Attempted carding now accounts for more than one in six checkout requests at the most heavily attacked travel businesses, according to a guide HUMAN Security released in September 2026, a near sixfold rise since 2022 that lands as AI agents built to search fares and book rooms send a disproportionate share of their traffic toward the sector.
In Short
A security company that watches a vast amount of website traffic says travel sites are being hit hard by both helpful AI bots and criminal ones, and the criminals are testing stolen payment cards at checkout far more often than four years ago. Your hotel points, airline miles and saved card details are what they are after, and stolen travel accounts have become cheap to buy on hidden online markets. Because a helpful AI assistant booking a trip can behave exactly like a fraud bot, travel companies are being pushed to judge what each visitor is trying to do rather than simply whether it is a machine.
A guide without a date
HUMAN Security, the New York-headquartered company behind the Human Defense Platform, has published "The 2026 Guide to AI, Agentic Traffic, and Cyberthreats for Travel and Hospitality", a 13-page document that narrows the company's annual benchmark data to a single industry. A companion edition covers retail and e-commerce. Neither the guide nor its landing page carries a publication date. The PDF file records a creation date of September 2, 2026, and the guide is listed on HUMAN's resources page after the company's late-July FunFoneFarm research, which places its release in September.
It is not a fresh dataset. The guide recombines two pieces of research HUMAN had already put into circulation. The first is the 2026 State of AI Traffic & Cyberthreat Benchmark Report, which, according to HUMAN, was based on more than one quadrillion interactions analysed in 2025. HUMAN's newsroom dates the US release of that report to March 26, 2026; an international distribution followed on April 9, the date PPC Land used when it examined how AI agents and fraud had become indistinguishable. The second is a survey of more than 2,400 Americans conducted in February 2026, the results of which HUMAN published on May 13 and which PPC Land covered in June.
What the travel edition adds is the vertical cut: four-year attack series for travel at both the median and the 90th percentile of HUMAN's customers, a dark web price table that goes beyond the two travel listings reported earlier, and survey breakdowns on who travellers think should pay when an AI booking goes wrong. The footnote is specific about scope. Attack data covers interactions observed across HUMAN's customer base from 2022 to 2025.
Where AI traffic lands
HUMAN defines AI-driven traffic as traffic generated by or on behalf of AI systems. According to the guide, it nearly tripled over the course of 2025, and more than 95 percent of it was concentrated in three industries: retail and e-commerce, streaming and media, and travel and hospitality. The company divides that traffic into three categories. Travel's position is different in each.
Training crawlers, the bots that collect material for model training, sent 16.60 percent of their traffic to travel and hospitality, making it the third-largest vertical. Retail took 62.50 percent and media 19.70 percent, so the three together accounted for more than 98 percent of training crawler volume. Tech, SaaS and services received 1.10 percent, financial services 0.09 percent and everything else 0.10 percent. According to HUMAN, the concentration reflects the value of structured travel data, such as flights, hotel availability and pricing, as input for AI travel assistants and comparison tools.
AI scrapers, which fetch pages in real time, sent 21.10 percent of their traffic to travel. Streaming and media received 40.90 percent and retail 36.70 percent; the three combined accounted for 98.70 percent. HUMAN links scraper demand to dynamic pricing tools, fare comparison engines and AI travel agents, and says the holiday travel season in 2025 intensified demand for real-time pricing data across both travel and retail.
The third category, agentic AI, covers software that acts on pages rather than reading them. Travel captured 19.2 percent of all agentic traffic in 2025, third behind retail at 46.6 percent and streaming and media at 28.5 percent. Tech, SaaS and services took 4.10 percent, financial services 0.23 percent and other sectors 1.37 percent.
The sharper figure sits beneath that total. HUMAN separates agentic browsers, such as Perplexity's Comet, from purpose-built agents, which it describes as systems designed for narrow, task-specific workflows. The browsers concentrate in e-commerce. The purpose-built agents do not: 38.4 percent of their traffic was directed at travel sites. "These are agents designed to search fares, compare hotels, and complete bookings autonomously," the guide states. HUMAN's interpretation is that the travel booking workflow is one of the first to be automated end to end.
Annual shares also age quickly. HUMAN's monthly benchmark series has since put travel lower, at 13.7 percent of agentic traffic in May 2026, a month in which the share of agent traffic that site operators blocked climbed to nearly 9 percent. The monthly reports cover a different period and are not a like-for-like comparison with the 2025 annual figure. The travel guide does not refer to them.
Four years of attacks, two very different curves
The cyberthreat section splits each attack type into two lines. One tracks the median HUMAN customer in travel and hospitality. The other tracks heavily targeted businesses, which HUMAN defines as the 90th percentile of organisations included in the research. Most of the guide's alarm comes from the second line; most travel businesses sit closer to the first.
Scraping
The median scraping rate has barely moved: 5.70 percent of traffic in 2022, 4.52 percent in 2023, 4.38 percent in 2024 and 4.78 percent in 2025. HUMAN's gloss on that flat line is pointed: "stability is not the same as safety." A consistent attack rate, the guide argues, reflects attackers' belief that the industry remains worth targeting.
At the 90th percentile the series swings wildly, from 17.43 percent in 2022 to 43.13 percent in 2023, down to 27.62 percent in 2024 and up to 47.77 percent in 2025. That last figure, nearly 48 percent of traffic to product or listing pages, is the highest in the four-year series.
The guide's main argument about web scraping in travel is that the legitimate and the hostile now want the same things. AI scrapers and threat actors both target real-time pricing, inventory and availability, according to HUMAN, and the sectors receiving the most AI crawler traffic mirror those most affected by malicious scraping. That overlap makes it harder to separate model-driven automation from data extraction. HUMAN has been tracking the problem for some time; in 2024 it documented a 107 percent year-over-year increase in scraping attacks.
Carding
Here the two curves diverge most sharply. Carding, the practice of testing stolen payment cards through checkout flows, ran at 0.16 percent of checkout traffic for the median travel business in 2022, rose to 0.59 percent in 2023, then fell to 0.45 percent in 2024 and 0.35 percent in 2025. For the typical company, carding has declined for two consecutive years.
At the 90th percentile it has done the opposite: 3.10 percent in 2022, 4.45 percent in 2023, 8.56 percent in 2024 and 17.60 percent in 2025. The rate more than doubled in a single year and grew nearly sixfold over four. In 2025 the heavily targeted group's rate was roughly 50 times the median. So is the travel sector seeing more card fraud, or less? The guide's data points to concentration: attackers appear to be pressing harder on a minority of businesses rather than raising pressure across the board.
Seasonality compounds it. One unnamed airline saw attempted carding climb from less than 1 percent of transactions early in 2025 to more than 8 percent at the height of summer, before falling back below 1 percent by year-end. HUMAN states that its customer was protected from the attack, a claim the guide does not substantiate with outcome data.
AI agents have entered the same workflow. HUMAN's Satori Threat Intelligence team observed carding-like patterns run through an AI browser agent, with threat actors rapidly cycling through multiple credit card additions and payment attempts. The guide calls it an established carding workflow moved into "a new, more scalable channel." In PPC Land's earlier reporting on the benchmark, the documented case involved one actor adding 11 cards and attempting six paymentsacross sessions. Agent activity around checkout is not hypothetical either: around Super Bowl LX in February, HUMAN recorded checkout requests made through AI agents rising 28 percent from the Saturday to game day.
Account takeover
Attempted account takeover at the median travel business was 1.19 percent in 2022, spiked to 9.91 percent in 2023, then fell to 2.87 percent in 2024 and 1.37 percent in 2025. Among heavily targeted businesses the figures were 36.20, 48.97, 36.17 and 45.11 percent across the same four years.
HUMAN summarises the pattern as a significant spike in 2023 before stabilising. That description fits the median. It fits the top of the distribution less well, where attempted takeovers rose by almost nine percentage points in 2025 to reach 45.11 percent, close to the 2023 peak. The targets, according to the guide, are loyalty points and stored payment credentials.
Fake accounts
The fake account figures are not specific to travel. Across all industries, fake account creation rose 259 percent from 2023 to 2024 and a further 89 percent in 2025, and HUMAN flagged an average of nearly 1.5 million fake accounts per customer in 2025. For travel businesses, fake accounts feed loyalty programme abuse and promotional fraud and serve as infrastructure for later attacks. The guide's point is that if AI agents are themselves creating accounts and booking autonomously, telling a legitimate AI-created booking from a fraudulent one requires what HUMAN calls intent-level visibility that most platforms lack. The industrial side of that problem was visible in July, when HUMAN's Satori team priced an AI-assisted phone farm kit at $5,000 upfront and $450 a month, infrastructure that also serves fake account creation.
The dark web price list
The guide's table of dark web prices is where its argument about travel defences rests most heavily, and also where the evidence is thinnest.
| Account type | 2025 | 2026 | Change (PPC Land calculation) |
|---|---|---|---|
| Budget airline | $128.00 | $126.50 | -1.2% |
| National airline | $175.00 | $45.50 | -74.0% |
| Fast food | $7.00 | $11.25 | +60.7% |
| Hotel chain | $201.00 | $40.50 | -79.9% |
| Sports betting platform | $26.00 | $3.50 | -86.5% |
According to HUMAN, falling prices for travel accounts signal that attackers have found more efficient paths to compromise in the vertical, meaning defences are not keeping pace. Financial services and tech accounts, the guide says, are moving the other way and becoming more expensive, which HUMAN reads as defences in those categories raising attacker costs. Those rows are absent from the travel edition's table; in the full benchmark, as PPC Land reported in June, cryptocurrency exchange accounts climbed from under $500 to $4,500.
Three caveats apply. The guide's wording, "one hotel chain's" and "one national airline's", indicates each row reflects a single brand's listings rather than a sector average. No sample size, marketplace or collection method is disclosed. And the travel trend holds for two of the three travel-related rows: the budget airline's accounts fell by $1.50, barely moving. A cheaper account can also mean a glut of supply rather than weaker defences, a reading the guide does not consider.
The sports betting row offers a comparison point. During Super Bowl LX, compromised betting accounts with balances above $1,000 were selling for roughly 20 percent of their stored value.
What travellers say they will hand over
The consumer half of the guide draws on HUMAN's February 2026 survey. According to the guide, 44 percent of respondents had already used an AI tool such as ChatGPT or Google Gemini to help plan a holiday, and a further 38 percent had considered it. More than half, 54 percent, were comfortable using AI to plan a trip from start to finish, and 50 percent were confident an AI assistant could find better deals than they could.
The tasks people trust AI with are the ones agents already perform at scale: finding local activities (64 percent), comparing prices (59 percent), food and destination recommendations (58 percent) and lodging options (51 percent).
Trust drops at the till. Some 43 percent would let an AI assistant book travel on their behalf if they kept final approval before payment. Without that approval, the figure falls to 12 percent, even if the agent stayed within budget and preferences. Eighty-two percent said they would be uncomfortable with fully autonomous booking, and 35 percent said no amount of savings would change their mind.
Who carries the loss when an AI travel assistant gets it wrong? Asked who should be held responsible if an AI assistant made a mistake that cost money or disrupted a trip, 40 percent named the AI company that built the tool, 20 percent the user, 19 percent said responsibility should be shared, 11 percent named the platform where the booking took place and 3 percent the travel provider. Those answers sum to 93 percent; the guide does not account for the remaining 7 percent. Among those choosing shared responsibility, 83 percent included the AI company, 72 percent the user, 55 percent the booking platform and 31 percent the travel provider. For travel businesses operating as the platform layer between AI agents and travel providers, the liability picture is only getting more complex, according to HUMAN.
The guide describes the gap between "assist" and "act" as wide. Platforms have kept building the layer that acts. Google's November 2025 travel update brought agentic booking for restaurants and flagged direct flight and hotel booking as future plans. Amazon added Expedia to Alexa+ in December 2025. On July 14, 2026, Chrome auto browse reached AI Pro and Ultra subscribers in the United States, handling tasks such as researching flights and accommodation. And on August 27, Google's AI Mode began completing hotel bookings inside the product through Google Pay, with ten partners including Booking.com, Expedia, Hilton and Marriott.
Same behaviour, different intent
The guide's central claim is a single number. Across all interactions analysed by the Human Defense Platform, only one half of one percent separates the rate of benign automation from the rate of malicious automation. In travel the consequence is concrete. An agent rapidly comparing prices and completing a booking may be a consumer's assistant or an automated fraud operation. "The behavior is the same. The intent is not," the guide states.
HUMAN frames the commercial bind in two halves. Travel businesses that treat all automation as hostile will block revenue from a fast-growing channel; those that allow it unchecked will absorb fraud. That framing marks a shift from where many site operators started. In 2024, 80 percent of companies on HUMAN's platform blocked known LLM user agents outright. By early June 2026, Cloudflare Radar data showed bots generating 57.4 percent of web traffic to HTML content. Blanket blocking also carries legal and commercial dimensions beyond security; PPC Land's January analysis of AI agents and flight booking set out how terms of service and platform economics, rather than model capability, shape what agents are allowed to do.
The final pages are a product pitch. HUMAN presents Sightline Cyberfraud Defense, which it says offers real-time visibility across bots, humans and AI agents on web, mobile and APIs, and AgenticTrust, described as a trust and control layer that detects agent actions and intent, verifies trust levels and governs how agents interact with web applications. The marketing side of that offer reached Adobe Experience Platform in April, when HUMAN extended agentic visibility to marketing teams.
Both dashboards in the guide are labelled as example data, "not indicative or representative of any agent, customer, or organization." The Sightline example shows 436.8 million legitimate requests against 62.9 million blocked, 29.2 million allowed requests from known bots and crawlers, and a CAPTCHA solve rate of 0.3 percent. The AgenticTrust example lists OpenAI's Atlas as the top agent by volume at 331,339 requests, last seen on March 10, 2026. OpenAI said on July 9 that it was beginning to sunset the standalone Atlas browser, weeks before the guide's file was produced.
Why the numbers reach the marketing team
The guide is written for security buyers, but several of its findings land in marketing budgets. Loyalty programmes are marketing assets, and the guide places them at the centre of both account takeover and fake account abuse. Checkout traffic is where conversion tracking lives; at businesses where attempted carding exceeds one request in six, a material share of unfiltered checkout events describes attackers rather than customers, the same measurement problem that invalid traffic poses in advertising. Pricing and availability data scraped from travel sites feeds comparison engines and AI assistants that increasingly sit between a traveller and the advertiser's own pages.
And the path to purchase is shortening. When a purpose-built agent searches fares and completes a booking, the search ad click, the landing page visit and the attribution trail that travel marketers have long relied on may never occur. HUMAN's data says 38.4 percent of that agent traffic already points at travel. Its survey says 12 percent of Americans would let an agent book without their explicit approval. The space between those two numbers is where the sector's commercial and security questions now overlap.
What the guide does not show
The data comes from HUMAN's own customer base, not the travel industry as a whole, and the guide does not disclose how many travel customers are included or how they are distributed between airlines, hotels and booking platforms. Attack rates measure attempted attacks, not successful fraud or financial loss. The 90th percentile is, by construction, the most attacked tenth of a sample whose size is undisclosed. The survey covers Americans only and publishes no margin of error or full question wording. The company's description of its own scale is also loose: the guide's "About HUMAN" section says the company "verifies 20 trillion digital interactions" without stating a period, while the same document cites more than one quadrillion interactions analysed in 2025.
None of that makes the figures wrong. It makes them one vendor's view, published as marketing material by a company that sells the remedy it describes.
Timeline
- 2022: Attempted carding at HUMAN's most heavily targeted travel customers stands at 3.10 percent of checkout traffic; scraping at that tier is 17.43 percent
- 2023: Median attempted account takeover at HUMAN's travel customers spikes to 9.91 percent
- 2024: HUMAN Security reports 80 percent of companies on its platform blocking known LLM user agents
- 2024: HUMAN documents a 107 percent year-over-year increase in scraping attacks
- November 17, 2025: Google's travel update adds agentic restaurant booking and flags direct flight and hotel booking as future plans
- December 23, 2025: Amazon adds Expedia, Yelp, Angi and Square integrations to Alexa+
- 2025: AI-driven traffic nearly triples; at the 90th percentile of HUMAN's travel customers, attempted carding reaches 17.60 percent of checkout traffic and scraping 47.77 percent of product and listing traffic
- January 18, 2026: PPC Land examines why AI agents are not yet booking flights autonomously
- February 2026: HUMAN surveys more than 2,400 Americans on AI travel planning
- February 14, 2026: HUMAN publishes Super Bowl LX data showing AI agent checkout requests up 28 percent
- March 26 and April 9, 2026: HUMAN releases the 2026 State of AI Traffic & Cyberthreat Benchmark Report in the US and internationally
- April 21, 2026: HUMAN extends agentic visibility to marketing teams inside Adobe Experience Platform
- May 13, 2026: HUMAN publishes the AI travel planning survey results
- June 4, 2026: HUMAN's May data puts travel at 13.7 percent of agentic traffic
- June 5, 2026: Cloudflare Radar shows bots at 57.4 percent of web traffic to HTML content
- July 9, 2026: OpenAI begins to sunset the standalone Atlas browser
- July 14, 2026: Chrome auto browse reaches AI Pro and Ultra subscribers in the US
- July 28, 2026: HUMAN's Satori team publishes its FunFoneFarm phone farm research
- August 27, 2026: Google AI Mode begins completing hotel bookings with ten partners in the US
- September 2, 2026: The PDF of HUMAN's travel and hospitality guide is produced
- September 2026: HUMAN releases The 2026 Guide to AI, Agentic Traffic, and Cyberthreats for Travel and Hospitality
Related PPC Land coverage
- Americans warm to AI travel planning but won't hand over the wallet - The first reporting on HUMAN's February 2026 survey, including task-level trust and payment reluctance.
- AI agents are now buying things - and fraud looks identical - The cross-industry benchmark the travel guide is cut from, including the half-percentage-point gap between benign and malicious automation.
- AI agent traffic dips in May but blocking rates keep climbing - HUMAN's monthly agent data, with travel's share and rising block rates.
- AI agent traffic is up 8x - HUMAN Security now tells marketers why - How HUMAN repositioned its agent classification for marketing teams inside Adobe Experience Platform.
- How fraudsters scored big during Super Bowl LX while AI agents surged - Event-level data on agent checkout activity and dark web pricing for betting accounts.
- AI cuts scam farm entry cost to $5,000, HUMAN Security research shows - The phone farm economy behind fake account creation at scale.
- Google AI Mode completes hotel bookings with 10 partners in US rollout - The point at which Google's assistant began closing hotel transactions itself.
- Chrome auto browse lets AI agents book travel and fill forms alone - Browser-native agents handling flight and accommodation research, and the security research around them.
- PPC Land's analysis of AI agents and flight booking - Why terms of service and platform economics, not model capability, limit autonomous flight purchases.
- OpenAI kills Atlas browser, folds it into new ChatGPT Work agent - The end of the agentic browser that tops the guide's example dashboard.
- Bots now outnumber humans on the web - and most aren't here to search - Cloudflare Radar data on the point automated traffic passed human traffic.
- 80% of companies block AI language models, HUMAN Security reports - The 2024 baseline, when most HUMAN customers blocked LLM user agents outright.
- Google expands AI travel planning to 200+ countries with booking features - The November 2025 update that first flagged agentic flight and hotel booking.
- Alexa+ gains Expedia, Yelp, Angi and Square to handle travel and home tasks - Amazon's move to put travel booking inside a voice assistant.
Summary
Who: HUMAN Security, a cybersecurity company that operates the Human Defense Platform and its Satori Threat Intelligence team, publisher of the guide. The findings concern airlines, hotel chains, online travel agencies and booking platforms among HUMAN's customers, the AI operators whose crawlers, scrapers and agents reach those sites, and the more than 2,400 Americans surveyed.
What: A 13-page guide combining HUMAN's 2025 traffic benchmark and its February 2026 consumer survey for the travel industry. It finds travel received 16.60 percent of AI training crawler traffic, 21.10 percent of AI scraper traffic, 19.2 percent of agentic traffic and 38.4 percent of purpose-built agent traffic; that attempted carding at the 90th percentile of travel businesses reached 17.60 percent of checkout traffic in 2025 against a median of 0.35 percent; that scraping at the same tier hit 47.77 percent of product and listing traffic; and that one hotel chain's loyalty accounts fell from $201 to $40.50 on the dark web.
When: The guide carries no date; its PDF was produced on September 2, 2026, and it was released in September 2026. Attack data spans 2022 to 2025, AI traffic data covers 2025, and the survey was fielded in February 2026.
Where: HUMAN's telemetry spans its global customer base across web, mobile and APIs; the consumer survey covers the United States only.
Why: The guide argues that legitimate AI agents and fraud operations now behave almost identically on travel sites, with half of one percent separating benign from malicious automation, so that blocking all automation forfeits bookings while permitting it invites fraud. For marketers, the same data bears on loyalty programme value, checkout conversion measurement and the attribution path as agents begin completing bookings themselves. All figures are vendor-supplied and drawn from HUMAN's own customers.
Discussion