‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. “We detected unusual activity while you were
Open original article- Ledger record
- #106
- First seen
- 17 Aug 2026, 21:26 UTC
- Last checked
- 25 Aug 2026, 06:56 UTC
- Version history
- 1 version
- Current fingerprint
10484793d532...10586e
Publisher layer
Recorded article metadata
- Publisher
- The Guardian
- Country
- England / United Kingdom
- Source published
- 16 Aug 2026, 06:00 UTC
- Source updated
- No update timestamp supplied
- Byline
- Shane Hickey
- Section
- Scams
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. “We detected unusual activity while you were
Change layer
Observed version timeline
-
1
‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. “We detected unusual activity while you were
Changed fieldstitlebylinedescriptionTextcontentTextsourcePublishedAtsourceUpdatedAtsectionimageUrltags- Version SHA-256
10484793d532...10586e- Capture SHA-256
2bce3d4df01c...722802
Interpretation layer
Labels with declared origins
Publisher categories are copied from source metadata. Machine signals report observable wording or format and do not determine truth, intent, ethics, or wrongdoing.
- machine content-type Reported news observable-rules-v1 / 70% rule confidence
- publisher category AI (artificial intelligence) rss-category
- publisher category Banks and building societies rss-category
- publisher category Consumer affairs rss-category
- publisher category Europe rss-category
- publisher category Money rss-category
- publisher category Scams rss-category
- publisher category Technology rss-category
- publisher category Travel rss-category
- publisher category UK news rss-category
- publisher category US news rss-category
- publisher category World news rss-category
Public response layer
Reception snapshots
Comment counts and samples remain absent until a lawful, source-specific capture method is reviewed. Absence is recorded instead of estimated.
Evidence layer
Capture provenance
- Capture ID
- #1
- Observed
- 17 Aug 2026, 21:26 UTC
- HTTP result
- 200 / parsed
- Raw payload
- 460,621 bytes, private gzip evidence
- Collector
- news-ledger/0.1
- Public boundary
- metadata and excerpt