McAfee Labs' latest research shows that even if users remove location tags and GPS information from photos, AI can still determine the shooting location by analyzing the content of the image. In tested travel photos, AI successfully identified the shooting location in 87% to 91% of cases, revealing a privacy risk that persists even after removing metadata.
Locate without GPS, rely on visual details
This technology does not depend on geographic metadata but extracts clues from the visual elements of the photo itself. Building styles, store signs, road markings, vegetation types, natural landscapes, and landmarks may all serve as references for positioning. Sometimes, even ordinary scenes such as beaches, hotel rooms, or rivers can allow AI to infer the country or specific location.
Existing AI geolocation tools have demonstrated the practical level of this capability. They analyze buildings, terrain, streets, signs, and environmental details to guess the location, and they can work even when the photo file contains no GPS or EXIF information. Modern visual models have a geographical awareness far beyond expectations.
Personalized fraud is the biggest threat
More concerning is that criminals may combine location capabilities with phishing scams. When someone posts vacation photos on social media, they might inadvertently reveal their destination or arrival, providing materials for precise fraud.
Scammers can then send fake messages disguised as bank security alerts, claiming that users have made suspicious transactions at the exposed location. Because the details match the real itinerary, the credibility significantly increases. McAfee warns that this highly customized form of fraud is becoming an increasingly serious threat. Users should avoid posting photos in real time, limit the visibility of their posts, and carefully check location clues in the images before posting. Although removing metadata helps, the visual information in the photo itself may still be used by AI.
