The high-ticket, book-it-yesterday itineraries that define luxury travel are exactly what fraudsters are hunting for, according to a new industry brief from the American Society of Travel Advisors.
The member-exclusive report, "Rising Fraud Threats in Travel," warns that criminals are increasingly layering stolen payment data, impersonation, and credential theft into single schemes, and that artificial intelligence is making those schemes both easier to run and harder to catch. Voice cloning, deepfakes, synthetic identities, and AI-written phishing emails with flawless grammar are now part of the standard toolkit, ASTA says.
"Fraud is becoming more sophisticated, more scalable and more difficult to detect, particularly as criminals use artificial intelligence to exploit trust and create a false sense of urgency," said Zane Kerby, ASTA's president and CEO. "Travel advisors need strong systems, clear verification procedures and current information to protect their businesses and their clients."
Luxury is in the Crosshairs
The brief singles out the use of stolen credit cards "to book high-value or last-minute travel, particularly airline tickets or luxury accommodations that can be quickly issued but are difficult to recover." A typical pattern involves multiple compromised cards used to book international itineraries in a short window, often with a request for urgent ticketing. When the real cardholder disputes the charge, the agency eats the chargebacks, debit memos, and administrative costs, which ASTA says "can far exceed the original transaction value." Citing industry estimates, the brief puts chargeback management at up to two to three times the original transaction value once penalties are included.
Business email compromise is the other scheme that should worry anyone moving large sums to overseas partners. ASTA describes cases in which an agency receives "updated wiring instructions for a hotel or destination management company that appear valid but actually route funds to a criminal's account." In one example cited in the brief, an advisor acted on what looked like a legitimate payment-change request from a hotel partner, but the sender's domain contained a subtle variation and the funds went to a fraudulent account.
The report also documents credential theft via fake system-update or supplier-login prompts, and international cases in which bad actors impersonated agencies during onboarding with airlines and technology providers using falsified credentials. Notably, ASTA finds no broad evidence that airline systems or GDSs are the primary point of compromise. The weak link, the brief says, is almost always a human process.
The Scale of the Problem
ASTA points to Federal Trade Commission data showing consumers reported more than $12.5 billion in fraud losses in 2024, a 25 percent jump from the prior year, and to Nilson Report estimates that global card fraud losses exceed $30 billion annually. Within travel specifically, the brief cites a Booking.com-reported 500 to 900 percent increase in travel scams over an 18-month period, with global travel fraud estimated at more than $21 billion a year for businesses and another $13 billion-plus lost by consumers. Nearly half of consumers, ASTA adds, distrust the industry's ability to protect them.
That distrust is the opening for advisors. The brief argues that "travel advisors are no longer just service providers—they are the first and most important line of defense," and that advisors can position vigilance as a selling point, "reassuring clients that booking through a trusted professional offers not just convenience, but a measure of protection as well."
ASTA's Action Items for Advisors
The brief closes with an eight-step playbook: unique passwords in a password manager and multi-factor authentication everywhere; a two-step verification protocol for any payment or banking change, confirmed through a second, known channel such as a direct call; staff training on modern phishing and voice-clone tactics; regular monitoring of booking, payment, and email accounts with alerts enabled; a documented incident response plan with bank, supplier, host agency, and IT contacts ready; tighter client-data handling, including never sending passport or payment details over unsecured email; setting communication expectations with clients so they know you will never request a payment change by email alone; and added due diligence on new or unfamiliar suppliers before any money moves.
ASTA also urges reporting incidents to banks, partners, the FTC, and, for cyber-related fraud, the FBI's IC3 portal, and points members to its online course, "Protecting Your Business: Fraud Protection for Travel Advisors," in the ASTA Learning Center.
The full brief is available to ASTA members via the association's Industry Resources page.
Related Stories
ASTA Launches Tool for Advisors to Report Supplier Concerns
The Real Cost of NCFs: What Advisors Are Actually Earning
ASTA Recovers $20,000 in Late Hotel Commissions for Advisors
ASTA Forecast Highlights Growth and Reform for Travel Advisors