All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
That vacation photo may reveal far more than you intended, even after you turn off location tagging.
McAfee researchers found that Qwen3-VL 30B, a freely available vision-language model from Alibaba’s Qwen team, could correctly identify the city and country shown in a travel photo 91% of the time. Gemma 3 27B, a model from Google DeepMind, reached 87% accuracy.[1]
Neither model received any GPS coordinates, hidden metadata, or even the photo’s filename. They found the location using only details visible in the picture.
For scammers, those details can turn a generic phishing message into something disturbingly personal. A fake bank text warning about a transaction overseas becomes much more convincing when it correctly names the city you’re visiting.
The technology also makes that personalization easy to automate. One publicly shared photo could give a scammer the location, context, and believable story they need to target you or someone you know.
Removing photo metadata won’t hide your location
How accurate is AI photo geolocation?
How to protect your vacation photos from scammers
Bottom line
How scammers can find you through a photo
A scammer doesn’t need to hack your phone or access your social media account. McAfee describes a process that begins with photos people have shared publicly on Instagram, Facebook, or X.
The scammer could download a photo and submit it to an AI vision model with a simple question: Where was this picture taken?
From there, the attack could unfold like this:
- The AI identifies the likely city, country, or region.
- The scammer checks when you posted the photo and gathers other public information from your profile.
- They write a message that references your destination.
- They send it while you’re traveling or shortly after you return.
The resulting message could claim your card was used in the country you’re visiting. This type of targeted smishing scam may be quite convincing when it correctly references your destination. Someone could pose as your hotel and ask you to reconfirm a reservation through a malicious link. Your friends or relatives might receive a message saying you’re stranded abroad and urgently need money.
The location only needs to be accurate enough to make the scam feel plausible.
McAfee says every step, from collecting pictures to producing targeted messages, can be automated. That could allow scammers to personalize phishing attempts in bulk without researching each victim by hand.
Removing photo metadata won’t hide your location
Photos can contain Exchangeable Image File Format (EXIF) data, which may include the date, device information, and GPS coordinates associated with an image. Removing that information is still worthwhile, although it won’t defeat the technique McAfee tested.
The researchers specifically excluded metadata, EXIF data, and file naming conventions. The AI models received only the visible image.
Those visuals contain plenty of clues. AI can examine:
- Landmarks and skylines
- Storefronts, food stalls, and transportation
- Street signs, road markings, and local languages
- Building materials and architectural styles
- Plants, landscapes, weather, and lighting
Some of those details are obvious. A famous building in the background can quickly expose a city. Others are easy to miss.
In one smaller experiment, an ordinary sunset photo was correctly traced to Hastings-on-Hudson, New York. Another close-up picture showed little more than tulips, yet AI identified the location as Keukenhof Gardens in the Netherlands based on the flowers and their arrangement.
Even generic beaches, rural roads, and hotel rooms can provide enough information to identify a country.
Cropping out a street sign or recognizable building could make identification harder, although it can’t guarantee anonymity. A photo may contain location clues you don’t recognize yourself.
How accurate is AI photo geolocation?
McAfee tested 21,236 travel images from publicly available research datasets. A standardized prompt asked Qwen3-VL 30B and Gemma 3 27B to identify each location using only the visual content.
Qwen3-VL 30B correctly identified both the city and country in 91% of the images. Gemma 3 27B achieved 87% accuracy. When the models missed the city, McAfee says they identified the correct country in nearly every case.
The company ran both models locally and used an automated Python script to process the images. A scammer using the same setup could avoid the rate limits and abuse monitoring found on public AI platforms.
McAfee also tested 102 personal travel photos contributed by employees. Accuracy fell compared with the larger dataset, although the models could still identify the country often enough to support a targeted scam.
The 91% figure applies to Qwen3-VL 30B when tested against a travel-image dataset, so results will vary by tool and photo.
The research establishes that criminals could use photo geolocation at scale. McAfee did not document an active criminal group caught using this exact workflow.
However, similar scams already rely on publicly shared pictures and personal details. The FBI has warned that virtual kidnappers take photos from social media and alter them to create fake proof-of-life images, while bank impersonators use familiar information to make bogus fraud alerts feel legitimate. AI geolocation could give those criminals another credible detail without requiring access to GPS data.
The tools and information needed to replicate McAfee’s findings are already accessible. McAfee published its complete testing process, including the models, dataset, and definition it used to judge accuracy.
How to protect your vacation photos from scammers
Turning off geotags remains a sensible precaution. Your posting habits and response to suspicious messages now matter just as much.
Wait until you return home
Posting in real time can tell strangers where you are and when you’re away from home. Save your photos and share them after the trip. If you want to post while traveling, avoid revealing your hotel, current activities, or itinerary.
Restrict who can see your pictures
Set personal accounts to private, review your followers, and follow these additional social media safety tips. Public photos are easier to collect and analyze automatically.
Remember that a private post can still be saved or reshared. Avoid posting anything that could seriously endanger you if it reached a wider audience.
Check the entire background
Look beyond the main subject before uploading. Street signs, hotel names, boarding passes, and storefronts can reveal your location directly. Less obvious scenery can still help AI narrow it down, so cropping offers only limited protection.
Don’t trust a message because it knows where you are
A correct location is no longer proof that a message came from your bank, airline, or hotel. Treat unexpected urgency as a warning, especially if the sender asks you to click a link, confirm a password, or move money. If a scammer has your number, block them.
The Federal Trade Commission recommends contacting the actual organization through a phone number or website you already know is legitimate. Never use the contact information included in the suspicious message.
For a supposed bank alert, open your banking app yourself or call the number printed on the back of your card.
Warn friends and family
Photo geolocation can also support emergency scams targeting people close to you. Tell family members to verify unexpected requests for money through another channel. A private code word can help them confirm whether a request genuinely came from you.
Bottom line
Free AI models can use the visible details in your pictures to identify where they were taken, even after metadata and location tags are removed. Posting while you’re still traveling gives scammers the most timely information.
Share vacation photos after returning home, restrict who can see them, and carefully inspect their backgrounds. If an unexpected message correctly names your location, verify it through the company’s official app, website, or phone number. Familiar details can make a scam believable, but they don’t make it legitimate.