IT security on holiday: because hackers don't go on holiday
Germany is in travel fever again: we finally have time to relax, recharge our batteries or explore new cities and countries. But when ‘summer, sun and sea’ are within our grasp, it's also ‘peak season’ for hackers. That's why you should not only adequately protect your sensitive data on your home computer, but also be familiar with the topic of cybersecurity before and during your holiday. How do I avoid falling for scams and rip-offs? From spycams to public Wi-Fi - what dangers can lurk while travelling? And how can I ensure a certain level of IT security at home and when travelling? You can find out all this in this blog post.
IT security on all channels - plan and prepare
At first glance, it is often impossible to distinguish well-made scammer sites from reputable platforms. It is therefore better to use trusted booking portals or book directly through the hotel, airline or a local travel agency. Review portals can also help: what experiences have other holidaymakers had there? In addition to the legal notice, contact details and the company's registered office can also provide information about the seriousness of the company. Also important: only pay via secure payment sites and check whether the amount debited really corresponds to the price of the holiday.
No matter what type of person you are - last-minute or early bird - the planning phase of your holiday is always a highlight. As we browse for the perfect accommodation, the anticipation begins. But in addition to feelings of happiness, there are also dangers: Cheap flights, luxury hotels at unbeatable prices, all-inclusive holiday bargains on paradisiacal sandy beaches - we are quickly dazzled by dream offers, especially when they are extremely cheap. But behind the supposed top deal can lurk an expensive trap.

The very first thing you should do is to check the offer page for a certain ‘trustworthiness’. In the browser line, ‘https’ should precede the page name. In Google Chrome, for example, a lock appears on secure pages - if a page is displayed with ‘Info’, ‘Not secure’ or ‘Harmful’, it is better to close the website. A look at the legal notice is also usually worth its weight in gold: If dubious or missing information is recognisable there - or in the worst case, there is no legal notice at all - you should never book through the site!
Well-made scammer sites often cannot be distinguished from reputable platforms at first glance. It is therefore better to use trusted booking portals or book directly through the hotel, airline or local travel agency. Rating portals can also help: What experiences have other vacationers had there? In addition to the imprint, contact details and the company's headquarters can also provide information about the company's reliability. Also important: only pay via secure payment sites and check whether the amount debited really corresponds to the price of the trip.
Prevent and protect:This should also be on your ‘holiday to-do list’
Many people make a packing list or write down to-do's that they have to do before they go on holiday - so they don't forget the toothbrush or leave the oven on. The neighbour knows that you should take the post out of the letterbox every morning and keep it there until you return and the plants are taken care of by the friend or relative with whom the dog or cat is staying during the holiday. But: Have you ever asked yourself before going on holiday whether your data will be kept safe?
Probably not - simply because you have too many other things on your mind and the last few working days before travelling are stressful for most people. Holiday handovers and absence notes in the office, to-do and packing lists at home. In our increasingly digitalised world, however, IT security should also be considered in order to protect accounts, documents and data from hackers.
Point 1: Create backups
A relaxed atmosphere on holiday can mean that mobile devices such as smartphones, tablets or notebooks are not always handled with the utmost care. Whether we jump into the pool with our mobile phone in our swimming trunks, wipe the iPad off the table or forget the notebook on the veranda and give thieves an opportunity - gone is gone. However, this does not apply to our data if we have created a backup beforehand. So plan time before you go on holiday to not only get rid of the accumulated data rubbish, but also so that you can back up your important photos, documents and files.
Point 2: Keep important travel documents
Your travel documents should not only be stored on one device. Save them elsewhere (e.g. mobile devices of fellow travellers or the cloud) or print them out on paper - as an exception, as this is not very sustainable. If the documents are saved on an external medium (e.g. USB stick or external hard drive), they should be encrypted.
Point 3: Create secure passwords & encrypt devices
Don't make it too easy for hackers: encrypt your mobile devices and/or hard drives with long lock codes that are memorable for you. Also renew your account passwords regularly (e.g. online banking). The passwords should be different for each account. You can find out how to create a secure password in one of our previous blog posts: ‘At least 8 characters, 1x capital letter & 1x special character’.
Point 4: Blocking hotlines and inactivity time windows
Make a note of the hotlines for blocking services (e.g. credit card, bank account) on a small card that you keep in a safe place. If you lose a mobile device or a credit or debit card, every minute can count - so you have the emergency numbers to hand. You should also minimise the inactivity time window on your mobile devices to prevent hackers from accessing your data.
Point 5: Cost check
Are you planning a longer trip, perhaps even travelling to another continent? Find out in advance what costs you will incur. Does the technology even work abroad? Is it worth buying (foreign) prepaid cards? And what roaming charges will you incur? Mobile phone shops and mobile phone providers can help you find out.
Point 6: Updates
Carry out regular updates on your smartphones, tablets and laptops and ensure that the latest version of the operating system is installed. This closes any security gaps and makes it harder for cyber criminals to gain access to your data.
Point 7: Downloads
To avoid having to make lengthy downloads on foreign WLAN networks when travelling, download films, e-books, your favourite music and podcasts before you go on holiday.
Point 8: Check terms of use
Would you like to take your work laptop with you on holiday? Clarify the terms of use with your employer - different instructions may apply to work devices abroad.
To save you time and effort before you go on holiday, we have prepared an ‘all-round packing list’ as well as a ‘to-do list’ on the subject of IT security for you to download.
You can find them here: Holiday packing list & IT security to-do list
A cybercriminal in the bag

It's finally time again: 2 weeks in Italy, cocktails on the beach, building sandcastles with the kids, taking the time to read a book again and simply unwind ... maybe a quick look at the emails? We don't want to be ‘overwhelmed’ by work straight after our holiday.
Dangerous: because this is not only bad for our mental health (after all, holidays are supposed to mean holidays), but can also - if not thought through - quickly end badly. Why? Cyber criminals are everywhere and especially where we least think about them - they are practically sitting in the hold with our luggage. The more ‘cosy’ the environment, the less dangerous we consider situations to be - especially those that we cannot see (see also our blog post: Workplace 2.0: Data disaster in the home office).
So that you can really enjoy your holiday, but also be on your guard, we have put together some potential sources of danger for you. The first ones start even before you have set off on your holiday.
Danger 1: Social media
Are you generally very active on Instagram, TikTok and the like? You should be extremely careful what you post, especially when it comes to travelling. You should therefore refrain from posting ‘anticipation posts’ announcing your trip and only upload your holiday photos - if at all - after you have been away. Otherwise you give burglars the perfect opportunity. The danger is even greater with public profiles than with private ones, where only friends can see your posts - but be careful here too. After all, you never know what people are saying to each other and, above all, where. If an unauthorised third party hears that ‘person X is travelling to the USA for another three weeks’ and ‘you should check on their flat in XY street every three days’, you could be in for a rude awakening after your trip. The fewer people who know about your holiday plans, the better. Also switch off your location services if you don't need them.
Danger 2: The domestic IT landscape
We have already informed you about regular updates and secure passwords - but there are still a few points that travellers should check at home. Switch off your home Wi-Fi if you don't need it. Make backup copies of important data on internal hard drives and data in the cloud. Don't leave passwords and information (e.g. online banking access) on your desk; it's best if you only have the data in your head or in a password manager anyway. If you have a smart home solution at home, switch on the absence mode. This switches the lights on and off several times a day, for example, and suggests that the occupant is not away. Outdoor cameras may even indicate to burglars that there is something to get. It is therefore better to place the surveillance media hidden in the home.
The suitcases are packed and the journey can begin - regardless of whether you are travelling by car, bus, train, boat or plane.There are potential risk factors here too:
Danger 3: Border control
In some countries, you may be required to allow officials to take a look at your smartphone, tablet or notebook during border controls. Certain territories may also demand a copy of every sector of your hard drive - this is not only a lengthy procedure, but may also allow you to view data that has already been deleted. You should therefore check in advance whether your destination is one of these countries and which technical gadgets really make sense for your trip.
During the long journey, take a short break, wait for your connecting train or flight and pass the time surfing the internet.
Danger 4: Public WLAN networks
Caution is also advised here: only surf websites that begin with a secure URL (https://) and in familiar, encrypted Wi-Fi networks. If you are asked to download a special digital certificate in order to access the services or if you are recommended additional software or an update that you need to use the Wi-Fi, disconnect immediately. Even in seemingly secure hotel Wi-Fi, you need to keep a watchful eye. Check whether the access data exactly matches the name of the wireless network - scammers have sometimes set up their own hotspots in the immediate vicinity of the hotel to intercept your data. For the scammer network, use almost identical names to the real hotel WLAN.
The flight is delayed, you're stuck in a traffic jam - the battery is almost empty. Good that the service area / airport lounge offers charging facilities, right?
Danger 5: Public USB charging stations
Our mobile devices are now better secured, but there have been and still are cases of malware being installed on smartphones or notebooks because public charging stations have been used. However, if you deliberately use older devices for your holiday or if the latest updates have not been made, there can still be security gaps if you use public charging cables. You can protect yourself either by using data blocker cables (which cannot transmit data, only the power for charging) or by carrying a power bank with you. This can also be charged at public charging stations.
Unfortunately, the power bank is at home, so to save battery power we prefer to surf the internet in the café round the corner. There we can also quickly print our boarding cards and check whether we have set our social media profile to private.
Danger 6: Internet cafés
Not a good idea! You don't know who was sitting at the PC before you - is the device already infected and intercepting data entered? Is virus protection installed and is the firewall up to date? Is there perhaps a user waiting behind you who is deliberately extracting data for criminal activities? Mistakes happen, especially when we are in a hurry, and we leave websites open that we are still logged in to, forget to delete the history and cookies or accidentally click on ‘Save passwords’. If we also log in to several accounts (e.g. social media profile, online banking, hotel website), we give cyber criminals an insane amount of data and information that can be used against us. You should also never connect your own storage media such as USB sticks or SD cards to public PCs - if these are infected with malware and you then connect them to your home PC again at home, the virus will also infect your computer.

We finally arrive at our accommodation - our hotel room is smart, the staff are friendly and the location is marvellous. Thoughts about our IT security are quickly forgotten. Better safe than sorry - even if we shouldn't let ourselves go crazy, a quick check is often enough:
Danger 7: Spycams in the accommodation
Do you check your hotel or guest room for cameras before you make yourself comfortable in your accommodation? No? But you should. It can be a little difficult to see with the naked eye, but it is generally advisable to take a look at the following: Is there a digital device in the ventilation shaft? Does something look strange on the edge of the mirror, TV, computer screen, window or picture? Are certain things (clocks, electronic devices, lamps, plants, vases) positioned strangely? Are there double smoke detectors? As cameras often emit infrared radiation, they can be detected through the camera lens of the mobile phone. Walk around suspicious areas with your mobile phone and hold the camera close to them - if a bright light appears, a surveillance medium has been positioned here. A hidden camera can also be found in the list of available WLAN networks - if a wireless device appears with keywords such as ‘cam’ or ‘camera’, this is highly suspicious.
Now you are a little unsettled - pictures are now only sent to other travellers outside the hotel via Bluetooth.
Danger 8: Radio networks
Bluetooth and WLAN are constantly ‘on’? This can give hackers a good opportunity. There can also be security gaps in the Bluetooth connection that cyber criminals can exploit to gain access to the smartphone. However, this applies not only to mobile phones, but to all Bluetooth-enabled devices. If you no longer need the wireless interface, cut the connection.
That no longer happens to us - Bluetooth and Wi-Fi are switched off. The smartphone is also packed in the bag. We also go into ‘offline mode’ with a nap on the beach.
Danger 9: Distraction and carelessness

Falling asleep on the beach and leaving your mobile phone next to you on the side table, hanging your bag with your tablet on the chair in the crowded bar or quickly putting your camera next to you on the bench for a selfie with your smartphone - opportunity makes thieves. If we have to carry our mobile devices with us at all, then we should neither act carelessly nor allow ourselves to be distracted. Think about what you really need and lock the rest of your gadgets in the hotel safe. The sun isn't good for our mobile devices either - for this reason alone, we shouldn't carry our smartphone and co. with us on the beach in the midday heat.
In the evening on the beach, we plan a little photo shoot - also to give those at home a quick update on how we're getting on. What we don't realise is that someone is looking over our shoulder as we enter our social media password.
Danger 10: ‘Shoulder surfing’
Whether during the journey (seat neighbour or person behind you on the train or plane) or disguised as someone waiting at photo hotspots - before you enter a PIN or password, check whether someone is standing behind or to the right and left of you who is watching you. Scammers also use this trick to spy on sensitive data. If necessary, hold your hand over the screen and tap with your thumb.
‘Shoulder scouts’ can also be found at ATMs, and special care should be taken here too. ATM skimming’ also occurs time and again. Manipulated machines read your PIN and make a copy of your card - such tricks are particularly well known in non-European countries. If you are worried that you have come across such an ATM, check your bank account to be on the safe side.
Danger 11: Online banking
And then it was forgotten: The WLAN network was not checked in the excitement and the access data for online banking was intercepted. It would have been better to block the bank card via the emergency call and contact your bank advisor, who can also view transactions.
Of course, the emergency number for the blocking service is in my bag at the hotel.We check our emails, our bank also has the emergency number in its signature. There's an email from our bank, and now they're also asking us to update our password. The link sent takes us directly to the page where we can set a new password.
Danger 12: Malware & phishing mails
Never click on links without first checking them or the email itself! A closer look is often enough to realise that the logo, the signature, the URL or even the name of the contact person is incorrect or not quite the same. In the worst-case scenario, clicking on the link will install malware that will steal your sensitive data. Make sure that you also have an up-to-date antivirus programme installed on the devices you take with you on holiday. You can find out how to recognise hacking methods and protect yourself against them in our blog post: Social engineering.

Luckily, your card could be blocked via the emergency number without any money being debited beforehand. And our installed security programme also recognised the threat and blocked it. Unfortunately, we can't help but check our emails that we received in the office - but via a secure VPN tunnel - after all, one shock is enough on holiday.
After the trip, we go through each step in turn according to our ‘IT security plan’: we check our bank account, credit cards and subscription statements - are all the charges correct? Before we reconnect the mobile devices we used on holiday to our home network, we run a malware scan.
The passwords for the services used are also updated again - just to be on the safe side.We deal with our e-mails in the same way as the incoming post: presumably important ones in one pile, adverts in another, which are dealt with one by one. This way we keep calm and don't take on a mountain of work straight after our holiday.
And to ensure that our wonderful holiday memories are not lost, we create a backup of the photos and videos that we took on site.
Our conclusion:

Less is more - this should especially apply to mobile devices while on holiday. Did you follow our tips before you went away and carry out a digital recycling programme as well as making a backup copy? Then why not enjoy your holiday less virtually and more in the here and now? Instead of just posting your holiday pictures, you can also invite your family to a good old ‘slide night’ and not only provide insider knowledge about the most beautiful places, but also treat your loved ones to a typical dish that you got to know on your trip. In our fast-paced world, we are also becoming increasingly hectic and careless - but checking emails on public Wi-Fi networks can quickly become dangerous when travelling.
Why not let work be work while on holiday and simply relax - that way, we return to our desks completely different and more motivated after our ‘break’. You should also take a calm and considered approach before travelling. Create backups and ensure a high level of IT security in your home network - work through the points step by step in the weeks before your holiday, just as you cross things off your packing list. Then nothing will be forgotten and you can do what you should also do with your mobile devices while travelling: simply switch off.
Our hardware, which we use every day, can also use a holiday or a ‘detox cure’ from time to time: digital recycling not only creates more storage space, but also ‘speeds up’ your PC, smartphone or tablet again. How can you do this? Here you will find useful tips and tricks on the topic: ‘Detox for smartphones, computers & tablets: digital recycling’
Serverando wishes everyone a wonderful holiday season. By the way, you can find inexpensive hard drives, storage media and NAS systems for secure backups in our shop - used & refurbished for more sustainability. With the voucher code ‘SaSS5’ you will also receive a 5% discount on our entire range.

















