the front desk almost never calls your room about a billing problem — they wait for you to come down and sort it at the desk. That’s the tell before the tell.

THE DEFENSE:

  • Hang up. Don’t verify anything on that call.

  • Call the front desk yourself, using the number on your key card or booking confirmation—not by pressing redial

  • Walk down and ask in person if you’re unsure

  • No legitimate front desk needs your full card number read back to them over the phone; if there’s a real billing issue, it can be resolved in person or through the booking platform

Where the Scams Cluster: A Destination Quick-Reference

Seven destinations account for the bulk of the scams in this article. Use the table to see which scam is most common where you're going, the tell, and the one-line defense.

Destination Most Common Scam The Tell The Defense
Rome Fake ticket vendors Booths/vendors near the official line, "skip the wait" pitch Buy only at the official counter or verified site; never a street vendor
Bangkok Tuk-tuk overcharges, closed-attraction redirect "Meter's broken," or a stranger claims the attraction is closed Use Grab, screenshot the fare first; verify closures yourself at the entrance
Paris Friendship bracelet scam Someone ties something on your wrist before you've agreed to anything Hands in pockets, don't engage, keep walking
Barcelona Distraction theft, fake police A spill or commotion, or someone flashing a badge and asking for cash Crossbody bag zipped to your body; real police never ask to see your wallet
Bali Fake currency exchange Street-vendor rates better than the bank Exchange only at banks or airport counters; count your money before leaving
Istanbul Taxi overcharges Meter "not working," inflated flat rate offered instead Insist on the meter or use a ride-hailing app
Mexico City Taxi overcharges, fake police Unmetered "tourist rate," or a badge-flash demanding ID and cash Hail through an app; ask any "officer" to walk to a station


Side-by-side macro photograph. Left: legitimate QR code printed directly on a parking meter surface. Right: scam QR code sticker pasted over the original, with the peeling corner and misalignment exaggerated slightly for visibility. No labels in the image itself — the caption handles the explanation.

NEW 2026 Threat: QR Code Phishing (“Quishing”)

Quishing is a 2026 escalation: scammers paste fake QR codes over legitimate ones at parking meters, restaurant tables, and hotel check-ins. The code looks identical. The defense is physical inspection and URL preview before any payment.

The scam: Scammers paste fake QR codes over legitimate ones on restaurant menus, parking meters, hotel checkout stands, and tourist information kiosks. When you scan the code, it directs you to a payment site that steals your credit card info or installs malware on your phone.

WHERE IT HAPPENS: Major cities worldwide, especially at parking meters and restaurant tables

THE DEFENSE:

  • Before scanning any QR code, check if it’s a sticker placed over the original

  • Look for signs of tampering—peeling edges, misaligned placement

  • For parking and payments, use official apps instead of QR codes

  • Check the URL preview before the page loads (most phones show this)

  • Never enter credit card info directly from a QR code—use contactless payment methods instead

  • For restaurants, ask for a physical menu rather than scanning a table QR code

Why this works: QR codes are impossible for humans to “read” visually. A scammer can generate a code that looks identical to the real one. The FBI issued a warning about quishing in late 2025 after a wave of parking meter scams cost tourists over $2 million in Los Angeles alone.

Pro tip: I now photograph legitimate QR codes when I check into hotels or park in lots, so I can compare if the code looks different later.

What to Do If You’ve Already Been Scammed

If you’re reading this section instead of the rest, you don’t need the framework right now—you need the next five steps.

  1. Contact your bank or card issuer first, not your insurer. Dispute windows are time-sensitive, and your bank can often freeze or reverse a charge faster than anyone else in this list can help you.

  2. File a police report, even if you know nothing will come of it. You’ll need the report number for insurance claims and, if a phone or documents were involved, for carrier or embassy paperwork.

  3. Contact your embassy or consulate if you’re abroad, especially if your passport was taken. They can expedite replacement travel documents faster than you’d expect.

  4. Document everything—screenshots, emails, receipts, the URL of any fake site. Timestamps matter if you escalate to a dispute or a report.

  5. Report it to the FTC at reportfraud.ftc.gov. It’s US-specific, but it feeds into international scam-tracking databases. Also report the vendor to whatever platform was involved (Airbnb, Booking.com, etc.)—even if they can’t refund you, it flags the account for the next traveler.

None of this undoes the loss. But it’s the difference between eating it quietly and giving yourself a real shot at getting some of it back.

travel scams infographic

FAQ: Outsmarting Travel Scams in 2026

Are QR codes in restaurants and parking lots safe to scan while traveling?

Be cautious of “quishing” (QR phishing). Scammers often paste fake QR code stickers over legitimate ones at outdoor cafes or parking meters to redirect you to fraudulent payment sites. Always verify that the sticker isn’t peeling or layered, and whenever possible, type the URL manually or use an official parking app.

Lock it down first, ask questions later. Use Find My iPhone or Find My Device to remotely lock and wipe it immediately—don’t wait until you’re back home. Call your carrier to suspend the SIM so nobody’s racking up charges on your line. Then, from a different device, change your passwords for email, banking, and anything with saved payment info. File a police report even if you know they’ll never catch anyone; you’ll need the report number for insurance and any carrier claims. If you had contactless payment loaded on the phone, call your bank and freeze the card too.

For casual browsing, mostly. HTTPS already encrypts the connection between you and the site, so scrolling Instagram on airport Wi-Fi isn’t the risk it was ten years ago. The risk shows up when you’re doing anything that touches money—online banking, entering a credit card, logging into a work account. For that, use your phone’s hotspot instead of the shared network, or run a VPN if you’re stuck. I use NordVPN for exactly this: banking or booking on hotel Wi-Fi, nothing else. Skip the public charging stations too—use your own charger and outlet, not a shared USB port.

Usually not, and this trips people up. Standard travel insurance covers things like trip cancellation, medical emergencies, and lost luggage—not money you handed over willingly, even if you were deceived into handing it over. If a fake ticket vendor takes your cash, that’s on you and your bank, not your insurer. Your first call after getting scammed should be your bank or card issuer, not your travel insurance company. Some premium credit cards include purchase protection or fraud guarantees that cover more than basic travel insurance does—check what’s already built into the card you’re using before buying a separate policy.

Anything you can’t dispute or reverse. Wire transfers, cryptocurrency, gift cards, and person-to-person apps like Zelle or Venmo for large amounts are the tells—all four move money in a way that can’t be clawed back once it’s sent. Credit cards can be disputed with your bank; wire transfers and crypto basically can’t. If a vendor won’t take a credit card and pushes you toward one of these instead, that’s not a red flag. That’s the scam telling you what it is.

Book through a platform with payment protection—Airbnb or VRBO, not a direct wire transfer to a “private owner.” Then check that the reviews mention specific details from the listing photos, not generic praise. Ask the host for a quick video call and get them to show you the balcony view or the street outside; if they hesitate or make excuses, that’s your answer. A host pushing you to pay off-platform “to save fees” is the single biggest red flag in this category—platforms exist specifically to protect that payment, and moving off them removes the protection on purpose.

The Verdict: What Actually Works vs. Security Theater

After years of testing travel security products, three are worth paying for and three aren’t. The best defense—skepticism, verification, walking away—costs nothing.

Worth the investment:

  • Virtual credit cards for online bookings (Privacy.com)

  • Schwab checking account for international ATM use

  • A crossbody anti-theft bag for high-risk areas

  • Transaction alerts set to $1+ threshold

  • VPN for public Wi-Fi (I use NordVPN—$4/month, works reliably)

Worth It?: Most “travel security” gear is priced for anxiety, not for outcomes. The three tools on the “worth it” list are the ones that have actually saved me money or stopped a scam in motion. Everything else, the free version of skepticism outperforms.

Keep it Real on VPNs: Most “travel security experts” push VPNs hard. Truth? Unless you’re accessing banking or email on public Wi-Fi, you probably don’t need one. HTTPS already encrypts your connection. VPNs add security but also slow your connection by 20-40%. I use NordVPN when booking flights or checking bank accounts on hotel Wi-Fi, but not for casual browsing. Who shouldn’t buy it: If you only access already-encrypted sites (https) on hotel Wi-Fi, save your money.

Not worth it:

  • RFID-blocking wallets (RFID theft is theoretically possible but virtually never happens)

  • Travel insurance from third-party brokers (get it, but buy directly from the insurer, not through a “comparison” site that adds markup)

  • “Travel security” courses (the free State Department travel advisory site has better, updated info)

The absolute best defense is free: skepticism, verification, and willingness to walk away from deals that feel wrong.

Wrap-Up: Trust Your Gut (It’s Calibrated from Thousands of Years of Evolution)

The Colosseum ticket scam cost me 50 euros and my pride. But it taught me something valuable: the same intuition that tells me a shot is off or an actor’s performance isn’t authentic works for spotting scams.

When that vendor offered to “save me time,” something felt wrong. But I ignored it because I was hot, tired, and impatient.

Every scam I fell for afterward—the Bangkok tuk-tuk, the Bali currency exchange, the phishing email—followed the same pattern. I ignored the small voice saying “this doesn’t add up.”

Your gut is pattern-matching based on thousands of years of evolutionary threat detection. When something feels off, it usually is. That hesitation isn’t paranoia. It’s your brain processing signals your conscious mind hasn’t assembled yet.

The scammers rely on you suppressing that voice. They create urgency, manufacture scarcity, and pressure you into deciding before thinking.

The best travel security tool you have is this: pause. Verify. And if it still feels wrong, walk away.

Trust that. It’s served humans well for millennia. It’ll serve you well in Rome.


As a member, you now get better savings when you book direct.

soho international film festival theatre 2024

📌 Affiliate Disclosure

PeekAtThis.com participates in the Amazon Services LLC Associates Program and other affiliate programs, including B&H Photo, Adorama, CJ, and ClickBank. If you purchase through links on this site, we may earn a small commission at no additional cost to you. These commissions help support the site and allow us to continue creating free content, reviews, and tutorials.

If this article helped you avoid an expensive mistake, discover a better piece of gear, or learn something new, consider sharing it with someone who might benefit from it too.

📌 Don’t forget to bookmark PeekAtThis.com and save any useful guides for future reference.

About the Author

Trent Peek is a filmmaker, writer, and producer based in Victoria, BC, and the founder of PeekAtThis.com. His production credits include set decoration on Netflix’s Maid, and writing/directing Going Home (2024 Soho International Film Festival) and Noelle’s Package (48-hour festival winner, shot on smartphone). He’s also a former President of Cinevic, Victoria’s Society of Independent Filmmakers, and works as a doorman at a four-star hotel — a job that’s taught him as much about reading people under pressure as any film set has.

When he’s not writing articles, testing gear, or working on film projects, Trent enjoys traveling, reading, exploring new technology, and developing future film ideas — many of which may never leave the notebook stage.

P.S. Writing in the third person still feels weird.

🎙️ Featured Interview

Trent recently appeared on the Pushin Podcast — listen to the full episode — where he discussed independent filmmaking, directing actors, production challenges, and lessons learned from working in film.
🔗 Connect With Trent
For more behind-the-scenes content, find Trent on YouTube and Instagram @trentalor.

Leave a Reply

Skip to content