AI Vision Models Pinpoint Vacation Spots with 91% Accuracy, McAfee Warns
Cybersecurity research reveals that freely available AI can identify travel destinations from photos without metadata, enabling highly personalized phishing scams.
Publicly shared vacation photos are providing a roadmap for cybercriminals, according to new research from cybersecurity firm McAfee. The company warns that freely available AI vision models can now pinpoint the exact location of travel images with high accuracy, even when metadata and geotags are removed.
In a study involving 21,236 travel images, McAfee tested two open AI vision models to determine their location-inference capabilities. Alibaba's Qwen3 VL 30B achieved a 91% accuracy rate, while Google DeepMind's Gemma3 27B identified locations 87% of the time. Crucially, these models did not rely on EXIF data or embedded coordinates. Instead, they identified locations based solely on visual cues, including local architecture, signage, vegetation, street markings, and the quality of light.
The Shift to Contextual Phishing
Traditional phishing attacks typically rely on high volume and generic messaging, hoping a small percentage of recipients will bite. However, the integration of AI vision models allows attackers to automate the process of identifying a user's current or recent location via public social media platforms like Instagram, Facebook, and X.
By scraping these images, scammers can convert mass phishing into targeted, contextual attacks. "AI removes the guesswork, allowing attackers to build highly specific, contextual scams at scale," said Brooke Seipel, Content Editor in Chief at McAfee. This capability allows a scammer to send a message referencing a specific city—such as alerting a traveler to "suspicious activity while traveling in Porto"—which makes the communication appear legitimate and urgent.
Why Location Data Matters
This technological shift removes the need for scammers to have a prior personal connection to their victims or rely on random chance. By providing plausible, real-time context, attackers can effectively lower a victim's guard. Vonny Gamot, McAfee's head of EMEA, noted that AI provides the context that makes these threats credible.
Travelers are particularly vulnerable during trips, as they are often away from home, utilizing unfamiliar networks, and operating under pressure to make quick financial decisions. A phishing message that correctly identifies their current city is far more likely to bypass a user's natural skepticism than a generic alert.
What to Watch
As AI vision models become more sophisticated and accessible, the risk of automated "doxing" via social media is expected to rise. Security experts suggest that users be mindful of the visual information contained in their public posts, as removing geotags is no longer sufficient to protect one's location. The industry is now watching how social media platforms might implement safeguards to prevent the automated scraping of images for these types of targeted social engineering attacks.