POST /booking/holdBlockedOne actor holding 28 seats, none paid
- 28 holds in 20 minutes, 0 paid
- Headless Chrome with stealth plugin
- Mobile proxy exit
Industry
Travel and ticketing fraud is bots and fraudsters taking inventory, data and value from booking flows: scalpers buying tickets on sale, seat-spinning bots holding seats they never pay for, scrapers hammering fare search, stolen loyalty accounts and card testing at checkout. Kavra assesses every search, hold, login and payment and tells your backend who to let through.
POST /booking/holdBlockedOne actor holding 28 seats, none paid
Travel and ticketing sell perishable inventory. A seat on tonight's flight, a room for Saturday or a ticket for a show is worth nothing once the moment passes, and it is worth the most at the moment demand peaks. That makes the booking flow a target for automation that grabs inventory first, holds it without paying, or reads every price you publish.
The threats come in four shapes. Scalping bots buy tickets the second a sale opens and resell them at a markup. Seat-spinning bots start bookings they never finish, so real customers see a sold-out flight. Scrapers query fares and availability at a volume no shopper could, which costs real money when each search calls a third-party distribution system. And fraudsters go after the value stored in the flow: loyalty points, saved cards and the checkout itself.
Each threat hits a different step of the booking journey.
| Threat | Where it strikes | Business impact |
|---|---|---|
| Scalping and ticket bots | Queue, on-sale, cart, checkout | Fans priced out, brand damage, angry artists |
| Seat spinning and fare holds | Seat map, hold, unpaid booking | Flights look sold out, real sales lost |
| Fare and availability web scraping | Search, calendar, availability APIs | Search costs, look-to-book strain, price undercutting |
| API abuse of mobile and partner endpoints | App APIs, partner feeds | Load on booking engines, bypassed limits |
| Loyalty account takeover | Login, points redemption, transfer | Points drained, members lost |
| Credential stuffing | Login, password reset | Account lockouts, support load |
| Purchase limits beaten with multi-accounting | Account creation, per-customer caps | Caps and presales defeated |
| Card testing and payment fraud | Checkout, gift cards, ancillaries | Chargebacks, processor fees, flown or used tickets |
| SMS pumping | OTP at login and checkout | SMS bills from fake traffic |
Seat spinning is a form of denial of inventory. No money changes hands, so payment fraud checks never see it.
The operator picks a route, date or fare class, often to hold cheap seats for a resale scheme or to push demand toward another seller.
Headless browsers walk through search and seat selection, entering fake or recycled passenger names to reach the step where inventory is held.
Each booking sits in its hold window until it expires. The seats are counted as taken, so the flight shows fewer or no seats to real buyers.
When holds expire, the bot starts new ones through fresh sessions and residential and mobile proxies, keeping inventory blocked for days.
The operator lets seats go when it suits them, or converts a few holds into cheap bookings through the scheme that paid for the attack.
Checking only at payment misses the attacks that never pay. Each step needs its own question, and most answers should be invisible to real travelers and fans.
On-sale traffic is spiky and fans are impatient, so speed alone is not proof. Evidence across layers is.
The browser claims to be a normal laptop but runs automation with stealth plugins, or an antidetect browser profile that contradicts itself.
One actor starts many bookings or carts across sessions and lets every one expire.
Thousands of fare or date queries in a steady rhythm, with no seat selection, no dwell and no return to book.
A returning actor shows up with a fresh fingerprint for each queue slot or account, a sign of fingerprint rotation.
Traffic appears to come from many homes in the right market, but the IPs belong to commercial proxy pools, VPNs or datacenters.
A member who always logs in from one city suddenly redeems points from a new device on another continent.
Ticket bots are regulated in several markets. In the United States, the BOTS Act makes it unlawful to get around a ticket seller's security measures or purchase limits for events, and the FTC enforces it. In the United Kingdom, regulations made under the Digital Economy Act 2017 made it an offense to use software to buy more event tickets than a seller allows, with a view to financial gain. Laws like these give sellers a reason to show that their limits are enforced by more than a checkbox.
Airlines and OTAs feel scraping on their cost line. Many booking flows pay per search or depend on a look-to-book ratio agreed with a distribution partner, so bot searches that never book raise costs and can strain those agreements. In Europe, strong customer authentication rules for online card payments add a step at checkout, which is exactly why fraudsters prefer taking over loyalty accounts with saved details and why card testing aims at flows with weak checks.
Good protection lets fans and travelers move fast and makes each bot session more expensive than the ticket it was after.
How Kavra helps
Kavra analyzes 3,000+ data points on every visit and returns an explained verdict for each search, hold, login and payment. Your backend decides.
Headless browsers, stealth plugins, HTTP clients posing as browsers and antidetect profiles are exposed by contradictions between layers.
Returning devices are recognized across sessions and accounts, and fingerprint rotation is kept as one actor, so caps hold.
Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.
Search crawlers and AI agents booking for users are verified by signature and published ranges. Unverified impostors are flagged.
Each login is compared with the member's trusted devices, networks and history, including impossible travel.
Invisible to real fans. Extra background checks run when evidence is unclear, with nothing for travelers to solve.
FAQ
Something else? Talk to our team.
They spread one buyer across many identities. Operators open accounts with fresh emails and phone numbers, give each its own browser profile and residential IP, and join the queue with hundreds of sessions. Per-account or per-IP limits count each one as a different fan. Linking sessions and accounts to the device and behavior behind them lets limits apply per actor instead.
Seat spinning is when bots repeatedly start bookings and hold seats without paying, then start again when the holds expire. The seats look taken, so real travelers see limited or no availability. Because no payment is made, card fraud checks never see it. It is stopped by spotting automation and repeated unpaid holds from the same actor at the hold step.
Look-to-book ratio compares the number of searches with the number of bookings they produce. Scrapers and fare bots search constantly and never book, which drives the ratio up. For airlines and OTAs that pay per search or have ratio terms with distribution partners, that means higher costs. Filtering scraper traffic before it reaches the search engine brings the ratio back toward real demand.
In several markets, yes. The US BOTS Act makes it unlawful to circumvent a ticket seller's security measures or purchase limits for public events, and UK regulations under the Digital Economy Act 2017 created an offense for using software to buy more tickets than allowed, with a view to financial gain. Rules vary by country and state, so check with counsel for your market.
Mostly through account takeover. They test leaked passwords against loyalty logins, then redeem points for gift cards, flights or hotel stays in someone else's name, or transfer them out. Members often notice late because they check balances rarely. Comparing each login with the member's usual devices and locations, and stepping up before redemption, stops most of it.
Not by default. Verified AI agents acting for a real traveler can bring legitimate bookings, and blocking them may cost sales. The risk is impostors: scrapers that claim to be a known agent. Verify agents by their cryptographic signature and published IP ranges, then decide per path whether to allow, check or block them.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.