Phone us
Busy airports, unfamiliar networks and frequent travel updates can create opportunities for cybercriminals and put personal data at risk. This article looks at some common airport habits that could expose personal or business information, and the practical steps travellers can take to protect it.

Travellers are often tired, distracted and under pressure, making them more likely to connect to an unverified network, scan an unfamiliar QR code or respond quickly to a convincing message.

Many of the risks encountered at an airport are not unique to air travel. Public Wi-Fi, phishing messages, malicious QR codes and stolen devices can affect people anywhere. However, airports bring these threats together in an environment where travellers are expecting frequent communications from airlines, booking providers, hotels and transport companies.

A few small changes to your airport habits can significantly reduce the likelihood of personal information, account credentials or business data falling into the wrong hands.

Connecting to the Wrong Airport Wi-Fi Network

Free airport Wi-Fi can be convenient, particularly when mobile reception is poor or roaming charges apply. However, a network name that appears legitimate is not necessarily operated by the airport.

A criminal can create a wireless hotspot using a convincing name, such as “Airport Free Wi-Fi” or the name of a nearby airline lounge. Travellers may connect without realising that the network is fraudulent. They could then be directed to a fake login page designed to collect email addresses, passwords, card details or other personal information.

Before connecting, confirm the correct network name through airport signage, the airport’s official website or a member of staff. Avoid using public Wi-Fi for online banking, making payments or accessing sensitive work systems. Where possible, use your mobile data connection or personal hotspot instead.

The Information Commissioner’s Office warns that using public Wi-Fi or an insecure connection can put personal data at risk. If a public network must be used, a reputable virtual private network (VPN) can help protect information travelling between the device and the VPN provider. However, a VPN will not make a fraudulent website legitimate or protect someone who voluntarily enters their information into a phishing page.

Sharing a Photograph of Your Boarding Pass

Posting a boarding pass on social media may seem like a harmless way to mark the beginning of a holiday. Unfortunately, a boarding pass can reveal far more than the passenger’s name and destination.

The booking reference printed on the pass may be used alongside the surname to access the “manage my booking” section of an airline’s website. Depending on the airline and booking system, this could expose contact details, travel arrangements, frequent-flyer information, seat selections and other booking data. In some cases, an unauthorised person may also be able to alter elements of the booking.

The barcode or QR code on a boarding pass should be treated as sensitive too. Covering the visible name or booking reference in a photograph is not necessarily enough if the barcode remains readable.

Boarding passes should be kept private, including after the flight. Paper copies should be securely destroyed rather than left in a seat pocket, hotel room or airport bin. Digital passes should not be posted online.

Announcing Your Holiday in Real Time

Boarding passes are not the only travel information people share. Airport check-ins, departure lounge photographs and public countdowns can disclose where someone is, where they are going and how long they may be away.

This creates both digital and physical security risks. A public post could indicate that a home is unoccupied. It can also provide criminals with useful information for targeted phishing. For example, someone who knows a traveller’s airline and destination could send a convincing message about a flight delay, baggage charge, hotel transfer or booking problem.

The National Cyber Security Centre advises people to consider their digital footprint because criminals can use information published online to steal identities or make phishing messages more believable. Travellers should review their privacy settings and consider waiting until they return before sharing detailed holiday photographs publicly.

Scanning Unfamiliar QR Codes

Airports now use QR codes for menus, parking payments, Wi-Fi access, airport maps and special offers. Their familiarity can make people less cautious about scanning them.

A QR code does not reveal its destination until it has been scanned. Criminals can exploit this by placing a fraudulent sticker over a genuine code or displaying their own code in a convincing location. The resulting website may imitate an airport, restaurant, parking provider or airline and ask the user to enter payment details or account credentials.

The NCSC reports that QR-related fraud commonly occurs in open public spaces, including stations and car parks, and frequently involves social engineering. Although QR fraud remains relatively small compared with other forms of cybercrime, the risk is credible and travellers should remain alert.

Before entering any information, check the web address displayed by the phone. Look for misspellings, unfamiliar domains or extra words intended to imitate a genuine organisation. If the code relates to a payment or account login, it is safer to open the organisation’s official app or type its known website address into the browser.

Working Where Other People Can See or Hear You

Airport lounges and departure gates are commonly treated as temporary offices. However, opening confidential documents or joining a sensitive call in a crowded terminal can expose information without any sophisticated cyberattack taking place.

Shoulder surfing involves obtaining information by watching someone’s screen or keyboard. A nearby person may see a password, PIN, customer record, email or confidential attachment. Phone conversations can also disclose names, project details, financial information or answers to common security questions.

If working at an airport is unavoidable, position the screen away from passing passengers and consider using a privacy screen. Avoid discussing confidential matters on calls, and do not leave a work device unlocked or unattended, even briefly.

Business travellers should follow their organisation’s remote-working and travel policies. Employers should also consider whether staff genuinely need access to all their usual information while travelling. Limiting access to what is necessary reduces the potential impact if a device is lost, stolen or observed by someone nearby.

Leaving Devices Unlocked or Unattended

Airports offer countless opportunities for a phone, tablet or laptop to be lost or stolen. A traveller may leave a device at a charging point, on a café table or in a security tray while distracted by luggage or family members.

Every device taken on a journey should have a strong screen lock. Biometric authentication, such as fingerprint or facial recognition, can provide convenient protection while reducing the need to enter a passcode in public. Devices should also lock automatically after a short period of inactivity.

Tracking and remote-wipe features should be enabled before travelling. The NCSC recommends using functions such as Find My on Apple devices or Find My Device on Android so that a lost or stolen device can be located, locked or erased remotely.

Important data should be backed up before departure, and devices, applications and browsers should be fully updated. Updates frequently contain security fixes that protect against known vulnerabilities.

Leaving Wireless Connections Open

Phones and laptops may be configured to search for known Wi-Fi networks or connect automatically when a familiar network name appears. In a busy airport, this can expose a device to unnecessary connections.

Bluetooth and nearby file-sharing services can also make a device visible to strangers. An unsolicited file, link or connection request may be sent to the user in the hope that curiosity or confusion will lead them to accept it.

Disable automatic Wi-Fi connections, Bluetooth and nearby sharing when they are not needed. If AirDrop is required on an Apple device, restrict it to contacts rather than allowing requests from everyone. Similar restrictions should be applied to Android’s Quick Share and equivalent features.

Using Public USB Charging Points Without Caution

Warnings about “juice jacking” describe the possibility of a compromised USB connection being used to transfer data or malicious software while charging a device. Confirmed real-world incidents appear to be rare, and the risk should not be exaggerated. Nevertheless, it is relatively easy to avoid.

The NCSC recommends avoiding public USB charging points and using a traditional power socket instead. Travellers can carry their own mains adaptor and cable, use a trusted power bank or use a charge-only cable that does not support data transfer.

If a phone displays a prompt asking whether it should trust a connected device, transfer data or charge only, select the charging-only option unless there is a clear and legitimate reason to do otherwise.

Responding Too Quickly to Travel Messages

Flight delays, gate changes, baggage problems and last-minute payment requests are all plausible during a journey. Criminals can take advantage of these expectations by sending phishing emails or text messages that appear to come from an airline, airport, hotel or booking provider.

A fraudulent message may claim that a flight has been cancelled, a payment has failed or a small fee is required to release baggage or confirm a reservation. The message will often create urgency and direct the recipient to a convincing imitation website.

Do not rely on the sender name or branding alone. Instead of following the link, open the airline’s official app, visit its website independently or speak to airport staff. Be particularly cautious if a message requests a password, payment card, one-time security code or immediate transfer of money.

The NCSC explains that phishing attacks use emails, text messages, websites and phone calls to steal personal information or infect devices. Suspicious emails can be forwarded to report@phishing.gov.uk, while suspicious text messages can usually be forwarded to 7726.

Mixing Business and Personal Travel Without Preparation

Taking a work laptop abroad introduces risks that extend beyond the individual traveller. A stolen device, exposed document or compromised account could affect colleagues, customers and the wider organisation.

Before departure, staff should know how to report a lost device or suspected security incident. Multi-factor authentication should be enabled, sensitive information should be encrypted and unnecessary files should be removed from the device. Access to company systems should take place only through approved methods.

Travellers should also be conscious of what is visible on luggage labels. A tag containing a full home address, personal telephone number and employer’s name may reveal more than is necessary. Initials, a mobile number and an email address may be sufficient to reunite the bag with its owner without publicly displaying a home address.

Cybersecurity Should Be Part of the Holiday Checklist

Most airport data risks do not require complex technical knowledge to avoid. The most effective precautions are straightforward: keep boarding passes private, verify Wi-Fi networks, be cautious with QR codes, protect screens from view, secure devices and slow down before responding to unexpected messages.

Airports are busy environments designed around movement, deadlines and frequent changes. Cybercriminals benefit when those pressures cause people to act without checking. Taking a few extra seconds to verify a network, website or message can make the difference between the start of a relaxing holiday and the beginning of a much more serious problem.

How AJC Can Help

AJC helps organisations understand and manage their cyber security and data protection risks, including those associated with remote working and business travel.

Our specialists can review policies and procedures, assess how personal and business data is handled, provide staff awareness training and help organisations prepare for incidents involving lost, stolen or compromised devices.

To find out how AJC can help strengthen your organisation’s cyber resilience and data protection arrangements, please contact our team.

Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.

Sources:

https://www.travelandleisure.com/airport-habits-that-can-put-your-personal-data-at-risk-12024770

https://www.ncsc.gov.uk/blog-post/qr-codes-whats-real-risk

https://ico.org.uk/for-the-public/online/wifi-security/

https://www.caa.co.uk/air-passengers/assisted-travel/how-to-access-help-and-support/

https://www.ncsc.gov.uk/collection/defending-democracy/guidance-for-high-risk-individuals

https://ico.org.uk/for-organisations/advice-for-small-organisations/information-security/data-security-advice/practical-ways-to-keep-your-it-systems-safe-and-secure/

https://www.caa.co.uk/media/puaffwhd/appendix-fi-synthesis-of-consumer-wants-and-needs-technical-report-may-2026.pdf

https://www.ncsc.gov.uk/collection/phishing-scams

https://www.ncsc.gov.uk/files/Small%20Business%20Guide%20Infographic%202.pdf

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/09/information-commissioner-s-office-shares-cyber-security-tips-for-small-businesses/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/working-from-home/how-do-i-work-from-home-securely/

Image accreditation: Getty Images on Unsplash.com+. Last accessed opn 3 August 2026. Available at: https://unsplash.com/photos/man-working-on-a-laptop-at-the-airport-waiting-to-board-the-plane-businessman-on-business-communicating-vita-internet-buying-tickets-at-sunset-transportation-technology-and-holidays-concept-y4VqGXq1g5A

In case you missed it...

krysta collin
Meet Krysta Collin, General Manager at...

In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...

Read More
AI Cyber Resilience
OpenAI Security Incident Highlights the Growing...

As AI becomes more capable, organisations need to understand both the opportunities and the risks it can create. This article...

Read More
Can AI Chatbots Be Trusted to Get the News Right?
Can AI Chatbots Be Trusted to...

Artificial intelligence chatbots are becoming a popular way to access and summarise information, but they are not always reliable. This...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.