Untangling Tourism Tech — Podcast

Episode 14 – AI Spoofs, Scams & Scares, what Tourism Operators need to do now to protect themselves

15 July 2025

Find us on your favourite podcast provider:

It looked like my email. It sounded like my voice. But it wasn’t me.Welcome to the age of AI-powered scams.

Cybersecurity isn’t just an IT problem anymore—it’s a marketing, operations, and brand reputation issue. In this episode of the Untangling Tourism Tech podcast, Fabienne and Liz share jaw-dropping stories of modern AI-powered scams and break down simple but powerful steps that every tourism business should take to protect their brand, money, and customers.

Cybersecurity on AI steroids: what’s happening now?

In 2025, scams have become faster, smarter, and eerily personal, all thanks to AI. Tourism operators and industry organisations are increasingly being targeted in ways that feel completely legitimate. One client had three separate scam attempts in a fortnight: emails that appeared to come from their CEO, referencing real projects and targeting trusted contacts. Another time, Fab received a call where the scammer pretended to have her voice on file.

AI can now to all the below, so imagine the insights it has to impersonate YOU either via email, text message but also voice…

Email spoofing: The open door most tourism businesses don’t know is unlocked

What Is email spoofing?

Spoofing is when someone sends an email that looks like it’s from you but it’s not. To the recipient, it might say fabienne@tourismtribe.com, but behind the scenes, it’s coming from a different source.

Real tourism example

A scammer posed as a tourism CEO and tricked a committee member into transferring money. They even used the correct first name, tone of voice, and referenced a real project, all gleaned from the organisation’s own website.

Why it works:

How to protect your email and domain from spoofing

Most tourism businesses don’t realise that email security starts with their domain.

Action Steps:

  1. Use a Professional Email Platform: switch to Google Workspace or Microsoft 365 or similar and avoid using email tied to your website hosting. Google Workspace and Microsoft 365 offer far stronger protection against spam and spoofing than standard web hosting email. They use AI and threat intelligence to scan billions of emails daily, blocking over 99.9% of spam and phishing attempts before they reach your inbox. Unlike basic email systems, they also fully support and enforce SPF, DKIM, and DMARC authentication, making it much harder for scammers to impersonate your email address or domain.
  2. Add the “Big 3” DNS Records to your domain
    These are essential for email protection:
    • SPF (Sender Policy Framework)
    • DKIM (DomainKeys Identified Mail)
    • DMARC (Domain-based Message Authentication, Reporting and Conformance)
  3. Run a free email security test
    You can check your email health here: https://mxtoolbox.com/emailhealth/ – If something fails, you’re at risk. Contact us on help@tourismtribe.com to help you sort it out if you don’t feel confidentdoing it yourself.
  4. Ensure admin access to your domain name
    If you don’t control your domain, you can’t protect your brand. Fight for admin access if needed, your future cyber-safety depends on it.
  5. Finally, review all your credentials and make sure you have admin access to all the tools that you may need access to in case of a cyber attack: start here and learn how to get your digital ducks in a row.

AI voice spoofing: the next frontier of fraud

What if a scammer could call your staff or clients sounding exactly like you?

It’s not hypothetical anymore. With voice cloning tech, all they need is:

Real example:

Fab clicked on a legitimate-looking email. Two weeks later, she received a call from a spoofed number using a voice that sounded like her—complete with stern tone and a believable script about a financial issue.

How to defend against voice spoofing

AI makes scammers faster, smarter, and more personal

Fab and Liz also dicusss how AI allows scammers to:

So while you’re working hard on AI search visibility and SEO, remember: scammers are scraping the same data to impersonate you.

Practical security tips for tourism businesses

Risk AreaWhat to Do
Email SpoofingSet up SPF, DKIM, and DMARC. Use Google Workspace or 365.
Voice CloningTrain your team to never act on unexpected calls. Hang up and verify.
Data ExposureLimit what you publish about team structures and personal bios.
AI AwarenessTalk with your team about AI-driven scams. Include it in staff onboarding.

Share this with your team

Use this podcast episode as a conversation starter at your next team meeting. Cybersecurity is no longer optional, especially when AI is involved.

Pocket Rocket AI marketing coach for tourism operators
Pocket Rocket App — Free

Your free AI marketing coach, right in your pocket

The free Pocket Rocket app gives you a personal AI marketing coach, website audit, weekly action plans and 5-minute tips. Built for tourism operators.

Like what you hear?

Get access to all our training, coaching, and tools built for tourism operators who want to grow with confidence.

Explore membership