Key Takeaways
- Hospitality, travel, and recreation organizations averaged 2,291 weekly cyberattacks in May 2026, up 24% year over year.
- Check Point Research counted 47,318 new travel-related domains during the month, with coordinated campaigns impersonating major booking and financial brands.
- Travel companies can reduce exposure through domain monitoring, stronger authentication, resilient holiday staffing, and established security frameworks.
Check Point Research has documented a sharp seasonal increase in cyber threats aimed at travelers and the businesses serving them, with phishing infrastructure expanding alongside the 2026 summer booking rush.
Hospitality, travel, and recreation organizations experienced an average of 2,291 cyberattacks per week in May 2026. That was 24% higher than in May 2025, while the comparable increase across all industries was only 2%.
Average weekly attacks against the sector have risen 122% since May 2023, when organizations recorded 1,032 attacks per week. Attackers appear to be concentrating resources on an industry with seasonal demand, high transaction volumes, extensive partner networks, and valuable stores of identity and payment data.
Researchers found that 47,318 new travel-related domains were registered in May 2026, an increase of 33% from April and 19% from May 2025. One in every 112 had already been classified as malicious or suspicious. Other domains may remain inactive until criminals are ready to use them, making registration patterns an important early-warning signal.
Several campaigns showed signs of industrial-scale preparation. More than 210 sequentially numbered domains used formats such as hotel-stay[N].com and stay-hotel[N].com, creating a reusable pool of hotel-themed phishing sites.
Another campaign combined American Express and Lloyds Travel Choice branding with phrases such as “happytrip” and “travelchoice” on .ink domains. A third spread imitations of Fora Travel across 108 top-level domains, including .cruises, .miami, and .international. Registering many variations improves the odds that a hurried traveler lands on a convincing copy.
Travel purchases are time-sensitive, expensive, and frequently made from mobile devices. A message claiming that a reservation is about to expire can push users toward action before close inspection.
Active examples identified in the analysis include bookingni[.]com, which copies the Booking.com sign-in process to capture credentials and card details. The domains booking-cn[.]com and booking-hk[.]com use localized pages, ¥ pricing, and a “mid-year summer sale” message to target Chinese-speaking customers. The same campaign operates booking-jp[.]com and booking-zh[.]com.
The impersonation extends beyond Booking.com. The domain airbnb-ca[.]com uses Canadian Rockies imagery and listings for Montreal, Toronto, Vancouver, and Banff. Meanwhile, skyscanners[.]shop and skyscanners[.]life advertise apparent “presale price” deals at Malaysian resorts, then collect deposits without creating legitimate reservations.
For businesses, these scams present more than a consumer-protection issue. Brand impersonation generates support costs, payment disputes, reputational damage, and account takeover attempts. Stolen customer credentials may also be tested against employee portals or partner systems.
Holiday timing adds another layer of risk. CISA and the FBI have warned that highly disruptive ransomware attacks often occur during holidays and weekends, when offices are closed or security coverage is reduced. Industry data from Semperis indicates that 52% of organizations experiencing ransomware attacks are hit on a weekend or holiday, and 78% cut security operations center staffing by 50% or more during these periods. In the travel sector, this operational vulnerability coincides directly with peak demand.
Organizations can respond by monitoring newly registered domains, accelerating takedown procedures, applying multifactor authentication, and rehearsing incident escalation outside normal business hours. The NIST Cybersecurity Framework offers a structured way to identify, protect against, detect, respond to, and recover from threats. ISO/IEC 27001 also supports consistent information-security controls across booking systems, hotel operations, payment environments, and third-party relationships.
Travelers have simpler options: type booking addresses directly into the browser, inspect domains closely, enable two-factor authentication, and favor credit cards for stronger dispute options. Urgency deserves skepticism, as countdown clocks are often fabricated even if the copied logos appear perfectly accurate.
Seasonal travel fraud is planned well before vacationers begin searching. Check Point Research’s findings show that defenders need to prepare on the same schedule, before malicious domains become live campaigns and before lean holiday staffing turns a manageable alert into a larger incident.
⬇️