Travel Brand Impersonation Scams Surge as Emirates and Uber Become Prime Targets
Kaspersky recorded nearly 270,000 attack attempts impersonating travel brands over 12 months, with Emirates and Uber the most exploited names in a surge of booking-related phishing.

A traveller checking a flight booking app on a smartphone in an airport terminal, representing travel-related phishing risk
Kaspersky has recorded 262,663 detections linked to attacks impersonating major transport brands over a single year, new data shows, part of a wider pattern this quarter of attackers exploiting trust in familiar names rather than breaking through technical defences directly. The findings, published in late July 2026, cover the period between the second quarter of 2025 and the first quarter of 2026.
Two brands account for nearly all of the volume
Attacks using the appearance of Emirates made up 61 percent of detections associated with the transport brands Kaspersky analysed, while those masquerading as Uber represented 37 percent. Kaspersky was careful to clarify that these figures do not indicate the companies themselves were compromised. Cybercriminals were instead using the appearance and names of established brands to build convincing phishing pages, fraudulent applications and fake offers designed to look legitimate to a distracted or time-pressured victim.
The malware points at financial theft, not just credential harvesting
The malware categories behind these campaigns point directly at financial exposure. Trojans were the most commonly detected threat type associated with transport brand impersonation, accounting for 30.5 percent of detections, followed closely by Trojan-Bankers at 22.5 percent. Trojan-Bankers are purpose-built to steal banking credentials and payment information, meaning an employee responding to a fraudulent booking confirmation or account alert risks exposing considerably more than a single travel itinerary.
Evgeny Kuskov, Lead Security Researcher at Kaspersky, pointed to why travel brands sit in such a favourable position for attackers: this category sits at an unusual intersection of trust, urgency and payment activity, all in the same transaction. People booking a flight or a ride are often moving quickly, comparing prices across several tabs, and primed to click on anything that looks like a good deal or an account issue. Kuskov also flagged that the most targeted brands span entirely different services, from ride-sharing to full-service airlines, indicating attackers are casting a wide net across the travel ecosystem rather than concentrating on a single niche.
How the scams actually worked
One documented scheme impersonated Ryanair and told targeted travellers they were entitled to flight compensation. Victims were directed to either enter account credentials or pay a small processing fee to receive the supposed payout, with a countdown timer used to create urgency and push victims past the point of careful scrutiny. Kaspersky flagged this kind of extreme time pressure as a reliable warning sign in its own right: legitimate airline compensation processes do not require decisions within seconds or upfront fees to release a refund.
Hotel and accommodation platforms were also targeted, though at meaningfully smaller scale, with 5,414 attack attempts recorded against travel and accommodation service brands over the same period. Trojans specifically accounted for 54.6 percent of detections in the accommodation category, an even higher share than transport, reinforcing why corporate hotel bookings carry elevated malware delivery risk alongside the credential and payment exposure already covered above. One scheme replicated Booking.com's appearance, directing victims to a fake reservation page requesting personal and payment details. Victims completing the process received no genuine reservation at all, in some cases only discovering the fraud after failing to receive confirmation or arriving at a destination with no valid booking waiting for them.
Why this matters beyond individual travellers
For enterprises across the GCC, the relevance extends well past individual traveller safety. Corporate travel bookings, expense reimbursements and executive itineraries move through many of the same booking channels this data describes, and finance and travel management teams handling payment credentials on behalf of an organisation represent a meaningfully higher-value target than an individual leisure traveller.
This pattern mirrors a benchmark MENA Cyber Wire has already flagged for the financial sector: a joint report from Boston Consulting Group and the Data Security Council of India found India's BFSI sector absorbs cyberattacks at 1.6 times the global average, a figure GCC financial institutions have been urged to treat as a warning about their own risk profile rather than an India-specific data point. The same logic applies here. Any workflow touching payment credentials, whether inside a bank or inside a corporate travel desk, tends to draw disproportionate attacker attention, and organisations that have already tightened identity and access management practices should extend that same discipline to travel booking workflows and corporate card usage specifically. Credential theft through a spoofed booking page can move laterally into far more damaging account compromise if reused credentials or saved payment details are involved.
What security teams should actually do
Kaspersky's guidance translates into a set of policies worth codifying for any organisation managing business travel at scale:
- Book directly through official corporate travel platforms or verified airline and provider websites rather than links received through email, SMS or social media.
- Check website addresses carefully before entering payment information, since fraudulent domains are frequently near-identical to genuine airline and booking platforms.
- Train employees to treat unusually cheap fares paired with demands for immediate payment, particularly through wire transfer or gift cards, as an active red flag rather than a lucky find.
- Enforce multi-factor authentication on travel and expense accounts, and source apps only through official app stores. Together these close off a meaningful share of this attack surface on their own, consistent with what continuous, monitored detection programmes across GCC enterprises are already built to catch when phishing attempts slip past initial employee awareness.
As business travel volumes across the region continue climbing, brand impersonation of this kind is likely to remain a persistent line item in gulf cyber security news rather than a passing trend. Nearly 270,000 attempts against transport brands alone in a single year makes clear this is now an established attack category, not an edge case worth a single awareness email and nothing more.
Related Intelligence
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.