The same photo you post to Instagram or Facebook to share with friends is now all a scammer needs to track your exact location and rob you — thanks to AI tools that identify where a picture was taken nearly nine times out of ten, without any metadata or geotags at all.

McAfee tested more than 21,000 travel images using two freely available AI models. One identified the correct location 91% of the time; the other hit 87%. The images didn't need location tags or embedded metadata. The AI just… looked at them. Landmarks and signage are the obvious giveaways, but even generic scenes get cracked. In one test, ChatGPT correctly identified a seemingly ordinary river scene as Hastings-on-Hudson, New York. Another image of flowers was traced to the Keukenhof gardens in the Netherlands based on the arrangement of tulips and smaller blue flowers planted between them.

Here's how the scam works: you post family photos from Porto without naming the city. Days later, a text arrives claiming your bank detected unusual card activity "while you were travelling in Porto" and asks you to verify details through a link. Because the message contains a detail only someone who knew about your trip should have, it feels legitimate. The scammer never knew — the photo told them.

Both Digital Trends and The Guardian covered McAfee's research, and both framed this as a consumer-awareness story: be careful what you post, don't click suspicious links. Fair enough as far as it goes. But neither outlet touched the deeper problem. Big Tech built the surveillance infrastructure that makes this possible. The same platforms that vacuum up every scrap of visual data you upload — to train their own AI models, to serve you ads, to build dossiers on your movements and preferences — created the environment where freely available AI tools can dox your location from a flower arrangement. The privacy threat isn't a bug. It's the business model.

Vonny Gamot, McAfee's head of EMEA, told The Guardian: "What AI does is give context … so that makes the scam [and] makes the threats credible." McAfee staff who replicated the experiment with their own photos reportedly became uncomfortable with how easily their travels were pinpointed.

The practical advice is simple, if annoying: wait until you're home to post holiday photos publicly, or restrict them to people you actually know. Never click a link in an unsolicited message claiming your account is compromised — contact your bank directly. But the structural problem remains. You are generating the data. Big Tech is hoarding it. And now anyone with access to off-the-shelf AI can weaponize it against you.

The question neither outlet asked: why are these AI models — capable of pinpointing a random stretch of river in New York from a photo — freely available in the first place, and who exactly benefits from that capability being democratized before the public even understood what it meant?