Summer Travel Fraud in Mexico Up 3% Amid Cybercrime Surge | #cybercrime | #infosec


Travel fraud in Mexico rose 3% this summer, while commercial retail cyberattacks more than doubled over the past three years, exposing tourism and retail enterprises to severe operational disruptions and financial risks. The proliferation of spoofed corporate domains, employee errors, and third-party vendor vulnerabilities threatens payment gateways, consumer trust, and supply chain continuity. With major retail data breaches costing up to US$91 million and e-commerce downtime incurring losses of US$20,000 per hour, robust cybersecurity and verification controls have become critical operational imperatives across Mexico’s commercial landscape.

——

Travel fraud in Mexico increased 3% during the summer vacation season compared to 2025, driven by fake digital offers and cloned websites targeting holiday consumers, according to data from the Mexico City Citizens’ Council for Security and Justice. The fraudulent scheme, known locally as “montaviajes,” capitalizes on online searches for discounted vacation packages, flights, and hotel bookings. 

The organization reported handling over 1,637 incident reports during holiday periods, with beach destinations representing the primary focus of fraudulent activities. Cancun accounted for 43% of reported cases, followed by Acapulco, Huatulco, and Puerto Vallarta.

Perpetrators spoofed recognized corporate identities in 72% of recorded cases. Fraudulent operators created cloned websites and fake social media profiles mimicking brands including Volaris, Aeroméxico, Hoteles RIU, Booking, Grupo Oasis, Expedia, Xcaret, and Best Day to legitimize nonexistent offers.

Financial losses per victim remain substantial. In 57% of reported cases, victims made bank transfers ranging between MX$10,000 (US$574) and MX$30,000 (US$1,722), with the highest individual loss reaching MX$2 million (US$114,816). Demographic tracking indicates that individuals over 50 years of age represent 30% of total cases, forming the most vulnerable demographic segment.

To mitigate exposure, the Citizens’ Council advised consumers to verify travel agency registrations with the Ministry of Tourism (SECTUR), check regulatory records with consumer protection agency PROFECO, avoid purchasing packages via unverified email or messaging links, and directly confirm commercial agreements with airlines and hotel operators.

Mexico Faces Expanding Cybersecurity Threat

Broader commercial fraud and cybersecurity incidents targeting the retail sector in Mexico more than doubled over the past three years, according to a new report by Kaspersky. The sector’s expanding reliance on digital sales platforms, artificial intelligence, automated logistics, and connected ecosystems has increased the volume of sensitive data managed by businesses, making payment credentials, customer profiles, and loyalty program data prime targets for cybercriminals.

“The retail sector has reached a stage where cybersecurity can no longer be viewed as technical support but as a condition for operating, selling and maintaining consumer trust,” stated Claudio Martinelli, General Manager for the Americas at Kaspersky. Martinelli noted that digitalization interconnects all retail operational phases, allowing minor security vulnerabilities to escalate into enterprise-wide operational disruptions.

Data protection and payment infrastructure security represent critical operational priorities for the sector. Retailers depend heavily on consumer data to manage dynamic pricing, targeted marketing, and automated supply chains. A major data breach across corporate networks can generate regulatory fines, legal liabilities, contractual costs, and remediation expenses reaching up to US$91 million for large retail corporations.

Payment systems face persistent targeting from attackers seeking to manipulate transactions, intercept financial data, or steal credentials during purchases. Physical point-of-sale terminals remain vulnerable when integrated with corporate networks, customer databases, and loyalty programs. Cyberattacks capable of taking online storefronts or payment infrastructure offline can generate operational losses of up to US$20,000 per hour, converting transaction security into a core business continuity issue.

Human error remains a primary driver of cybersecurity incidents within retail organizations. Unintentional employee mistakes account for between 64% and 86% of data breaches, according to the report. Attackers deploy social engineering tactics, including Business Email Compromise, manipulated banking information, malicious API scripts, and fake invoices. Recent incidents demonstrate an increasing use of artificial intelligence tools, such as deepfakes and voice cloning, delivered across email, social media, and collaboration tools like Microsoft Teams.

Supply chain dependencies further expand the retail attack surface. Modern retailers rely on external technology vendors, logistics providers, and cloud platforms. Industry research cited by Kaspersky shows that 30% of cyberattacks targeting retailers originated through business partners or third-party suppliers. However, only 9% of retail executives identify third-party supply chain risk as their primary cybersecurity concern, highlighting an underestimation of vendor exposure across the industry.

Kaspersky warned that leaked source code, publicly available offensive tools, and generative artificial intelligence lower barriers for threat actors. To build cyber resilience, the report recommends that retail enterprises identify non-negotiable business processes, increase employee security awareness, deploy advanced threat detection technologies, and utilize managed security services to monitor complex digital environments.





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW