New research from Gen, parent company of internet security company Norton, has uncovered some alarming news showing cyber criminals infiltrating systems people trust to run their scams and steal your money.
Gen’s H1 2026 threat report showed the latest threats had one thing in common – they were moving away from sending malicious links or dropping malware and instead targeting familiar systems and workflows we use every day.
In Australia scams were the biggest threat in the first half of 2026, followed by phishing, malvertising, and scam yourself attacks.
Scam activity has spiked by 32 per cent with a sharp rise in gambling scams, which surged an incredible 927 per cent while e-shop scams rose by 76 per cent, tech support scams were up 68 per cent, dating scams up 31 per cent and generic financial scams up 70 per cent.
But the central finding of the threat report shows a definitive shift in how attacks are launched.
The most successful threats in the first half of the year didn’t rely on technical exploits or deception.
Instead they succeeded because they were hard to tell apart from normal digital life.
For example a scam arrives through a hotel booking platform referencing a real reservation.
Or WhatsApp accounts compromised not through a password breach but by tricking users into approving an attacker’s browser as a linked device.
Fraud has also moved through real and verified financial accounts because the people behind those accounts had been recruited through social media with offers of quick cash.
“The most effective attacks in the first half of 2026 didn’t look like attacks,” said Vita Santrucek, Chief Technology & Development Officer at Gen.
“They arrived through booking platforms, family message threads, software update channels and AI agent workflows – all places people already trust.
“As attackers blend into everyday digital experiences, protection has to move closer to the moments where confidence is earned, exploited or broken.”
Threat Report Highlights
– 114.2 million e-shop scam attacks blocked, up 109 per cent – highlighting the growing risk of fake online stores targeting shopper
– A 387 per cent increase in government impersonation scams – showing criminals are increasingly exploiting trust in public institutions to steal money and information
– A more than 454 per cent increase in family impersonation scams, while separate “GhostPairing” activity showed how WhatsApp’s linked-device feature can be abused to gain persistent access to an account and allow people to impersonate loved ones
– 20.3 million tech support scam attacks blocked – reflecting continued attempts to trick people into giving scammers remote access to their devices or financial information
– More than 304 million scam-ad impressions identified across the EU and UK in less than one month – underscoring how easily fraudulent ads can reach people
– Roughly 1.9 billion tracking attempts blocked during H1 2026 – demonstrating the scale of online tracking that can erode consumer privacy
– Norton and LifeLock breach notification alerts with attributed lead sources increased 628.1 per cent up to 3.3 million, with more than 10 million breach notifications sent in total – proving more people’s personal information is being exposed in data breaches
– 734 per cent increase in bank account (depository) activity alerts – further evidence of the rapid financial exploitation that follows a breach
– 1 million web skimming attacks blocked, up 212 per cent – showing how attackers continued to target checkout flows where users already expect to enter payment details
– More than 15.7 million breached records containing email addresses identified, giving cybercriminals more opportunities to target consumers with phishing, scams, and account takeover attempts

