Meet Krysta Collin, General Manager at...
In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read MoreTravellers are often tired, distracted and under pressure, making them more likely to connect to an unverified network, scan an unfamiliar QR code or respond quickly to a convincing message.
Many of the risks encountered at an airport are not unique to air travel. Public Wi-Fi, phishing messages, malicious QR codes and stolen devices can affect people anywhere. However, airports bring these threats together in an environment where travellers are expecting frequent communications from airlines, booking providers, hotels and transport companies.
A few small changes to your airport habits can significantly reduce the likelihood of personal information, account credentials or business data falling into the wrong hands.
Free airport Wi-Fi can be convenient, particularly when mobile reception is poor or roaming charges apply. However, a network name that appears legitimate is not necessarily operated by the airport.
A criminal can create a wireless hotspot using a convincing name, such as “Airport Free Wi-Fi” or the name of a nearby airline lounge. Travellers may connect without realising that the network is fraudulent. They could then be directed to a fake login page designed to collect email addresses, passwords, card details or other personal information.
Before connecting, confirm the correct network name through airport signage, the airport’s official website or a member of staff. Avoid using public Wi-Fi for online banking, making payments or accessing sensitive work systems. Where possible, use your mobile data connection or personal hotspot instead.
The Information Commissioner’s Office warns that using public Wi-Fi or an insecure connection can put personal data at risk. If a public network must be used, a reputable virtual private network (VPN) can help protect information travelling between the device and the VPN provider. However, a VPN will not make a fraudulent website legitimate or protect someone who voluntarily enters their information into a phishing page.
Posting a boarding pass on social media may seem like a harmless way to mark the beginning of a holiday. Unfortunately, a boarding pass can reveal far more than the passenger’s name and destination.
The booking reference printed on the pass may be used alongside the surname to access the “manage my booking” section of an airline’s website. Depending on the airline and booking system, this could expose contact details, travel arrangements, frequent-flyer information, seat selections and other booking data. In some cases, an unauthorised person may also be able to alter elements of the booking.
The barcode or QR code on a boarding pass should be treated as sensitive too. Covering the visible name or booking reference in a photograph is not necessarily enough if the barcode remains readable.
Boarding passes should be kept private, including after the flight. Paper copies should be securely destroyed rather than left in a seat pocket, hotel room or airport bin. Digital passes should not be posted online.
Boarding passes are not the only travel information people share. Airport check-ins, departure lounge photographs and public countdowns can disclose where someone is, where they are going and how long they may be away.
This creates both digital and physical security risks. A public post could indicate that a home is unoccupied. It can also provide criminals with useful information for targeted phishing. For example, someone who knows a traveller’s airline and destination could send a convincing message about a flight delay, baggage charge, hotel transfer or booking problem.
The National Cyber Security Centre advises people to consider their digital footprint because criminals can use information published online to steal identities or make phishing messages more believable. Travellers should review their privacy settings and consider waiting until they return before sharing detailed holiday photographs publicly.
Airports now use QR codes for menus, parking payments, Wi-Fi access, airport maps and special offers. Their familiarity can make people less cautious about scanning them.
A QR code does not reveal its destination until it has been scanned. Criminals can exploit this by placing a fraudulent sticker over a genuine code or displaying their own code in a convincing location. The resulting website may imitate an airport, restaurant, parking provider or airline and ask the user to enter payment details or account credentials.
The NCSC reports that QR-related fraud commonly occurs in open public spaces, including stations and car parks, and frequently involves social engineering. Although QR fraud remains relatively small compared with other forms of cybercrime, the risk is credible and travellers should remain alert.
Before entering any information, check the web address displayed by the phone. Look for misspellings, unfamiliar domains or extra words intended to imitate a genuine organisation. If the code relates to a payment or account login, it is safer to open the organisation’s official app or type its known website address into the browser.
Airport lounges and departure gates are commonly treated as temporary offices. However, opening confidential documents or joining a sensitive call in a crowded terminal can expose information without any sophisticated cyberattack taking place.
Shoulder surfing involves obtaining information by watching someone’s screen or keyboard. A nearby person may see a password, PIN, customer record, email or confidential attachment. Phone conversations can also disclose names, project details, financial information or answers to common security questions.
If working at an airport is unavoidable, position the screen away from passing passengers and consider using a privacy screen. Avoid discussing confidential matters on calls, and do not leave a work device unlocked or unattended, even briefly.
Business travellers should follow their organisation’s remote-working and travel policies. Employers should also consider whether staff genuinely need access to all their usual information while travelling. Limiting access to what is necessary reduces the potential impact if a device is lost, stolen or observed by someone nearby.
Airports offer countless opportunities for a phone, tablet or laptop to be lost or stolen. A traveller may leave a device at a charging point, on a café table or in a security tray while distracted by luggage or family members.
Every device taken on a journey should have a strong screen lock. Biometric authentication, such as fingerprint or facial recognition, can provide convenient protection while reducing the need to enter a passcode in public. Devices should also lock automatically after a short period of inactivity.
Tracking and remote-wipe features should be enabled before travelling. The NCSC recommends using functions such as Find My on Apple devices or Find My Device on Android so that a lost or stolen device can be located, locked or erased remotely.
Important data should be backed up before departure, and devices, applications and browsers should be fully updated. Updates frequently contain security fixes that protect against known vulnerabilities.
Phones and laptops may be configured to search for known Wi-Fi networks or connect automatically when a familiar network name appears. In a busy airport, this can expose a device to unnecessary connections.
Bluetooth and nearby file-sharing services can also make a device visible to strangers. An unsolicited file, link or connection request may be sent to the user in the hope that curiosity or confusion will lead them to accept it.
Disable automatic Wi-Fi connections, Bluetooth and nearby sharing when they are not needed. If AirDrop is required on an Apple device, restrict it to contacts rather than allowing requests from everyone. Similar restrictions should be applied to Android’s Quick Share and equivalent features.
Warnings about “juice jacking” describe the possibility of a compromised USB connection being used to transfer data or malicious software while charging a device. Confirmed real-world incidents appear to be rare, and the risk should not be exaggerated. Nevertheless, it is relatively easy to avoid.
The NCSC recommends avoiding public USB charging points and using a traditional power socket instead. Travellers can carry their own mains adaptor and cable, use a trusted power bank or use a charge-only cable that does not support data transfer.
If a phone displays a prompt asking whether it should trust a connected device, transfer data or charge only, select the charging-only option unless there is a clear and legitimate reason to do otherwise.
Flight delays, gate changes, baggage problems and last-minute payment requests are all plausible during a journey. Criminals can take advantage of these expectations by sending phishing emails or text messages that appear to come from an airline, airport, hotel or booking provider.
A fraudulent message may claim that a flight has been cancelled, a payment has failed or a small fee is required to release baggage or confirm a reservation. The message will often create urgency and direct the recipient to a convincing imitation website.
Do not rely on the sender name or branding alone. Instead of following the link, open the airline’s official app, visit its website independently or speak to airport staff. Be particularly cautious if a message requests a password, payment card, one-time security code or immediate transfer of money.
The NCSC explains that phishing attacks use emails, text messages, websites and phone calls to steal personal information or infect devices. Suspicious emails can be forwarded to report@phishing.gov.uk, while suspicious text messages can usually be forwarded to 7726.
Taking a work laptop abroad introduces risks that extend beyond the individual traveller. A stolen device, exposed document or compromised account could affect colleagues, customers and the wider organisation.
Before departure, staff should know how to report a lost device or suspected security incident. Multi-factor authentication should be enabled, sensitive information should be encrypted and unnecessary files should be removed from the device. Access to company systems should take place only through approved methods.
Travellers should also be conscious of what is visible on luggage labels. A tag containing a full home address, personal telephone number and employer’s name may reveal more than is necessary. Initials, a mobile number and an email address may be sufficient to reunite the bag with its owner without publicly displaying a home address.
Most airport data risks do not require complex technical knowledge to avoid. The most effective precautions are straightforward: keep boarding passes private, verify Wi-Fi networks, be cautious with QR codes, protect screens from view, secure devices and slow down before responding to unexpected messages.
Airports are busy environments designed around movement, deadlines and frequent changes. Cybercriminals benefit when those pressures cause people to act without checking. Taking a few extra seconds to verify a network, website or message can make the difference between the start of a relaxing holiday and the beginning of a much more serious problem.
AJC helps organisations understand and manage their cyber security and data protection risks, including those associated with remote working and business travel.
Our specialists can review policies and procedures, assess how personal and business data is handled, provide staff awareness training and help organisations prepare for incidents involving lost, stolen or compromised devices.
To find out how AJC can help strengthen your organisation’s cyber resilience and data protection arrangements, please contact our team.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://www.travelandleisure.com/airport-habits-that-can-put-your-personal-data-at-risk-12024770
https://www.ncsc.gov.uk/blog-post/qr-codes-whats-real-risk
https://ico.org.uk/for-the-public/online/wifi-security/
https://www.caa.co.uk/air-passengers/assisted-travel/how-to-access-help-and-support/
https://www.ncsc.gov.uk/collection/defending-democracy/guidance-for-high-risk-individuals
https://www.ncsc.gov.uk/collection/phishing-scams
https://www.ncsc.gov.uk/files/Small%20Business%20Guide%20Infographic%202.pdf
Image accreditation: Getty Images on Unsplash.com+. Last accessed opn 3 August 2026. Available at: https://unsplash.com/photos/man-working-on-a-laptop-at-the-airport-waiting-to-board-the-plane-businessman-on-business-communicating-vita-internet-buying-tickets-at-sunset-transportation-technology-and-holidays-concept-y4VqGXq1g5A
In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read MoreAs AI becomes more capable, organisations need to understand both the opportunities and the risks it can create. This article...
Read MoreArtificial intelligence chatbots are becoming a popular way to access and summarise information, but they are not always reliable. This...
Read More