MalwareBytes

Scammers are getting smarter about where they target you 


Scammers are becoming more strategic about where they target people. 

Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. 

This finding comes from Malwarebytes’ own threat research systems and draws on global data between April 15 and July 14, 2026. The research reveals the various ways scammers are adapting their tactics and provides new insights about where they show up, when they strike, and which brands they impersonate.  

Here’s a look at the key takeaways. 

Every scam has a preferred platform 

You’re far more likely to receive a fake giveaway scam via a social media feed than you are by email or text. On the other hand, half of all IRS scams will come via a phone call. Malwarebytes measured more than 20 different types of scams, ranging from tech support and refund scams to sextortion and scareware, and found that each one favors a specific platform.

Intuitively, the platforms favored often match the content of a scam—job scams mostly arrive through typical work channels like email, romance scams mostly arrive through social media where meeting strangers is least questioned, and tech support scams mostly arrive through the phone. The channel can also shape how the scam feels: A DM can feel personal, while a phone call creates pressure to respond in the moment. And prior research shows that scammers often repeat what works, which might explain why they keep doing what they’ve been doing so far.  

The web still wins 

Despite the rise of social media and messaging apps, scams are reaching us through the web more than any other platform, followed by email and SMS.  

No surprise that the web is the most popular doorway. Malwarebytes blocks around 500,000 phishing websites a day.  

MrBeast beats Trump 

He’s already the most popular YouTuber in the world, famous for his online antics and extreme stunts, but Malwarebytes data shows that “MrBeast” can now add “most impersonated person” to his resume, handily beating Elon Musk and Donald Trump (numbers two and three, respectively).

MrBeast, whose real name is Jimmy Donaldson, is the go-to favorite for scammers looking to piggyback on his fame by using his likeness in some 30% of impersonation scams, ranging from crypto giveaways to transfer fee swindles. Familiar faces lower the public’s guard and make scam messages feel more credible, which is why they work so well. So, the next time MrBeast shows up in your feed asking you to send cash as part of a verification process, watch out.  

12:00 pm ET is the “golden hour” for scammers targeting Americans 

If you’re on the East Coast in America, lunchtime is also scamming time. Malwarebytes data shows that high noon is the golden hour for scam texts, and it’s roughly 874% busier than the quietest time, which is 1:00 am ET.    

Scam texts peak on Fridays 

The rate of scam texts hitting your phone builds throughout the week. From a low on Sunday, they increase steadily in frequency and hit their peak on Fridays. So by the time you’re leaving work and preparing for the weekend, you’re also getting hit with roughly 50% more fraudulent text messages than you were when the week began. The data doesn’t tell us why, but it does suggest scammers are deliberately timing their campaigns rather than sending messages at random. 

Big brands are big business for scammers  

The world’s biggest brands are also some of the most useful to scammers. They’re instantly recognizable, used by hundreds of millions of people, and already part of our everyday lives, making them a natural fit for everything from fake offers to bogus account alerts. Based on reports from Malwarebytes users, the five most impersonated brands are: 

  • Google
  • Microsoft 
  • Apple 
  • Roblox 
  • Amazon 

According to Malwarebytes users, Google’s brand name was abused at least twice as often as Amazon.  

Gaming is becoming a bigger target 

Scammers are increasingly targeting gaming communities. According to data collected by Malwarebytes Scam Guard, about half of all gaming scams can lead to a financial hit of $1,000 or more, what we term a “high-severity risk.” The most impersonated gaming sites were Roblox, Steam, Discord, and Minecraft. Roblox saw a 15% spike in scam activity from mid-June to mid-July, while Steam saw a 19% spike over the same period. 

How to spot and stop scams 

The data points to a scam economy that’s becoming more specialized. Rather than relying on one-size-fits-all campaigns, criminals are tailoring scams to the platforms we use every day, from email and text messages to gaming communities and social media. The tactics may change, but the goal stays the same: to earn your trust long enough to steal your money or your information. Knowing how those tactics vary from platform to platform makes them easier to recognize, and easier to avoid. 

In general:  

  • Do not click links or call phone numbers in unsolicited emails, text messages, or social media DMs. 
  • When in doubt, check the legitimacy of the message by going directly to the company’s official website and asking about it through official channels. Don’t follow sponsored search results to get there—these can be scams. 
  • Do not give out personal details, PINs, passwords, payment information, or verification codes during an unsolicited call. Legitimate companies will not ask for passwords or verification codes over the phone. Hang up and call back through the organization’s official phone number. 
  • Use a browser extension that blocks scam and phishing sites, such as Malwarebytes Browser Guard. It can flag a fake storefront before you land on it, including ones it hasn’t seen before. 
  • Install a mobile security product like Malwarebytes Mobile Security that filters out scam and spam text messages. 
  • Check if a message is legitimate. Malwarebytes Scam Guard can check a message, phone number, or link against its expansive threat intelligence database to determine if it is malicious or safe. It then provides information on red flags and any next steps you should take. Scam Guard flags approximately one in five analyzed sessions as high-risk—situations that could result in significant financial losses ($1,000 or more) or personal harm. 

Methodology   

The data in this report comes from Malwarebytes proprietary threat research systems, collected between April 15 and July 14, 2026. All data is anonymized and reflects what Malwarebytes is able to observe through its own infrastructure. 

This report is also available to read in PDF format.



Source link