Back to ledger
GBThe GuardianScams

‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos

Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. “We detected unusual activity while you were

Open original article
Ledger record
#106
First seen
17 Aug 2026, 21:26 UTC
Last checked
25 Aug 2026, 06:56 UTC
Version history
1 version
Current fingerprint
10484793d532...10586e
01

Publisher layer

Recorded article metadata

Publisher
The Guardian
Country
England / United Kingdom
Source published
16 Aug 2026, 06:00 UTC
Source updated
No update timestamp supplied
Byline
Shane Hickey
Section
Scams
Source-supplied excerpt
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. “We detected unusual activity while you were
02

Change layer

Observed version timeline

  1. 1
    Initial capture

    ‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos

    Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details You are on a short break in Porto and post some pictures of your family on Instagram or Facebook. With a small section of the Douro river in the background, you think it could have been taken anywhere. A few days later, you get a text saying that your card was compromised. “We detected unusual activity while you were

    Changed fieldstitlebylinedescriptionTextcontentTextsourcePublishedAtsourceUpdatedAtsectionimageUrltags
    Version SHA-256
    10484793d532...10586e
    Capture SHA-256
    2bce3d4df01c...722802
03

Interpretation layer

Labels with declared origins

Not an adjudication.

Publisher categories are copied from source metadata. Machine signals report observable wording or format and do not determine truth, intent, ethics, or wrongdoing.

  • machine content-type Reported news observable-rules-v1 / 70% rule confidence
  • publisher category AI (artificial intelligence) rss-category
  • publisher category Banks and building societies rss-category
  • publisher category Consumer affairs rss-category
  • publisher category Europe rss-category
  • publisher category Money rss-category
  • publisher category Scams rss-category
  • publisher category Technology rss-category
  • publisher category Travel rss-category
  • publisher category UK news rss-category
  • publisher category US news rss-category
  • publisher category World news rss-category
04

Public response layer

Reception snapshots

No reviewed reception capture yet.

Comment counts and samples remain absent until a lawful, source-specific capture method is reviewed. Absence is recorded instead of estimated.

05

Evidence layer

Capture provenance

Capture ID
#1
Observed
17 Aug 2026, 21:26 UTC
HTTP result
200 / parsed
Raw payload
460,621 bytes, private gzip evidence
Collector
news-ledger/0.1
Public boundary
metadata and excerpt