
Over the years, my travel checklist has grown from simply making sure I’ve packed all the essentials — that flight neck pillow is a must — to having a dedicated list of cybersecurity practices I follow before, during and after every trip.
The online threat landscape has evolved, and so have the tactics cybercriminals use to target unsuspecting travelers. That means we also need to be more mindful about staying safe online while we’re away from home.
After all, while having a password stolen or a bank account compromised is never a pleasant experience, being in a foreign city or country when it happens comes with a unique set of challenges. Losing access to your finances, documents, travel bookings or important accounts while you’re miles away from home can quickly wreck a trip.
I’ve put together this guide, drawing on my years of experience as a security- and privacy-conscious traveler. These are the tools, habits and simple tips I personally rely on to keep my passwords, bank accounts, devices and other sensitive information safe whenever I travel.
I always watch out for these online travel risks
These are, in my experience, the most important online threats to keep in mind whenever you’re away from home.
I think twice before using public Wi-Fi

I have a private Wi-Fi network at home, so whenever I travel through airports, cafes or hotels, free public Wi-Fi is incredibly convenient. It lets me stay connected without constantly recharging my local data plan — or paying for expensive eSIM data packages when I’m traveling abroad.
Generally, public Wi-Fi isn’t the security threat that VPN marketing often makes it out to be. That’s thanks to modern encryption, which keeps your data safe while in transit between your device and websites, apps and other online services you’re using. That said, I’ve grown increasingly wary of using public Wi-Fi, especially for sensitive tasks such as logging into my bank account. I never connect to one without first enabling a virtual private network, or VPN.
Using a VPN can be helpful on public Wi-Fi as a privacy tool to hide your internet activity — what apps you use and websites you visit — from snoops such as internet providers and government agencies. With a VPN enabled, third parties like network administrators and internet providers can’t tell what apps you’re using, websites you’re visiting, files you’re downloading or videos you’re streaming.
While a VPN primarily provides privacy protection, you get some basic security benefits. Namely, VPNs can guard against certain threats, such as packet-sniffing attacks on public Wi-Fi, which are designed to intercept data traveling between your device and the Wi-Fi router, potentially capturing sensitive information such as login credentials or other personal data.
Likewise, a VPN can guard against adversary-in-the-middle, or AiTM, attacks, where cybercriminals position themselves between your device and the website you’re communicating with in an attempt to intercept your data. While these attacks have become harder to pull off today thanks to widespread encryption such as HTTPS, they may still be a risk on unsecured networks.
I also always make sure I’m joining the correct network. If I see multiple Wi-Fi networks with similar names at a cafe, hotel or airport lounge, I’ll confirm the official network name with a staff member before connecting. Doing so helps me avoid evil twin attacks, where a hacker sets up a fake Wi-Fi network that closely resembles the legitimate one. If you connect to the rogue network instead, the attacker can potentially monitor your internet activity and, in some cases, steal sensitive information such as your login credentials.
I know phishing messages thrive on urgency

Phishing scams are on the rise, especially with AI now making them far more convincing. Scammers can clone voices, generate deepfakes and create highly personalized, localized messages that look like they came from a legitimate business or service you use.
At their core, these are social engineering attacks designed to get you to click a link before you have time to think. They can be especially dangerous while traveling, particularly in countries where you don’t fully understand the local language. Even if you use a translation app, it’s still easy to miss subtle warning signs and end up clicking a malicious link or entering your personal details on a fake login page.
That’s why I’m always skeptical of unexpected emails, texts or WhatsApp messages that try to create a sense of urgency. They may pretend to come from an airline, hotel, bank or delivery service with messages like, “Your hotel booking has been canceled” or “Your flight requires immediate confirmation.”
I double-check every travel booking website

You can use scam detectors from antivirus companies and other cybersecurity companies to try identifying scams.
Screenshot/CNET
Even before I set out to travel, I’m already thinking about online safety. When I’m booking flights, reserving hotels or buying tickets for museums, attractions or events, I always double-check that I’m using a legitimate website or app.
I’ve also learned never to make these bookings in a hurry. One of the most common scams is typosquatting, where attackers create fake websites with URLs that differ from the real one by just one or two characters. Sometimes it’s as subtle as replacing the letter “m” with “rn” or making another tiny change that’s easy to miss at a glance.
These fake websites often look almost identical to legitimate ones, so it’s surprisingly easy to fall for them. They’ll prompt you to log in, enter your payment details and complete your booking, making it seem as though everything has gone through normally. In reality, you may have just handed over your login credentials and payment information without booking anything at all.
I pay extra attention before scanning QR codes
I also pay close attention to the QR codes I’m scanning while traveling, whether I’m paying at a restaurant, a local shop, a parking meter or an electric vehicle charging station. Attackers increasingly use QR phishing, also known as quishing, by simply placing their own QR code stickers over legitimate ones.
These scams can be as simple as redirecting your payment to the attacker’s account instead of the business’s. In more sophisticated cases, the QR code takes you to a fake payment page that asks you to log in, enter your credit card details or provide other personally identifiable information that can later be used for identity theft or financial fraud.
Other online travel risks I keep in mind
I avoid sharing my live location on social media. Even though I’m not a huge Instagram poster myself, I always tell my friends and family to save their travel photos until they’ve left that location or returned home.
While it’s not the biggest cybersecurity risk, posting your whereabouts in real time can help bad actors build a geographical profile of your movements and routines. They can use it to find out when you’re away from home or target you with location-specific phishing scams.
I typically never plug in unfamiliar USB cables, charging cables or USB drives into my devices, especially in public places. In some cases, these can be modified to act as a keyboard and trick your device into running prewritten commands, such as attempting to install malware, altering DNS settings or creating a backdoor that attackers can exploit later.
Luckily, you don’t really need to worry too much about “juice jacking”, which is theoretically possible, but extremely uncommon in the real-world, or threats from legitimate charging stations.
How I protect myself while traveling
Over the years, I’ve settled on a handful of tools and simple habits that make traveling much safer. Most of them are intuitive apps and services that run quietly in the background, while others take just a few seconds to use. Together, they help me protect my data and devices wherever I go.
I always travel with a VPN
Getty Images/ Zooey Liao/ CNETA VPN is one of the first tools I recommend installing before a trip. While a VPN doesn’t make you anonymous online, it does add an important layer of privacy. For me, a VPN is especially useful when I’m connected to public Wi-Fi to keep my activity hidden from prying eyes, such as internet providers, network administrators and government agencies. It encrypts your internet connection and routes your online traffic through a secure VPN server instead of directly through your internet provider.
This helps keep your information private from online snoops. I also find a travel VPN useful for another reason: it lets me access region-restricted content while I’m abroad — by changing my public IP address. Whether it’s my favorite streaming service, a sports event that’s only available back home or another website that’s unavailable in the country I’m visiting, a VPN often lets me access it by connecting to a server in my home country.
That said, I always pick a trustworthy VPN and check the VPN laws of the country I’m traveling to beforehand. Some countries, such as China and Russia, have strict regulations around VPN usage, so it’s important to know the local rules before relying on one. I also make it a point to install and set up my VPN before I leave, since downloading or configuring one after arriving may be difficult in countries where VPN access is restricted.
I rely on antivirus software to keep my devices secure
James Martin/CNETA VPN is built for privacy, not security. I use antivirus software for security. It works around the clock to protect my devices by detecting and removing malware, spyware, ransomware and other malicious software in real time.
The good news is that you don’t necessarily have to pay for antivirus software. Free solutions such as Microsoft Defender (for Windows) do an excellent job. It offers multiple scanning options, real-time malware protection and a built-in firewall to help block suspicious apps and websites.
That said, if you want complete peace of mind while traveling, a third-party antivirus can be a compelling choice. In addition to antimalware protection, these all-in-one internet security packages typically include useful extras such as a password manager, parental controls, dark web monitoring, ad blocking, cloud backups and real-time phishing protection. Buying these features together as part of a security suite is often more cost-effective than paying for each service separately.
But there are pros and cons to bundling your privacy and security software, so you’ll want to consider the upsides and downsides before bundling.
I use a password manager to protect my accounts
Jason Cipriani/CNETAnother tool I use every day, both while traveling and at home, is a password manager. It helps me generate strong, unique passwords for every online account I have without the hassle of remembering them all. Instead, all of my passwords are stored in an encrypted vault, and I can unlock it securely using Face ID, my fingerprint or a master password.
I personally use Apple’s built-in Passwords app on my iPhone 17 Pro. One of my favorite features, which is common across many free password managers, is that it autofills my passwords without actually revealing them on screen. This reduces the chances of someone stealing my credentials through shoulder surfing while I’m using my phone in a cafe, airport or other public place.
If you’re considering a dedicated third-party password manager, you’ll often get additional travel-focused features as well. For example, 1Password includes Travel Mode, which, when enabled, removes all vaults from your device except those you’ve marked as “safe for travel.” That way, if you’re ever subject to a border or customs inspection, your sensitive information remains under wraps.
I back up everything to the cloud before I travel
Sarah Tew/CNETA cloud backup service gives me complete peace of mind whenever I travel. I know that even if my phone is stolen, lost or accidentally damaged, all of my precious photos, videos, travel documents and other important files are safely backed up and accessible from another device with an internet connection.
For the same reason, I make sure automatic syncing is turned on. That way, every new photo I take, document I save or contact I add is automatically backed up to the cloud without me having to think about it.
Better yet, almost every top cloud storage service offers some amount of free storage — Google Drive, for example, includes up to 15GB at no cost — and you only pay as your storage needs grow. If you’re someone who stores sensitive data in the cloud, though, I’d recommend prioritizing strong security features when selecting cloud storage, including data encryption, secure data transfers and seamless syncing across multiple devices.
I always enable multi-factor authentication
Matt Elliott/CNETUsing strong, unique passwords is a great first step, but I always pair them with multi-factor authentication, or MFA, sometimes known as two-factor authentication, or 2FA. It adds another layer of protection and can help protect your accounts even if your password is somehow compromised. For example, if an attacker manages to steal one of my passwords, they still can’t log in because they’d also need the time-based verification code generated by my authenticator app that’s only available on my device.
I enable Find My before every trip
Patrick Holland/CNETBefore I travel, I always make sure Apple Find My (or Google’s Find Hub if you have an Android) is enabled on my device. In addition to helping you locate a lost or stolen phone, they can also track accessories such as earbuds and smartwatches. More importantly, they include privacy-focused features that can help protect your personal information.
If your device goes missing, for instance, you can remotely lock it and display a custom message on the screen, such as an alternate phone number or email address where someone can reach you. Or, if you believe your device isn’t coming back, you can remotely erase all of your personal data from it, ensuring that your photos, messages, documents and other sensitive information don’t end up in the wrong hands.
A few more travel safety tips I swear by
The right tools are only half the equation. I also rely on these simple, free habits to keep my devices and personal information safe while traveling.
- Keep your devices and apps updated. Vendors regularly roll out updates that fix bugs and patch security vulnerabilities. I always make sure to install them before traveling, since it’s safer and also saves valuable mobile data compared to downloading updates on the go.
- Enable transaction limits and alerts. Most banks let you set daily spending and per-transaction limits, as well as real-time transaction alerts. These can help limit your financial losses and notify you immediately if your account or card is compromised.
- Learn how to identify phishing. Because phishing attacks rely on social engineering, they can usually be prevented if you’re cautious. Check the sender’s email address or phone number, inspect the URL before clicking, watch out for generic greetings, look for spelling or grammar mistakes and contact the company directly if you’re ever in doubt.
- Know what to do if something goes wrong. In addition to quickly changing your passwords, signing out of all active sessions, running a security scan on your device and notifying your contacts, it’s also worth knowing which local authorities or organizations to contact if you fall victim to a scam or theft while traveling.
For more, learn how to identify scams so you can determine if that call, text or email is real.







