Smishing in travel reservations: National Police warn of fake bank SMS messages

The National Police is warning of an SMS scam targeting those who have recently booked holidays online, impersonating banks.

Smishing in travel reservations: National Police warn of fake bank SMS messages

Police alert for SMS fraud following tourism bookings on digital platforms

The National Police has issued an urgent alert about a new type of scam affecting citizens who have recently booked travel through digital platforms, according to ultimahora.es. Cybercriminals send SMS messages that appear to come from banking entities just hours after the victim has completed a tourism reservation.

The synchronisation of the fraud is its most disturbing feature. The message arrives within such a tight timeframe of the reservation that it creates an appearance of legitimacy that is difficult to ignore, which has led the authorities to point to possible data breaches in e-commerce platforms.

A recent case illustrates the mechanism of the deception: a Spanish citizen received an SMS in which her bank informed her of an alleged debt of 3,000 euros, just the day after she had booked a holiday package. The message included a telephone number and urged her to contact immediately to "regularise the situation".

This criminal method falls under the category of "smishing", a variant of classic phishing that uses SMS as a fraud channel. The criminals use convincing corporate language and incorporate real personal data to lend credibility to the message.

The choice of a holiday context is not accidental. Travel reservations typically involve transactions of several hundred or thousands of euros, which predisposes victims to believe there is a real problem with the payment made. This is compounded by an emotional factor: someone who has just planned their holidays can react impulsively when faced with the fear of losing the reservation or facing unexpected charges.

The National Police have detailed several indicators to identify these fraudulent messages. No legitimate banking entity requests sensitive data via SMS or asks its customers to call numbers provided through that channel. When there is a real issue, banks use electronic banking, certified mail or calls from verifiable numbers on their corporate websites.

Time pressure is another warning sign. The scammers warn of immediate consequences if action is not taken quickly, a tactic designed to prevent the victim from checking the information against official sources before responding. Spelling or grammatical errors, although increasingly less frequent due to the professionalisation of cybercrime, remain relevant indicators, as do generic senders or unknown numbers.

Source: Google News ES — Crime (es)

Read this article in the original language