Authorities as well as cyber security professionals have issued an alert to tourists visiting Oman to be on the guard against a spate of travel-related scams online that have increased in recent times as hackers adopt the strategy of masquerading as airlines and hotel companies in order to swindle people of money, banking details and other personal information. This alert has been issued at a time when year round travel has continued even as the summer season has come to an end.
According to researchers, the scam is being carried out by making use of the reputation of various travel companies. Victims are often persuaded to share sensitive financial information, make advance payments or click malicious links under the guise of confirming reservations or claiming refunds.

According to global cybersecurity company Kaspersky, nearly 270,000 cyberattack attempts linked to major travel brands were detected worldwide between the second quarter of 2025 and the first quarter of 2026. Airlines and transport providers accounted for the largest share of these attacks, with cybercriminals using counterfeit websites and phishing campaigns to capture customer credentials. Researchers also identified widespread use of banking Trojans capable of stealing financial data and providing attackers with access to victims’ bank accounts.
One of the fraudulent schemes involved fake compensation offers impersonating a European airline, where travellers were asked to pay a small processing fee or enter banking credentials to receive a refund. Another common tactic targeted accommodation bookings through counterfeit hotel reservation pages that appeared genuine until customers arrived to discover no booking had been made. Cybersecurity experts stressed that legitimate airlines and hotels do not request compensation fees or sensitive payment information through unsolicited messages.
Oman’s Consumer Protection Authority (CPA) has also urged residents to verify website authenticity before completing online transactions or submitting complaints. Officials advised consumers to ensure government websites begin with “https” and end with “.gov.om”, warning that even minor differences in web addresses could indicate phishing attempts. Travellers were also encouraged to review cancellation policies, confirm reservation details directly with service providers and avoid making payments over unsecured public Wi-Fi networks. The warning follows a recent fraud case in Dhofar, where several residents reportedly lost between OMR100 and OMR1,500 after a bogus travel agency lured customers with heavily discounted overseas holiday packages before disappearing with their payments. Authorities say the incident highlights the increasing sophistication of travel-related fraud and the importance of verifying offers through official channels before making any financial commitment.



