Surge in fake Delta, Hilton and El Al domains: how scammers target vacationers
A report by the Israeli cyber company BrandShield found a 77% increase in domains related to Delta and 122% around Hilton compared to last year. El Al saw a 19% increase in suspicious domains between April and June 2026. Scammers are also increasingly impersonating El Al representatives in private messages to customers.

As phishing attempts multiply, we are becoming — and rightly so — increasingly suspicious. We have already learned to recognize that a payment message via SMS can often be a phishing attempt, and the same applies to booking vacations and flights online, which have become a fertile ground for scam attempts in recent years. One of the phenomena is fake sites impersonating well-known brands, whose sole purpose is to steal your credit card details. These pages are removed quickly, but new ones are constantly being created.
New data from the Israeli cyber company BrandShield points to a sharp rise in the registration of domains related to airlines and hotels. A notable surge was recorded around the airline Delta: the number of domains related to the brand rose from 1,421 in August 2025 to 2,517 in July 2026 — an increase of 77%. Last June alone, a record of 2,815 domains was recorded. Hilton also recorded a sharp surge: from 156 domains in August last year to 347 in July this year — an increase of 122%. Around El Al, 892 domains were recorded in April 2026, compared to 1,059 in July 2026 — an increase of about 19% within three months.
The impersonating domains are distributed through social networks or via SMS messages with a link. However, impersonation sites are not the only method. A Facebook user, for example, posted that he received a private message from a source impersonating an El Al representative after he complained about an issue in the Facebook group 'El Al Victims'. The impersonator already knows that the user is a customer and is familiar with the problem they wrote about publicly. Under the cover of 'handling the inquiry', they may ask to move to a private conversation, click on a link, or provide personal details and booking information. It is precisely the timing that makes the method convincing: unlike a random phishing message, the approach arrives at a time when the customer is actually expecting a service representative to get back to them.
At BrandShield, they emphasize that registering a domain that includes a brand name does not in itself indicate fraud, but the abundance of domains around well-known brands increases the potential exposure to phishing sites. 'Periods of high demand for vacations and flights are a fertile ground for impersonation attempts. The attackers know that consumers are looking for good prices, sometimes under time pressure, and build sites that look almost identical to the original,' says Yoav Keren, CEO of BrandShield. 'The increase we see in domain registrations around brands like Delta, Hilton, and also El Al requires the public to be more suspicious: not to settle for a logo or design that looks familiar, but to check the website address and think twice before depositing personal details and credit card data.'
On impersonation sites, the difference from the original can be particularly small: one letter replaced in the address, a hyphen, a different extension, or a word like 'booking' or 'tickets'. The site itself may include the logo, colors, and look of the real company — until the stage where the victim enters personal or credit card details.
How not to fall into the trap?
-
Did you contact an airline on Facebook? Do not assume that whoever got back to you is a company representative. Ensure that you are communicating with the official account or service channel.
-
Do not automatically click on links sent via SMS, WhatsApp, email, or a private message. It is better to enter the official website or app yourself.
-
Check the website address, and not just the logo and design. A small change in the domain can give away an impersonation.
-
Do not rely only on the lock symbol. Even an impersonation site can use an HTTPS connection.
-
A price that is too good should raise suspicion. An offer that is radically lower than the accepted prices is a reason for further checking.





