The fraud targeting your agency today is not what you were trained for.
Most travel agencies have some version of fraud awareness in place. Chargeback policies. A reminder not to share passwords. A vague sense that phishing emails are something to watch out for.
It’s not enough. Not anymore.
The criminals targeting travel agencies in 2026 are using tools that did not exist 18 months ago.
Account takeover: When the criminal becomes an insider
When a fraudster obtains your agency’s ARC/BSP or IATA accreditation number, they don’t announce themselves. They enter your GDS or NDC channel using your legitimate credentials, behave like a normal agency (sometimes for days) and wait. When they act, they act fast, typically over a weekend or public holiday, using cash as the payment method so that liability falls entirely on the agency.
AI-powered impersonation: Phishing, brand cloning, and what’s next
The phishing emails that were easy to spot a few years ago due to misspellings and obvious urgency are gone. Today’s attacks are grammatically flawless and engineered to bypass rational thinking. Criminals can clone your agency’s domain, replicate your communication style, and create a fraudulent version of your business that your own clients cannot distinguish from the real thing.
Voice cloning and deepfake video are not yet widely reported within the travel agency channel specifically, but the technology is already being used to defeat biometric verification in financial services, including fabricating identity documents and fooling bank authentication systems.
Security in the NDC era
As agencies move onto NDC platforms, they’re entering a new digital environment with new security considerations. Gonzalo explains how LATAM is responding, through its Security Culture initiative, smarter anomaly detection, and the shift toward passkey authentication, and what agencies need to do to stay protected as these systems evolve. The principle is simple: agencies that delay adopting new security upgrades become the easiest target. Criminals don’t attack the strongest link.
The human firewall: where most agencies are actually failing
Nine times out of ten, according to ARC’s data, a compromised agency traces back to human error rather than a technology failure – a person who clicked a link under pressure or shared credentials without adequate due diligence.
The session examines what separates agencies that get hit from agencies that don’t – and it’s not primarily about technology spend.
Eight things Cornelius and Gonzalo say every agency should do now:
This is a practical, expert-led session built for travel agency owners, managers, and advisors who want to understand the real threat landscape – and take concrete action.
Brought to you by WTAAA – uniting global travel agency associations to keep the profession informed, protected, and future-ready.
The Human Firewall is a WTAAA expert series on the fraud threats facing travel agencies globally.
Part 1: Know Your Enemy (you are here)
Account takeover, AI-powered phishing, and the human vulnerabilities criminals exploit.
Part 2: The Payment Layer
WTAAA sits down with Mastercard to examine the payment fraud risks most agencies don’t know exist, including VCN vulnerabilities, identity verification beyond passwords, and what predictive fraud intelligence means for your business.
A WTAAA Global Industry Report:
The Human Firewall: How AI-Powered Fraud is Targeting Travel Agencies, and What the Industry Must Do About It
This whitepaper maps the threat landscape as it exists today, drawing on practitioner expertise and multiple data sources to provide a comprehensive overview.
>> Coming soon