Summer means holidays, last-minute bookings, and offices operating with smaller teams. For hackers, it means fewer checks, longer response times, and more opportunities. Data from 2026 shows that the holiday season is already being exploited on a large scale.
The numbers behind the season
Check Point reported that, in May 2026, the hospitality, travel, and leisure sector experienced more than 2,000 cyberattacks per organisation every week. This represents a 24% increase compared with May 2025 and a 122% increase compared with May 2023. By comparison, the annual increase across all industries was only 2%.
Cyberattacks generally intensify during holiday periods, both throughout the summer and during the end-of-year season, when online activity and transaction volumes increase significantly.
Why summer works so well for attackers
It is not a coincidence. It is a deliberate strategy built around several predictable vulnerabilities:
- Reduced staffing and disrupted approval chains. With key decision-makers away, employees are less likely to verify unusual requests, creating ideal conditions for Business Email Compromise attacks: “Transfer the money urgently, I’m travelling.”
- Slower response times. IT and security teams often operate with reduced coverage, which means that an incident discovered on Friday evening may remain unattended until Monday morning.
- Distraction and urgency. Employees and consumers are focused on planning their holidays, not on checking whether a link is suspicious. At the same time, generative AI is making phishing messages increasingly difficult to distinguish from legitimate communication.
- Public networks and personal devices. Hotel Wi-Fi check-ins, work laptops connected from airports, and booking apps installed in a hurry all expand the potential attack surface.
The types of attacks that dominate the season
Coordinated campaigns involving the mass registration of hotel-themed lure domains have been observed, alongside campaigns impersonating well-known financial brands through fake travel reward offers. These are accompanied by more traditional attack methods:
- Cloned websites that imitate major booking platforms, such as Booking, Airbnb, and airline websites, and are designed to steal personal information.
- E-mails claiming that “your booking has been cancelled” or asking users to “confirm payment,” creating a false sense of urgency.
- Fake Wi-Fi networks, also known as “evil twin” networks, in airports, hotels, and cafés, which imitate the name of the official network.
- Traditional BEC attacks, which exploit the absence of managers and the difficulty of quickly verifying an “urgent” request.
It is important to note that HTTPS and modern encryption have reduced the risk of data being directly intercepted on public networks. However, the danger has not disappeared. Attackers increasingly use fake Wi-Fi networks and login pages that appear legitimate. In other words, the connection may be encrypted, but the recipient of the information may still be an attacker.
How companies and their employees can protect themselves
- Maintain security visibility regardless of the season. Automate routine tasks and monitor systems continuously rather than expecting employees to give up their holidays.
- Verify every urgent request involving a bank transfer or a change to payment details through a second communication channel, especially when the request comes from someone who claims to be travelling.
- Update emergency contact lists and approval chains before the holiday season begins, so there are no gaps in the verification process.
- Educate teams about seasonal risks, including fake bookings, cancellation emails, and unknown Wi-Fi networks, rather than focusing only on generic phishing scenarios.
- Encourage employees to use a mobile hotspot instead of public Wi-Fi for sensitive activities, such as accessing business accounts or connecting to a corporate VPN. Two-factor authentication should also be enabled wherever possible.
Summary
Summer does not create new vulnerabilities. It amplifies the ones that already exist: reduced staffing, rushed decisions, and distraction. The difference between companies that are affected and those that make it through the season unharmed is not necessarily their budget, but their consistency.
A security assessment can identify the exact weaknesses that become easy targets when a team is operating at half capacity.