Journal Press India®

Journal of Hospitality and Tourism Review
Vol 1 , Issue 1 , January - June 2026 | Pages: 1-11 | Research Paper

When the Algorithm Becomes the Adversary: Agentic AI Threats and Cybersecurity Vulnerabilities in India's Hospitality, Aviation, and Digital Payment Infrastructure

Author Details ( * ) denotes Corresponding author

1. * Ajay Parasher, Professor, Department of Public Management, Ethiopian Public Service University, Addis Ababa, Ethiopia (ajayprasher1969@rediffmail.com)
2. Parikshit Sharma, Associate Professor, Jagran School of Hospitality & Tourism, Jagran Lakecity University, Bhopal, Madhya Pradesh, India (prkshtsharma25@gmail.com)

Since the outbreak of the COVID-19 pandemic, we have seen a crucial shift in AI dimensions and usage. What earlier was mostly reflexive and responded to queries only, has shifted to a different paradigm of self-initiated actions and has become autonomous in nature. This paper examines and explores how upcoming agentic systems are remodeling the threat landscape of cybersecurity for the service sector of India, namely Hospitality, Aviation, and the Digital Payments environment. Through a qualitative study based on the case-study method, the research aims to analyze three deeply interconnected vulnerability structures: AI-architected social engineering scams targeting hotel Property Management Systems (PMS); operational disruption risks arising from API sprawl within Global Distribution Systems (GDS) consumed by the airline and hotel industries; and the critical exploitation of Aadhaar-Enabled Payment System (AePS) biometric infrastructure through machine-learning-assisted fingerprint cloning. The discussions and findings reveal how India’s hyperdynamic digital integration has outpaced the development of correlated defensive mechanisms. Towards the end, the paper sums up a multi-layered mitigation framework anchored in defensive AI Red-Teaming, biometric locking protocols under the UIDAI ecosystems, and regulatory compliance with the Digital Personal Data Protection (DPDP) Act 2023.

Keywords

Cybersecurity, Hospitality Sector, Aadhaar Fraud, Agentic AI, DPDP Act, Systemic Risk, Resilience

  1. Anthropic. (2024). Claude's character and agentic capabilities: A model card overview. Anthropic Technical Documentation. https://www.anthropic.com
  2. Bischoff, P. (2023, September 15). MGM Resorts cyberattack: What happened and what we know. Comparitech. https://www.comparitech.com/blog/information-security/mgm-resorts-cyberattack/
  3. Bommasani, R., Hudson, D. A., Aditi, E., Altman, R., Arora, S., Koreeda, M., & Liang, P. (2022). On the opportunities and risks of foundation models. arXiv preprint. https://doi.org/10.48550/arXiv.2108.07258
  4. Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101. https://doi.org/10.1191/1478088706qp063oa
  5. Brundage, M., Avin, S., Clark, J., Toner, H., Eckersley, P., Garfinkel, B., & Amodei, D. (2024). The malicious use of artificial intelligence: Forecasting, prevention, and mitigation (2nd ed.). Future of Humanity Institute, University of Oxford.
  6. CERT-In. (2024). Annual cybersecurity report 2024: Sectoral threat landscape. Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, Government of India.
  7. Creswell, J. W., & Poth, C. N. (2022). Qualitative inquiry and research design: Choosing among five approaches (5th ed.). SAGE Publications.
  8. Decrop, A. (1999). Triangulation in qualitative tourism research. Tourism Management, 20(1), 157–161. https://doi.org/10.1016/S0261-5177(98)00102-2
  9. Directorate General of Civil Aviation (DGCA). (2024). Annual civil aviation statistics 2023–24. Ministry of Civil Aviation, Government of India. https://dgca.gov.in
  10. Galbally, J., Marcel, S., & Fierrez, J. (2023). Biometric antispoofing methods: A survey in face recognition. IEEE Access, 11, 37892–37915. https://doi.org/10.1109/ACCESS.2023.3265011
  11. Kapoor, A., & Bhandari, V. (2024). The Digital Personal Data Protection Act 2023: Regulatory architecture and implementation challenges. The Centre for Internet and Society, India. https://cis-india.org
  12. MeitY India. (2023). Digital Personal Data Protection Act 2023: Compliance manual and sectoral guidance. Ministry of Electronics and Information Technology, Government of India.
  13. Mishra, R., & Singh, A. (2023). Cybersecurity posture of mid-market Indian hotel chains: An empirical assessment. Journal of Hospitality Information Technology, 15(2), 44–63. https://doi.org/10.1080/19368623.2023.2187341
  14. National Payments Corporation of India (NPCI). (2024). Annual report on UPI transaction ecosystem and fraud risk management 2023–24. NPCI. https://www.npci.org.in
  15. Open Web Application Security Project (OWASP). (2024). OWASP API security top 10 — 2024 edition. OWASP Foundation. https://owasp.org/www-project-api-security/
  16. Papadaki, M., Tryfonas, T., & May, J. (2023). API security in aviation distribution systems: Vulnerability mapping and remediation priorities. Journal of Air Transport Management, 108, 102379. https://doi.org/10.1016/j.jairtraman.2023.102379
  17. Park, J. S., Zou, C., Shaw, A., Hill, B. M., Cai, C., Morris, M., & Bernstein, M. S. (2024). AI and security: The emerging threat of autonomous cyberattack agents. Proceedings of the IEEE Symposium on Security and Privacy, San Francisco.
  18. PricewaterhouseCoopers (PwC). (2019). Marriott International data breach — A case study in post-merger cybersecurity failure. PwC Digital Risk Advisory. https://www.pwc.com
  19. Reserve Bank of India (RBI). (2025). Report on digital fraud in the Indian banking sector 2024–25. Department of Regulation, Reserve Bank of India. https://www.rbi.org.in
  20. Unique Identification Authority of India (UIDAI). (2025). Advancements in biometric security, face authentication, and the Aadhaar locking ecosystem: Annual report 2024–25. UIDAI, Government of India. https://uidai.gov.in
  21. Venkataraman, K. (2024). Digital transformation and cybersecurity risk in Indian low-cost aviation: A post-pandemic analysis. Asian Journal of Transport Policy, 6(1), 112–129. https://doi.org/10.1080/23249935.2024.2203111
  22. Weidinger, L., Uesato, J., Rauh, M., Griffin, C., Huang, P.-S., Mellor, J. & Gabriel, I. (2022). Taxonomy of risks posed by language models. In Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency (FAccT '22) (pp. 214–229). ACM. https://doi.org/10.1145/3531146.3533088
  23. Yin, R. K. (2018). Case study research and applications: Design and methods (6th ed.). SAGE Publications.
Abstract Views: 3
PDF Views: 9

Advanced Search

News/Events

Dr. Moonje Institute...

C.H.M.E. Society's Dr. Moonje Institute of Management and Computer...

Book Title: Convergi...

Title: Converging Horizons in Construction and the Bu...

Update: Reviewer Nam...

Dear Reviewer, Greetings!! We are pleased to inform you that your ...

💐Heartiest Congra...

JPI team extends its heartiest Congratulations to Prof. (Dr.) Thipendr...

Ramachandran Interna...

Ramachandran International Institute of Management (RIIM), Pune Org...

PCETs Pimpri Chinchw...

PCET's Pimpri Chinchwad College of Engineering and Research Org...

Institute of Managem...

Institute of Management Technology, Nagpur Organizing International...

GENDER CULTURES: Mul...

IIULM University, Milan, Italy Organizing GENDER CULTURES: Mul...

Dept. of MBA, Karnat...

Department of MBA, KLS, Gogte Institute of Technology, Belagavi Org...

Indira School of Bus...

Indira School of Mangement Studies PGDM, Pune Organizing Internatio...

By continuing to use this website, you consent to the use of cookies in accordance with our Cookie Policy.