Post a beach selfie and the internet now knows more than you think. New research from McAfee Labs shows that freely available AI tools can figure out where a photo was taken roughly 91% of the time — and they don't need GPS data or location tags to do it. Background scenery, architecture, signage and even the quality of light are enough.

The tools in question aren't exotic. McAfee's tests used publicly accessible AI models via ChatGPT, Claude and Copilot — no special access, proprietary data or technical skill required. And the photos don't need famous landmarks either. In one example, ChatGPT pinpointed a picture of Hastings-on-Hudson, New York, that showed nothing more than a wooded ridge and some water.

Why does that matter to anyone on holiday? Because scammers love context. As McAfee CTO Steve Grobman put it to Forbes, location builds trust — instead of blasting out generic phishing texts, fraudsters can send one that name-checks your exact resort and lands while you're actually there. Imagine you're in Playa del Carmen and you've just posted from the beach. A scammer runs your photo through a free AI model, learns where you are, then sends a text about a 'payment problem' at your hotel with a link to fix it. Since the message gets your location right, it feels credible — and that's the trap.

McAfee's report lists the sort of messages travellers might receive once a con artist has deduced their current or recent destination: alerts about 'unusual account activity while you were traveling in [city]', flagged card transactions in a country you just visited, hotel reservation 'reconfirmation' links, or even a plea apparently from you to your loved ones: 'Hi, it's [your name], I'm in Mexico and all my cards are being declined. Could you send me $$?' An unsolicited message that knows where you've been suddenly looks a lot like a legitimate one. There's also the old-fashioned bonus risk: posting from abroad advertises to burglars that your home is empty.

The experts aren't saying stop sharing holiday photos altogether. But a few habits go a long way. First, wait until you're home — ideally a few days after you return — before uploading, since real-time posts hand scammers a live signal. Second, tighten your privacy settings so only people you actually know can see your content. Third, treat any urgent message that references your location as a red flag, not proof of legitimacy — scammers name your destination precisely because it puts you at ease. Never click links in unsolicited texts or emails; instead, open the company's official app or website yourself, or call the number printed on the back of your card. And if you book a lot of travel, consider using a dedicated email address for reservations, which limits how much scammers can cross-reference between your social media presence and your financial accounts.

None of this requires paranoia, just a small delay between your poolside selfie and your Instagram upload. Post when you're home, keep your circle private, and stay suspicious of any message that's a little too well-informed about your itinerary.

Story via Frommer's.