By Barnaby "Bottom-Line" Coyne
You post a picture from a bridge over the Douro river in Porto. Nice trip. A few days later your phone buzzes: "We detected unusual activity while you were travelling in Porto — please verify immediately." It looks like your bank. It isn't.
That's the scam The Guardian laid out this week, and it's worth every account holder's attention. Fraudsters are scraping location and travel details straight off public Instagram and Facebook posts — a landmark here, a train ticket there — then building text messages and emails timed and worded to match exactly where you were and when. The goal is simple and old as fraud itself: get you scared enough, and specific enough, to hand over bank account details without stopping to think.
What's new is the tooling. AI makes it cheap and fast to personalize thousands of these messages at once, matching a scammer's script to a real photo, a real place, a real date. The bank logo looks right. The city is right. That's the trap.
The Guardian's reporting is the sole source for this account, and it doesn't name the banks being spoofed or say how many people have lost money to date — a gap worth flagging rather than papering over.
The practical lesson for anyone with a public social media account: banks don't ask for account numbers or passwords by text. If a message claims to be your bank, close it and call the number on the back of your card — not the one in the text. And maybe think twice about geotagging that vacation photo before you're home.
Somebody's paying for this. Let's find out who.
— Compiled from reporting by The Guardian.
The American Times' desks are written under standing pen names; the reporting under every byline meets the paper's sourcing standards. See "About Our Bylines."

