The travel and tourism industry has undergone significant transformation in recent years due to new technologies. Artificial intelligence (AI) supported travel planning, biometric check-ins, interconnected booking systems, and smart room technology create an almost completely networked holiday experience. However, this rapid progress comes at a steep price: with every digital offering, the attack surface increases. Hotels and travel companies are among the most frequently targeted organizations by cyber criminals and state-backed actors.
Huge Bunches of Data and High Costs
Travel companies manage lots of personal data. Cybersecurity is thus an important issue. Any successful breach can provide attackers with passport numbers, credit card details, and access to frequent flyer programs that can be very valuable on the black market. The financial consequences of an attack are equally significant.
According to the Ponemon Institute’s Cost of a Data Breach Report, three of the world’s five highest average breach costs are in EMEA regions: the Middle East at $7.29 million per incident, the Benelux countries at $6.24 million and the United Kingdom at $4.14 million. Within the travel and tourism sector itself, a data breach costs an average of $4.03 million in the hotel industry and $3.98 million in transportation. The transport sector now accounts for eleven percent of all cyberattacks in Europe, ranking it second after the public sector.
Good and Bad News About AI
The growing use of artificial intelligence (AI) has created a dilemma for cybersecurity. On the one hand, it is a valuable tool for detecting and responding to threats. On the other hand, attackers use AI for their own purposes. In the World Economic Forum’s Global Cybersecurity Outlook 2026, 94 percent of surveyed executives identify AI as the most important driver of change in the threat landscape.
Cybercriminals are using generative AI to launch sophisticated social engineering campaigns at scale. KnowBe4’s latest Phishing Threat Trends Report found that 86 percent of all phishing attacks are now AI-powered.
Most Dangerous Attack Vectors
Several attack vectors are currently threatening travel companies in the EMEA region:
- Reservation hijacking uses ClickFix techniques to infiltrate hotel staff credentials. Attackers are using malware disguised as system updates or CAPTCHA pages to gain access to the hotel’s computer system. Once in the system, they contact real guests using their real booking numbers and travel dates to get them to make false payments.
- Double-extortion ransomware can cause a complete hotel shutdown. When attackers’ encrypt the property management systems, staff cannot check guests in, authorize payments, or give digital room keys to guests. The double extortion means that attackers can threaten to release sensitive travel data.
- Fragmented supply chains create additional attack surfaces, and one booking involves the global distribution system, local travel agents, local providers, and payment processors. Smaller suppliers may not have the budget to invest in security. This leaves the larger travel company as the weakest link for attackers to target.
- Geopolitical tensions contribute to instability in the travel industry, especially since political issues cause closures of airspace and affect travelers’ confidence. However, politically motivated attacks are also increasing, and include the jamming and spoofing of satellite navigation signals and large-scale distributed denial-of-service (DDoS) attacks against organizations.
From Reactive Protection to Human Resilience
In the past, traditional security models have focused on creating the strongest possible technical perimeter. Reservation hijacks and supply-chain attacks show that even the best firewall is useless if an overworked employee falls victim to an AI-powered social engineering or an unsecured AI agent is compromised through prompt injection.
Operational human resilience is about more than just a mandatory annual training checkbox: It is about protecting the entire digital workforce, including people and AI agents. Companies that recognize the human element as their greatest asset in defending against cyberattacks will be best poised to withstand the onslaught of a hostile threat environment.
