The FBI on Wednesday flagged a wave of fake airline rebooking sites targeting Americans trying to escape or reroute Gulf itineraries, saying criminals are buying search ads and cloning carrier pages within hours of real cancellation notices.
How the sites work
Investigators described typosquatted domains that swap letters in major airline names, then prompt users to "verify" itineraries by entering record locators, passport numbers, and payment cards. Some pages display live flight data scraped from public trackers to appear authentic while routing card payments to merchant accounts registered in unrelated countries.
Other variants offer "priority rebooking" for a flat crypto fee—a overlap Treasury addressed separately when it sanctioned mixers tied to evacuation scams. The FBI said victims often encounter both payment rails in the same week as they chase seats.
Who is exposed
Corporate travel desks reported the highest loss rates because assistants bulk-process changes for executives leaving Riyadh and Dubai conference circuits. Leisure travelers searching on phones during airport layovers also dominate complaints to the Internet Crime Complaint Center, especially when legitimate carrier call centers hold for hours.
Airlines said they never ask for full card numbers on standalone rebooking pages and do not charge separate "security deposits" to move passengers off canceled Middle East legs. Carriers urged customers to type URLs manually or use official apps after the State Department kept Level 3 advisories in place.
Search and ad abuse
The bureau said paid results for phrases such as "Doha rebooking help" rotated through dozens of domains over ten days, outpacing takedown requests to registrars. Meta and Google told reporters they removed thousands of ads this month, but criminals relaunch with new billing identities faster than manual reviews.
FBI cyber division officials recommended travelers capture screenshots and header information before closing fraudulent tabs—metadata that helps hosting providers pull pages even when operators hop jurisdictions.
What is confirmed versus claimed
Agencies confirmed rising complaint counts and shared hash values for known fake pages, but they have not published a single mastermind indictment tied to the entire cluster. That gap is normal in fast-moving fraud waves; travelers should treat absence of a named defendant as reason to stay skeptical of any third-party "fix" site.
Practical defenses
Use card numbers only on carrier domains ending in known corporate suffixes, enable two-factor authentication on loyalty accounts, and refuse wire or crypto payments for seat changes. Report URLs to IC3 even if no money was lost—feeds help ad platforms and FBI sinkholing efforts.
Travel insurers said claims for fraudulently purchased tickets remain difficult unless policies explicitly cover cyber scams; documenting advisory levels at purchase still helps legitimate disruption claims.
Until Middle East schedules stabilize, the cheapest rebooking offer is often the costliest. The FBI's alert is blunt: if the site is not the airline you already ticketed with, close the tab and call the number on your boarding pass or confirmation email—not the one the ad suggested.
Airline fraud units said they are sharing domain lists with payment processors twice weekly during the Gulf disruption, a tempo travelers rarely see but one that explains why some legitimate-looking pages vanish mid-checkout when issuers block new merchants.
Corporate travel desks
Global travel management companies told InfoHandle they are blocking browser extensions that auto-fill credentials on unknown domains, a step rarely used before the Gulf disruption. Assistants managing executive itineraries said criminals copied legitimate portal skins closely enough to pass casual inspection during late-night rebooking pushes.
Payment processors added velocity rules on merchant category codes tied to "travel services" registered in the last 30 days, slowing some legitimate small agencies alongside fraud rings. The FBI asked processors to share those merchant IDs weekly rather than waiting for court orders.
Carriers emphasized that waiving change fees does not mean waiving identity checks. Several U.S. airlines published hash lists of authorized domains after the alert, a transparency move consumer groups had requested for years.
Law enforcement has not released a consolidated loss total; IC3 historically lags victim reporting by weeks. Even so, the bureau said complaint velocity in the Gulf corridor already exceeds the spike seen during early pandemic refund scams, when fake airline portals also proliferated.
Travelers using VPNs to reach carrier sites from Middle East IP addresses should still verify TLS certificates and avoid clicking links embedded in unsolicited texts claiming "final boarding window." The FBI said SMS lures now outpace email for the first time in this campaign.








