Guidance Article

UK holidaymakers warned as NCSC says Russian-linked phishing targets travel and messaging apps

Published on 24 July 2026 | Cybersecurity

UK holidaymakers warned after NCSC alert on Russian-linked phishing in messaging apps

UK travellers and holidaymakers should take note of a recent warning from the National Cyber Security Centre (NCSC): Russia-based actors have been using messaging apps to target people, especially those who may be seen as high-value or high-risk targets. The NCSC said it has seen growing malicious activity involving messaging apps, alongside guidance from international partners on phishing campaigns aimed at commercial messaging applications. (ncsc.gov.uk)

This matters for ordinary holidaymakers because the same tricks used against more sensitive targets can also be adapted for travel-related scams: fake booking messages, fake airline support accounts, bogus hotel contacts, or “urgent” texts and chat requests that try to get you to click a link or share a code. The NCSC’s general phishing guidance says attackers use messages that may lead to malware, credential theft, or money loss. (ncsc.gov.uk)

What happened

On 31 March 2026, the NCSC published a warning about malicious activity from Russia-based actors using messaging apps. In the same period, the FBI and CISA also warned that Russian intelligence-linked actors were targeting commercial messaging applications with phishing techniques designed to capture account PINs, two-factor authentication codes, or to add an attacker’s device as a linked device. (ncsc.gov.uk)

The NCSC said this is part of a broader pattern of targeted phishing and social engineering. In practical terms, that means the attacker may pose as someone familiar, trusted, or official, and try to get the victim to act quickly. (ncsc.gov.uk)

Why it matters to UK holidaymakers

Holiday planning usually involves lots of digital contact: booking sites, airline apps, hotel confirmations, ride-hailing apps, parcel updates, and messaging apps used to coordinate with family or travel companions. That creates more chances for someone to send a convincing fake message at just the right time. The NCSC says phishing is when scammers send messages or texts containing links to sites that may contain malware or trick people into giving away passwords or money. (ncsc.gov.uk)

If a criminal gets into your messaging account, they may be able to:

  • impersonate you to friends or family
  • ask for emergency money
  • reset other accounts linked to your phone number or email
  • access travel confirmations and personal information

The NCSC and FBI guidance suggests that messaging-app attacks can lead to account takeover, especially where attackers obtain verification codes or trick users into linking a new device. (ncsc.gov.uk)

Who may be affected

The NCSC’s March 2026 warning focused on high-risk individuals, and its guidance is especially relevant to people whose work, travel, or contacts may make them more exposed to targeted phishing. That said, travel-themed scams are often broad and opportunistic, so any holidaymaker using messaging apps, email, or booking services could be caught out. (ncsc.gov.uk)

You may be at higher risk if you:

  • use messaging apps to organise travel or stay in touch while abroad
  • book accommodation, flights, ferries, or tours online
  • often receive links, QR codes, or verification codes by text or chat
  • travel with children, older relatives, or colleagues who may also be targeted

Warning signs to look out for

Phishing messages can look polished, but there are common red flags. The NCSC advises people not to click suspicious links or install software if prompted, and to be wary of unknown message requests. (ncsc.gov.uk)

  • Unexpected messages about booking changes, refunds, customs fees, or missed deliveries
  • Urgent pressure to act now, often with a threat such as “your account will be closed”
  • Requests for a one-time passcode, PIN, or verification code
  • Links that take you to a login page you were not expecting
  • Messages from a known contact that feel unusual, rushed, or out of character
  • QR codes sent through chat or email without a clear explanation

The FBI’s March 2026 guidance says attackers often impersonate a contact and send a malicious link or QR code, or ask for a PIN and two-factor code. (ic3.gov)

What readers should do now

If you are travelling soon, or already on holiday, take a few simple steps now. The NCSC says if you have opened a suspicious link or installed software, you should run a full antivirus scan if available. (ncsc.gov.uk)

  • Do not click links in unexpected messages.
  • Do not share verification codes, PINs, or passwords with anyone.
  • Check through a second channel before acting on any “urgent” request, such as calling the airline, hotel, or contact directly using a known number.
  • Review linked devices in your messaging apps and remove anything you do not recognise.
  • Enable two-step verification on messaging and email accounts if available.
  • Update your apps before you travel, especially messaging, email, and banking apps.
  • Run an antivirus scan if you have clicked something suspicious or installed anything you did not expect. (ncsc.gov.uk)

If you think a message is suspicious, the NCSC says you can report suspicious emails through its reporting service and find advice on phishing actions. (ncsc.gov.uk)

How to stay safer next time

A calm, routine approach is best. Most phishing works because it creates pressure, not because it is especially technical. The NCSC recommends being cautious with unknown accounts and, for messaging apps, considering a phone call or other secure method to verify who you are dealing with. (ncsc.gov.uk)

  • Use official apps and official app stores only.
  • Keep your phone locked with a strong passcode, biometrics, and automatic updates.
  • Turn on two-factor authentication, preferably using an authenticator app where possible.
  • Never reuse passwords across travel, email, and banking accounts.
  • Before a trip, save trusted contact numbers offline in case your inbox or messaging app is compromised.
  • Be cautious with “message requests” from people you do not know.

The NCSC also points high-risk users to extra protections such as its personal internet protection service, which can help block access to known malicious domains on personal devices. Availability and suitability may vary, so check the current NCSC guidance before relying on it. (ncsc.gov.uk)

What we know, and what is uncertain

What is clear is that the NCSC has warned about Russia-based actors abusing messaging apps and that partner agencies have issued similar warnings about phishing against commercial messaging applications. What is less certain is whether a given travel scam is directly linked to the same actors; many scams are copied and reused by different criminals. So if you get a suspicious travel message, treat it as unsafe regardless of who appears to be behind it. (ncsc.gov.uk)

Key takeaway

Holidaymakers do not need to panic, but they should be careful. If a travel-related message, booking update, or chat request feels urgent or unusual, do not click, do not share codes, and verify it using a trusted contact method. (ncsc.gov.uk)

Sources