Event Planning Tips

Event Planner Scams in the Age of AI: 9 Threats to Watch For

The misspellings are gone. The awkward grammar is gone. The generic "Dear Valued Customer" greeting is gone. Everything you were taught to watch for in a phishing email was a byproduct of scammers writing in a second language at volume. That constraint no longer exists.

Event planner scams have always thrived on our workflow, because the job requires clicking links from strangers, onboarding vendors you have never met, and moving large sums of money on short timelines. What changed is that attackers can now research a specific planner, read their public event calendar, note which show they are running next month, and write a message that references all of it. Any experienced event planner will tell you the volume has gone up. What has actually gone up is the accuracy.

In September 2026, Skift Meetings reported on Nirjary Desai, CEO of KIS (cubed) Events, who lost control of her social accounts to a fake Meta policy violation notice. What made it work was not the message quality. It was the timing. She was in the middle of a real dispute over a social post when the warning landed. The year before, she had lost close to $20,000 to a fraudster posing as a Glidden Paints representative, complete with fake vendors, forged invoices, and real phone conversations.

Two different attacks. One planner. Both successful against someone who was already paying attention.

Here are the nine that are actually circulating, what each one looks like, and the single habit that stops each of them.

1. The attendee list scam

What it looks like: An email or LinkedIn message offering "the verified attendee list" for a show you are exhibiting at or organizing. The sender uses the show's real name, sometimes its real logo, and quotes a specific attendee count. Price is usually a few hundred to a few thousand dollars.

This is the oldest scam in the trade show business and it has never stopped working. It is persistent enough that industry associations have petitioned the FTC to intervene against the operators selling fraudulent lists and room blocks. Individual shows now run permanent scam alert pages because the messages go out to every exhibitor on the public exhibitor directory.

What makes it worse now: The lists are more convincing. AI-generated sample records look plausible, with real-sounding titles at real companies. Some sellers now deliver actual data scraped from LinkedIn and enriched with guessed email patterns, so the buyer gets something, just not what they paid for and not anything with consent attached.

The habit that stops it: No legitimate show sells its attendee list to exhibitors. None. If the show wanted exhibitors to have attendee contact data, it would provide it through sanctioned lead retrieval or a sponsored email program. Treat every list offer as fraud by default.

2. Room block poaching and housing pirates

What it looks like: Your exhibitors and attendees get calls or emails from a "housing bureau" claiming to handle the official block, warning that rooms are almost gone, and taking a deposit. The rooms do not exist, or they exist at a worse rate outside your block, which blows your attrition numbers.

This one has real legal history behind it. USPOULTRY was awarded $750,000 in damages against a convention hotel poacher, which tells you both that the practice is actionable and that it is worth enough money to be worth suing over. PCMA has written about the problem for years.

What makes it worse now: Cloned websites. A poacher can spin up a near-perfect copy of your housing page in an afternoon, with your branding, your hotel photos, and a domain one character off from yours.

The habit that stops it: Publish one housing URL, put it everywhere, and tell attendees in your confirmation email, your mobile app, and your pre-event communications that you will never call them about rooms. Register the obvious typo domains before someone else does.

3. Vendor and client impersonation with a fake RFP

What it looks like: An inbound inquiry from a recognizable brand asking you to produce an event. It is flattering, it is specific, and it moves fast. Somewhere in the process you are asked to front costs for AV, staffing, or a venue deposit to a vendor the "client" recommends. That vendor is part of the operation.

This is the Glidden Paints pattern from the Desai case, and it is the most expensive one on this list because it targets your accounts payable rather than your credentials.

The habit that stops it: Never pay a vendor introduced by a new client until you have verified that vendor independently. Call the brand's main switchboard from a number you found yourself, not one in the email, and ask for the person who supposedly signed the brief.

4. Platform impersonation phishing

What it looks like: A policy violation warning, a copyright claim, a suspended account notice, or a "your payment method failed" alert from Meta, Google, LinkedIn, Stripe, or your event registration software vendor. The link goes to a credential harvesting page.

What makes it worse now: Timing. Attackers watch for a trigger. They send the copyright claim right after you post a video with licensed music. They send the payment failure notice right after your registration opens and your card volume spikes.

The habit that stops it: Never act on a platform notice from the notice itself. Open a new tab, type the platform's address, and log in there. If the warning is real, it will be waiting in your account.

💡 Pro tip: Turn on a hardware security key or an authenticator app for every account that touches money or attendee data. Most of these attacks end at the second factor. SMS codes do not count, because the attacker who has your password can often intercept them.

5. Business email compromise and invoice redirection

What it looks like: A vendor you actually work with emails to say their banking details have changed, please update before the next payment. The email thread looks real because it often is real, forwarded from a compromised mailbox with a new reply-to.

What makes it worse now: Attackers who get into a mailbox can read months of history and write the change-of-bank notice in the vendor's own voice, timed to a real invoice that is actually outstanding. If you have already tightened up how payments move through registration, this is the same discipline applied to money going out instead of money coming in.

The habit that stops it: One rule, no exceptions: banking detail changes are verified by phone, using the number you already had on file, before any payment goes out. Write it into your AP process and tell your vendors it applies to them so nobody takes offense.

6. Voice cloning on authorization calls

What it looks like: A phone call, sometimes a video call, from your CEO, your client contact, or your finance lead, approving an urgent payment. The voice is right. Sometimes the face is too.

Voice cloning has moved from novelty to commodity, and the security community now treats it as the natural evolution of business email compromise. A few seconds of public audio is enough source material, and event professionals have a lot of public audio: panel recordings, podcast appearances, conference keynotes, promo videos.

The habit that stops it: A callback rule and a code word. Any payment authorization received by voice gets hung up on and called back on a known number. For small teams, a shared passphrase that never appears in writing works fine and takes five minutes to set up.

7. Fake speaker, sponsor, and exhibitor inquiries

What it looks like: An inbound sponsorship inquiry with a generous budget, or a speaker application from someone with a plausible bio. The goal is usually one of three things: a fraudulent payment that gets reversed after you have delivered the benefit, access to your exhibitor portal, or a badge that gets them onto the show floor to work your attendees.

The habit that stops it: Verify corporate affiliation independently before granting portal access. Keeping exhibitor accounts, booth staff registrations, and badge allocations in one auditable system rather than scattered across email threads makes this far easier, which is one more reason getting exhibitors onto your technology is worth the effort.

8. Fake directory and registration renewal invoices

What it looks like: An invoice for a trade show directory listing, a domain renewal, a business registry entry, or an exhibitor guide you never ordered. The amount is small enough that somebody in accounting might just pay it.

What makes it worse now: Volume and personalization. These used to be obvious form letters. Now they reference your actual show, your actual booth number, and your actual dates.

The habit that stops it: Every invoice needs a matching purchase order or a named internal owner who confirms they ordered it. No PO, no payment.

9. Credential phishing aimed at your attendee database

What it looks like: The first eight scams want your money. This one wants your data, and it is the one the industry talks about least.

A registration database is the most complete social engineering profile most organizations will ever assemble. Names, titles, employers, mobile numbers, hotel confirmations, arrival dates, dietary notes, sometimes accessibility information. It is everything an attacker needs to run a convincing attack on every one of your attendees, and it sits in a platform that a handful of people access with a password. The same first-party data that makes your events measurable is what makes your database worth stealing.

The habit that stops it: Two things, and neither is training. First, enforce single sign-on and hardware second factors on every account that can export attendee records. Second, ask your platform vendor the three questions in the next section.

✨ Expert Advice: Run an export audit before your next event. Pull the list of every person and every integration with export permissions on your registration and event check in software. Most teams find at least one former contractor, one departed employee, and one integration nobody remembers connecting.

What our industry gets wrong about this

The standard response to every one of these stories is more training. Send the team a phishing simulation. Circulate a memo about suspicious emails. Remind everyone to check the sender address.

That was reasonable advice when the fakes were bad. It is now the weakest control in the stack, because the signals it teaches people to detect have been automated out of existence. A well-resourced attacker in 2026 produces a message indistinguishable from a real one, and no amount of squinting at it will change that.

The controls that still work are structural, not perceptual. Out-of-band verification for anything involving money. Hardware second factors on anything holding data. A named owner for every invoice. A single published URL for housing. Least-privilege access on your attendee database. None of these require anyone to correctly identify a fake, which is exactly why they hold up.

The second thing the industry gets wrong is silence. Planners who get hit stay quiet because it is embarrassing, which means the next planner has no warning that the same operator is working the circuit. The Desai story is useful precisely because she talked about it twice.

It is also worth asking the broader question about physical and digital risk together, because the two budgets usually sit with different people. If you have ever wondered whether event security is worth it, the answer increasingly includes the parts of your event that never touch the venue floor.

⚡ Practical Advice: Add a fraud section to your standard event planning checklist. Three lines is enough: publish the anti-scam notice to exhibitors, confirm the housing URL is the only one in circulation, and re-verify banking details for every vendor being paid this cycle.

Three questions for your registration vendor

Most platforms get asked for a SOC 2 report during procurement and are never asked another security question for the life of the contract. That is a procurement ritual, not a security posture. Before your next renewal, ask these:

  1. What are we actually collecting that nobody uses? Every field you collect is a field that can leak. Custom questions accumulate across years of events and rarely get pruned.
  2. How long is attendee data retained after the show closes? You want a specific answer with a number in it. "Indefinitely" is an answer, and it tells you something.
  3. Who can export in bulk, and is it logged? Bulk export is the single riskiest action in the system. It should require elevated permission and it should leave a record.

If any of those takes more than a day to answer, that delay is the finding. A platform that runs registration, check-in, badging, and lead retrieval on one attendee record, like Expo Pass, should be able to show you the whole data path in a single conversation rather than routing you through three departments.

Final Takeaway

Event planner scams did not get more common. They got more accurate. The fakes now match the real thing closely enough that detection is a coin flip, which means the answer cannot be better detection. Build the process controls that work regardless of whether anyone spots the fake: verify money out of band, put hardware keys on anything holding attendee data, require a named owner for every invoice, and prune what you collect. Then talk about it when something gets through, because the operator who hit you is already working on the next planner on the list.

Frequently Asked Questions

What is the most common event planner scam right now?

The attendee list scam remains the most widely distributed, because exhibitor directories are public and the same message can go to thousands of exhibitors at once. The most expensive per incident is vendor impersonation with a fake RFP, since it targets accounts payable rather than a single login.

How do I know if an attendee list offer is legitimate?

Assume it is not. Legitimate shows do not sell attendee contact lists to exhibitors. If a show wants to give exhibitors access to attendees, it does so through sanctioned lead retrieval, a sponsored email program, or the event app, all of which carry consent from the attendee.

Does security awareness training still help with event industry fraud?

It helps at the margins, but it is no longer a primary control. Training teaches people to spot misspellings, generic greetings, and awkward phrasing, and AI-generated messages have none of those. Process controls that do not depend on human detection, like callback verification for payments, are what actually stop these attacks.

What should we do about room block poaching before a show?

Publish one housing URL and repeat it in every attendee and exhibitor communication, state clearly that you will never call anyone about rooms, register lookalike domains, and post a scam alert page on your event site. If poaching is already happening, document it, because there is legal precedent for recovering damages.

Who in our organization should own event fraud prevention?

Whoever owns accounts payable and whoever owns the registration platform, jointly. Most of these attacks resolve to either a payment leaving the building or an export leaving the database, and those are two different people in most organizations.

This article was written with the help of AI and edited by humans. Graphics were generated with the assistance of AI.

Keep reading

Event Planning Tips

Room Blocks and Group Rates: A Planner's Guide

Room blocks and group rates, explained. How blocks work, what attrition really means, and how to negotiate hotel rooms like a pro, minus the surprise bill.

July 21, 2026

Bring your next event to life.

See how Expo Pass powers registration, check-in, and engagement from start to finish.

Get a demo