Meetings Industry Faces Rising Threat From CybercrimeSeptember 1, 2026

By
September 1, 2026

Meetings Industry Faces Rising Threat From Cybercrime

Planners should be careful when conducting business via computer because credible-looking correspondence might actually be a scam.

Planners should be careful when conducting business via computer because credible-looking correspondence might actually be a scam.

The client appeared legitimate. The emails were professional. The requirements for the “office opening and teambuilding day” were detailed. The budget seemed substantial. Over several weeks, Atlanta-based event professional Nirjary Desai exchanged documents, timelines and planning details with what appeared to be Glidden Paint.

Then, nearly $20,000 vanished.

Desai, MBA, owner/ principal project manager of KIS(cubed) Events, was the target of a cyber-enabled payments scam that exploited one of the industry’s greatest strengths, its willingness to solve problems quickly for clients.

A fraudster, posing as a Glidden Paints exec, engaged her firm for what appeared to be a standard event, exchanging detailed emails, documents and timelines over several weeks. As part of the arrangement, Desai was asked to advance funds to several “required” vendors, only discovering later that both the client and vendors were part of the same operation.

The incident highlights how social engineering and business email compromise are affecting meeting and incentive planners. In Desai’s case, the attackers did not need to break into her systems; they relied on credible-looking communication and knowledge of standard industry workflows, including planners fronting payments to keep programs on track.

The credit card they used for the “vendors” went through and Desai then transferred funds to them. A few days later she was contacted by the bank that the card was stolen. In addition, a fraudulent ACH wire transfer was submitted for $10,000 that went through.

As meetings, conventions and incentive programs become increasingly dependent on digital platforms, cybercriminals are discovering that event professionals represent attractive targets. Registration systems contain personal information. Housing platforms manage payment details. Incentive travel programs include executive itineraries and VIP data. Event organizers routinely coordinate large payments among hotels, destination management companies, transportation providers, production vendors and venues, often under significant time pressure.

The result is a growing wave of cybercrime targeting an industry that has traditionally focused more attention on physical security than digital security. Today, danger also is hidden behind computer screens. As digital tools are relied on to manage registration, housing and data collection, the industry has become a lucrative target for cybercriminals exploiting weak links in event tech systems.

Why the Industry Is Vulnerable

For cybercriminals, meetings and incentive travel programs present a unique combination of opportunity and urgency.

Meeting planners manage large databases containing attendee information, payment details, travel records and corporate contacts. Incentive travel professionals often oversee executive itineraries, rooming lists, airline arrangements and confidential business information. At the same time, planners work across dozens of technology platforms and communicate with numerous vendors, suppliers and stakeholders.

“Scams do not start as ‘cybersecurity incidents,’” says cybersecurity and compliance executive Carl B. Johnson, founder and CISO of Cleared Systems. They start as normal-looking business opportunities.

“A planner receives a professional email from someone claiming to represent a corporation, a new office or an executive team. The opportunity sounds legitimate, the budget may sound attractive and then the pressure begins: use this preferred vendor, move quickly, wire funds, accept unusual payment instructions or skip the normal verification process,” says Johnson. “That is where planners get exposed.”

Johnson recommends event planners treat new corporate inquiries the same way a security team treats a new vendor relationship: verify the company independently, confirm the requester through a known corporate channel, review payment instructions carefully and slow down any request that introduces urgency, secrecy or a third-party vendor the planner has not vetted.

“Event planners should be especially cautious when a new client insists on using a preferred vendor, changes payment instructions or pushes the planner to move money before the client relationship has been properly verified,” he adds.

“Cybersecurity is not just firewalls and passwords. For event planners, cybersecurity also means protecting the payment process, vendor relationships, client intake process and the decision-making workflow,” says Johnson.

The Human Element

Many of today’s most successful cyberattacks don’t begin with sophisticated malware or a network breach. They begin with a conversation.

“Cybercriminals don’t just hack technology; they hack human behavior. In the events world, they exploit people’s desire to be helpful, responsive and fast,” says Emmanuel Nwajiaku, founder and senior GRC advisor for Im Way Ahead LLC. “In a fast-moving event environment, staff may feel pressure to click, approve, download or pay before taking time to verify.”

Business email compromise, or BEC, may be one of the most financially damaging threats to event organizers, says Nwajiaku. In these attacks, a criminal either compromises a legitimate email account or convincingly impersonates a trusted vendor, client or executive.

“Because the request appears to come from a familiar person or organization, the usual warning signs may not be obvious,” says Nwajiaku.

For meeting and incentive travel professionals, these attacks can be especially costly because large deposits and vendor payments are common throughout the planning process. A fraudulent wire transfer may not be discovered until weeks later when a hotel, destination management company, transportation provider or production vendor reports that payment never arrived.

When Referrals Become Attack Vectors

Another incident involving event strategist Sara Beth Raab, chief events officer of SB Events, underscores how vulnerable even seasoned professionals are to sophisticated fraud targeting the meetings and incentives sector.

Approached by a seemingly high-value prospect who arrived via a trusted industry referral, Raab engaged in multiple calls and detailed planning discussions before the red flags appeared. The “client” eventually asked her to route payments to his preferred vendors, effectively turning her agency into a pass-through bank for funds she had not yet received.

Raab declined, holding a firm boundary without escalating the situation, and no money changed hands.

She later learned this was part of a wider pattern aimed at event agencies and independent planners, often leveraging respected industry organizations and foundations to appear legitimate.

In addition, Raab is seeing an increase in scams in the events space focused on job opportunities.

“I can’t figure out what exactly the point of the conversation is. They don’t seem to be selling anything … And they don’t seem to be trying to get any additional information … they just talk about how they can help you find opportunities but never say what those opportunities are,” Raab says. “I will say, I did use AI to help me figure out if it was AI … meta and ironic.”

Purchasing cyber insurance and creating incident response plans to avoid problems with cyber attacks would be helpful.

Purchasing cyber insurance and creating incident response plans to avoid problems with cyber attacks would be helpful.

AI Being Used in Scams

AI is making these scams even more sophisticated. Criminals are now using AI-generated “deepfake” video calls to supercharge traditional business email compromise scams. In one widely reported case, a senior finance employee in Hong Kong received an email, apparently from the firm’s UK-based CFO, instructing him to urgently execute a series of confidential transfers. Initially suspicious, he was invited to a video call that appeared to include the CFO and several colleagues he recognized, all speaking and behaving as expected. Reassured by seeing their “faces” on screen, he went on to complete multiple transfers totaling roughly $25 million to accounts controlled by the fraudsters.

Investigators later determined that every person on the call had been an AI-generated fake, built from publicly available footage and audio of the company’s executives. Attackers cloned both faces and voices, then orchestrated a convincing group meeting over a mainstream videoconferencing platform. No core financial systems were hacked, and no one broke into the company’s network; instead, the crime relied almost entirely on social engineering and the employee’s trust in what he thought he was seeing and hearing in real time. The fraud only came to light when the employee informally checked with head office about the “confidential” transfers and learned they had never been authorized.

For corporate and incentive travel programs, this incident is a warning that traditional trust signals — recognizing a leader’s voice on a call, or seeing them on Zoom from a hotel room or airport lounge — are no longer sufficient to greenlight large or unusual payments. Travel and events professionals often handle last-minute venue deposits, airline payments and onsite emergency expenses under time pressure and across time zones, which makes them attractive targets. Companies are responding by tightening controls: enforcing dual approvals for high-value transfers, requiring out of band verification via known phone numbers for any unusual request and training staff that it is acceptable — even expected — to pause a transaction and independently verify it, no matter how senior the person on the screen appears to be.

Red Flags

For corporate and incentive travel planners and suppliers, these cases are a timely reminder to re-evaluate financial protocols around new business. Common red flags include requests to pay third party vendors before client funds have been received, unusual urgency around deposits and insistence on using nonstandard payment channels.

The widespread adoption of QR codes throughout the events industry has created another opportunity for criminals.

It has removed many of the visual cues people once used to judge whether a link was legitimate, says Nwajiaku.

“At events, attackers can use fake QR codes, raffle forms, giveaway pages or promotional links to direct attendees and staff to malicious websites, credential-harvesting forms, or fraudulent payment pages,” he says.

There is also risk from promotional devices such as USB drives. A free giveaway can become a baiting attack if the device is designed to install malware or compromise a system.

Event organizers should adopt an approved-link and QR-code policy. Vendors should not be allowed to place ad-hoc QR codes on signage, booths or printed materials without review. Registration, payment, lead capture and giveaway forms should use approved, verifiable links.

“The goal for the event industry should not be to make staff, vendors and attendees paranoid. The goal should be to build a culture of verification. A simple, intentional pause to verify a payment request, confirm a vendor change or check the source of a QR code can prevent serious financial loss and protect attendee information,” says Nwajiaku.

The Real Cost of a Cyber Incident

The financial consequences of cybercrime extend far beyond stolen funds.

Meeting planners handle registration databases full of personal and sometimes payment data. They curate corporate travel patterns, incentive-trip details and VIP itineraries that can be monetized or used for social engineering.

They also rely on a patchwork of software platforms, including registration systems, event apps, housing tools, AV integrations, virtual platforms and customer relationship management systems, all connected through numerous APIs and third-party vendors.

Cyber incidents can stop an event in its tracks. Ransomware attacks targeting registration platforms can freeze check-in operations, badge printing and payment processing. Business email compromise schemes can redirect exhibitor, sponsor and client payments. Attacks on event Wi-Fi networks, mobile applications and lead-retrieval systems can undermine attendee experiences and exhibitor return on investment.

The financial damage often extends well beyond the initial attack. Organizations may face forensic investigations, legal expenses, cyber insurance claims, crisis communications efforts, regulatory reviews and investments in new security technologies.

For meeting planning companies, whose businesses depend on trust and repeat relationships, reputational damage can be even more costly than direct financial losses.

Data leaks involving attendee information, executive travel plans, spending patterns or confidential corporate data can have long-lasting consequences, particularly in industries such as pharmaceuticals, finance, healthcare and government, where privacy expectations are especially high.

Building a Culture of Verification

Experts agree that prevention begins with awareness.Strong supplier vetting, two-factor authentication, secure payment procedures and staff training on phishing and social engineering are increasingly viewed as baseline requirements rather than optional safeguards.

Corporate planners should also verify domains for event websites, use secure payment gateways and include cyber risk in RFP evaluations when sourcing destination management companies, technology providers and other event partners.

Some organizations are going even further, purchasing dedicated cyber insurance coverage and developing incident-response plans specifically for meetings and events.

As the industry continues to embrace AI-powered personalization, virtual site inspections, mobile engagement platforms and increasingly connected event technologies, cybersecurity is becoming an operational necessity.

The future of meetings and incentive travel depends not only on creativity, logistics and attendee engagement, but also on protecting the digital infrastructure that makes those experiences possible.

Because in an industry built on trust, the most damaging disruption may never occur in a ballroom, exhibit hall or resort meeting room. It may arrive through a seemingly ordinary email.  C&IT

Back To Top