As travel surges this summer, Zimperium has announced that it is sounding the alarm on escalating mobile cyber-threats targeting employees on the move.
According to new threat intelligence from Zimperium, over five million unsecured public Wi-Fi networks have been detected globally since the beginning of 2025 with 33% of users still connecting to these open networks, putting enterprise data at immediate risk.
“An ideal attack surface”
Kern Smith, VP of Global Solutions, Zimperium commented: “Mobile devices are now a primary gateway to corporate data but during travel, they’re also the most vulnerable.
“Unsecured Wi-Fi, phishing disguised as travel alerts and risky sideloaded apps are creating an ideal attack surface for cybercriminals, especially in peak travel months.”
Global Hotspots and Rising US Threats
Zimperium researchers state that they have identified significant spikes in mobile malware activity across Southeast Asia, with Vietnam, Malaysia and the Philippines experiencing some of the highest infection volumes.
The company says that Luxembourg has emerged as a global outlier with elevated mobile malware targeting international travellers and corporate devices.
In the US, major cities like Los Angeles, New York, Portland, Miami and Seattle are now seeing increased levels of mobile threats, driven by high numbers of business and vacation travellers, high mobile usage and widespread unsecured network access.
For enterprises with mobile workforces, Zimperium highlights that this trend represents a growing risk of data exposure and potential breach.
Mobile Threats Amplified by Travel
According to the Zimperium 2025 Global Mobile Threat Report, attackers are actively shifting to a mobile-first attack strategy. The most common threats facing traveling employees include:
- Man-in-the-Middle (MiTM) Attacks via public or rogue Wi-Fi
- Phishing disguised as travel alerts, such as fake itineraries or boarding passes
- Risky sideloaded apps downloaded during travel
- Captive portals collecting emails or phone numbers, increasing phishing risk
“Not hypothetical threats”
Smith later added: “These are not hypothetical threats. They’re happening now and they’re hitting devices that may lack even basic protection.”
Call to Action for Enterprises
Zimperium urges organisations to ensure visibility into all mobile endpoints, enforce device compliance and block connections to unsecured networks.
Businesses are encouraged to adopt enterprise-grade mobile threat defense to protect employee devices during travel.

