All the secrets of Cyber Security: Cyberoo's blog.

Cybersecurity on the go: how can you protect your data and devices on holiday?

Written by CYBEROO Global | 6 August 2026

To protect data and devices whilst travelling, you need just a few rules applied properly: updates before setting off, phishing-resistant multi-factor authentication, reliable connections, verified backups, and vigilance regarding QR codes, urgent requests and unusual login attempts. For those travelling with company data, however, security cannot stop at good personal habits: continuous monitoring and response are required.

 

Why is cyber security whilst travelling important?

Outside the office, connections, rhythms and habits change. People work from airports, hotels and shared spaces, use their smartphones more often and tend to react quickly to notifications and requests. It is precisely this combination of mobility, urgency and reduced control that provides fertile ground for phishing, credential theft and impersonation.

The figures show just how much the landscape has changed. According to the Cyberoo Observatory 2026, in 2025, 320 new threat actors were identified, 38,654 suspicious domains were detected, over 1,300 reports were made to the authorities regarding phishing, anti-spam and anti-fraud, and more than 2,700 unique vulnerabilities associated with the monitored providers were identified. The point is not just that attacks are on the rise: they are becoming more credible, faster and harder to distinguish from legitimate activity.

The ENISA Threat Landscape 2025, based on 4,875 European incidents, confirms that phishing and the exploitation of vulnerabilities remain among the main vectors of attack.

 

What are the most common cyberattacks whilst travelling?

In recent years, the most obvious risk was connecting to an open Wi-Fi network. That danger still exists, but today it is only part of the problem. Attackers primarily target digital identity: passwords, session cookies, OAuth tokens and existing authorisations. If they manage to steal these, they can gain access without ‘forcing’ anything and appear as a normal user.

Phishing, quishing and urgent requests generated by AI

Emails riddled with errors are no longer the norm. Artificial intelligence enables the creation of messages that are grammatically correct, contextualised and consistent with the tone of a colleague, a manager, an airline or an accommodation provider. Added to these are quishing, which uses QR codes to lead to fake login pages; smishing via text messages or messaging apps; and vishing, involving phone calls or voice messages designed to create a sense of urgency.

Fake Wi-Fi networks and traffic interception

A network named ‘Airport Free WiFi’ or ‘Hotel Guest’ may appear genuine without actually being so. A criminal can create an access point with a credible name, trick a device into connecting, and display a fake login portal to collect credentials or payment details. Even on a legitimate network, an out-of-date or poorly configured device may remain vulnerable.

Infostealers, session hijacking and access from unmanaged devices

B InfostealersB do not just target passwords. They can steal cookies, tokens, cloud credentials and already authenticated sessions. This makes it risky to work from a personal, shared or non-company-managed computer: a seemingly legitimate login may in fact be the result of a stolen session. Recent statistics indicate that credential misuse is the primary attack vector in the breaches analysed, accounting for 22 per cent of cases.

Juice jacking, USB ports and insecure charging

Public charging stations are convenient, but not always reliable. The risk can be reduced by using your own power adaptor plugged into a mains socket, a company power bank or a cable designed solely for charging. If a request for data transfer or authorisation appears on the screen, you must decline it.

Physical theft, shoulder surfing and oversharing on social media

A laptop left open, a password typed in full view of others or a photo of a boarding pass posted on social media can provide useful information for mounting an attack. Even announcing a business trip in real time can help make a fake message more credible: “I’ve seen you’re in Berlin – can you approve this payment straight away?”.

 

How can you protect your data and devices before setting off?

Travel security starts before you pack your suitcase. Update your operating system, browser, VPN and apps, then restart your devices to complete the installations. Enable disk encryption and automatic lock, check that your backup is up to date and can be restored, and take with you only the data you really need.

For work accounts, use unique passwords and an approved password manager. Where possible, opt for phishing-resistant authentication, such as passkeys or FIDO2 keys, rather than relying solely on codes received via text message or push notifications, which can be subject to MFA fatigue. Also, disable automatic connection to Wi-Fi networks and Bluetooth when not in use.

 

What rules should you follow whilst travelling?

  • Use a personal hotspot or mobile data. If you must use public Wi-Fi, check the exact network name with staff and enable your company’s VPN before accessing sensitive services.
  • Avoid carrying out sensitive tasks on shared devices. Check-ins, printing and quick browsing do not justify accessing your work email or cloud services from a public computer.
  • Do not scan QR codes blindly. Check the destination domain and, if the page asks for credentials or payment, access the service via the official app or by typing in the known address.
  • Verify urgent requests via an alternative channel. Payments, document sharing and MFA resets must be confirmed using a known contact, not by replying to the message itself.
  • Keep your devices with you. Use a privacy filter where necessary, lock your screen even for just a few minutes, and do not leave devices or access badges in your car or in an unsecured room.
  • Report any anomalies immediately. A lost phone, an unexpected MFA notification or a suspicious login must be reported straight away to the IT or security team.

 

What should you do if you suspect an attack whilst you are away from the office?

Do not wait until you return. Disconnect the device from the network without switching it off if company procedures require you to preserve evidence; contact your IT contact person or the SOC immediately and explain what happened, when and on which device. From a trusted device, change the relevant credentials and revoke active sessions by following the security team’s instructions. In the event of theft or loss, immediately activate the company procedure for remote locking and wiping.

 

Who are VIP users and why do they require greater protection?

A VIP user is not necessarily the CEO. It can be anyone with access to critical information, the ability to authorise payments, administrative privileges or a credible identity in the eyes of colleagues and partners. Whilst travelling, their exposure increases: a public diary, absence from the office and intensive use of a smartphone provide attackers with useful elements for carrying out spear phishing, Business Email Compromise and voice or video impersonations.

These users require additional controls: phishing-resistant MFA, two-factor verification for sensitive transactions, least privilege, monitoring of credentials exposed on the dark web and detection of domains that mimic the brand or personal identity. Protection must also cover laptops, smartphones, cloud accounts and SaaS services, not just the corporate network.

 

Why are best practices alone not enough?

User vigilance remains essential, but by 2026 an attack may utilise valid credentials, stolen sessions and legitimate tools. This is why organisations must be able to recognise subtle indicators such as logins from unusual countries, impossible travel, new devices, forwarding rules created in email inboxes or anomalous downloads from the cloud.

Cyberoo’s approach combines Managed Detection and Response and Cyber Threat Intelligence to monitor internal and external threats and respond continuously. In the systemic cybersecurity model, Threat Management is integrated with governance, compliance and staff training: the aim is not to add yet another tool, but to reduce risk in a coordinated manner, even when teams are on holiday and offices are empty.