Bitdefender Report Reveals How Scams Operate Across Digital Channels

Inside Bitdefender’s 2026 Global Scam Findings

Scams increasingly operate as coordinated campaigns that follow people across the digital services they use each day. A deceptive advertisement may lead to a fraudulent website before the interaction continues through a messaging app, phone call or payment request. This movement between channels makes scams harder to identify and exposes the limitations of controls designed around a single point of contact.

The Bitdefender Global Scam Intelligence Report 2026, based on the company’s telemetry and analysis from 1 January to 31 December 2025, documents this shift across web traffic, SMS, social media advertising, WhatsApp and voice calls. Its findings suggest that scam operations are becoming more organised, more adaptive and better able to exploit the trust people place in familiar platforms, brands and communication methods.

Scam Delivery Is Becoming Omnichannel

Web links remain a central part of scam infrastructure. Bitdefender scanned 2.8 trillion URLs during 2025 and found phishing to be the largest scam category, accounting for 24.5% of incidents in its dataset. Financial and investment scams accounted for 10.7%, followed by fake shops and advertising scams at 9.3% and job scams at 8.7%.

However, these categories should not be understood as separate threats confined to individual channels. The same financial scam can be promoted through a paid social media advertisement, continued through a messaging app and reinforced by a call from someone impersonating a financial institution. The lure changes to fit the platform while the underlying objective remains the same.

This model gives scammers several opportunities to establish credibility. Each interaction can make the next one appear more legitimate, particularly when the victim encounters consistent branding, account names and explanations across different services.

Paid Advertising Places Scams Within Everyday Content

The report identifies malicious advertising as a major scam delivery mechanism. Rather than arriving as an unsolicited email, scam advertisements appear alongside legitimate posts, videos and search results. Sponsored placement can give fraudulent content an appearance of legitimacy, even though a paid or promoted label is not a guarantee of safety.

Bitdefender estimates that scam advertisements reached 60 million people across social media and video platforms during the period analysed. The company recorded exposure among 18.2 million people in the United States, 11.1 million in Germany and 8.5 million in the United Kingdom. In Romania, more than 40% of the population was exposed to at least one scam advertisement, according to the report’s telemetry.

Some campaigns display the characteristics of coordinated commercial operations. In one case documented by Bitdefender, a single page launched more than 100 malicious advertisements on Meta platforms within 24 hours. Coordinated accounts promoted pages impersonating cryptocurrency and trading services, with advertisements localised for audiences across several regions.

The campaign later expanded from desktop devices to Android, showing how scam infrastructure can be adapted as opportunities change. Bitdefender also observed campaigns using technical measures to identify security analysis and display legitimate content instead of a malicious payload when scrutiny was detected.

These tactics were examined during Trusted Channels, Hidden Threats, a Bitdefender-hosted workshop at the Global Anti-Scam Summit Europe 2026. Bitdefender researchers described a malvertising campaign involving more than 60,000 malicious advertisements, over 3,000 domains and subdomains and thousands of coordinated social media accounts. The campaign operated across Meta, Google and YouTube and targeted Windows, Mac and Android users. Its advertisements impersonated trusted brands, news organisations and public figures while adapting their content around major entertainment, sporting and cultural events.

Familiar Trust Signals Are Being Repurposed

Across channels, scammers use features that normally help people judge whether an interaction is credible. These include caller ID, business account labels, verification marks, sponsored placements, familiar branding and messages received from known contacts.

Bitdefender found that 61% of the risky WhatsApp conversations it analysed originated from business accounts. More than 310,000 risky conversations were detected in India alone.

Business profiles can display a company name, logo and description while also supporting automated replies and other tools that allow operators to manage conversations at scale. These features are useful for legitimate organisations but can also help scam operations present themselves as established businesses and manage large numbers of prospective victims.

Account takeover adds another layer of credibility. The report describes a voting scam in which recipients are directed to a professional-looking website and asked to enter a phone number and verification code. The code is actually used to take over the victim’s WhatsApp account. The compromised account can then be used to approach the victim’s contacts, allowing the scam to spread through an existing relationship rather than an unknown sender.

Other campaigns turn recipients into distributors without taking over their accounts. Fake promotions may require a message to be forwarded to multiple contacts before a supposed reward can be claimed. In both cases, the scam uses social proximity to overcome the caution people may apply to unsolicited contact.

Looking to contribute to collaborative anti-scam initiatives? GASA Working Groups bring members together to develop practical, real-world solutions.

Financial Scams Adapt to Each Communication Channel

Financially motivated scams remain prominent throughout the report. Finance accounted for 36% of the risky SMS campaign categories identified by Bitdefender. Across all SMS traffic analysed, 5.16% was associated with risky campaigns, equivalent to approximately one in 20 messages.

Voice calls show a similar concentration. Bitdefender analysed nearly 150 million incoming calls during 2025 and classified 23.5 million as unwanted. This represents more than 15% of calls reaching protected devices, or approximately one in six.

Financial institution impersonation accounted for around one quarter of the scam calls classified by theme, while investment scams made up a further 8%. In Bitdefender’s US honeypot data, malicious calls lasting more than 30 seconds continued for an average of three minutes and 36 seconds. Phishing calls were the longest category, with an average duration of eight minutes and eight seconds.

The communication method shapes how pressure is applied. SMS messages often use delivery, government or financial impersonation to prompt an immediate click. Social advertisements place investment or shopping lures within normal browsing. Calls allow an operator to adjust the script in real time, answer objections and create urgency. Messaging apps provide space for longer conversations and repeated contact.

The report also shows that scam categories vary between countries. Phishing leads across the markets analysed, but delivery scams, romance scams, crypto fraud and other categories fluctuate by region. Scammers retain a broadly consistent operational model while adapting the narrative to local habits, institutions and current events.

Scam Activity Reflects Organised Working Patterns

The data indicates that many scam campaigns are run as structured operations rather than isolated attempts. Bitdefender’s call telemetry shows activity peaking between Tuesday and Thursday, with declines of 70% to 80% on Sundays. It also records patterns around holidays that resemble the schedules of legitimate organisations.

Voice operations can combine robocalls, spoofed local numbers and human operators. Automated systems generate or qualify leads before engaged targets are transferred to operators trained to obtain credentials, remote access or payments.

Advertising campaigns similarly use coordinated accounts, localisation, technical evasion and rapid testing across devices. Scammers also adapt quickly to news, entertainment releases, major events and seasonal shopping periods, inserting fraudulent offers into topics already attracting attention.

This industrial structure helps explain the scale and persistence of scam activity. Operators can refine scripts, reuse infrastructure and shift resources towards the channels and themes that generate the strongest response.

Prevention Must Follow the Full Scam Journey

The findings demonstrate why channel-specific warnings are no longer sufficient. People still need to recognise suspicious emails, but they also need to question promoted posts, unexpected business messages, caller ID and payment requests that appear to follow a legitimate interaction.

For organisations, prevention requires visibility across the full path from initial exposure to financial loss. Platforms, telecommunications providers, financial institutions, cybersecurity companies and public authorities each observe different parts of that path. Faster intelligence sharing can help connect an advertisement, domain, phone number, messaging account and beneficiary account before the same campaign reaches more people.

Controls should also account for the transfer of trust between channels. Removing a fraudulent website may have limited effect if the associated advertisements, messaging accounts and phone numbers remain active. Coordinated disruption is more likely to constrain an operation than action against a single asset.

The report’s figures reflect Bitdefender’s own products, services and analytical models rather than a complete measure of global scam activity. Even with that limitation, the patterns are consistent: scams are being delivered through interconnected systems, using familiar trust signals and organised infrastructure. Effective prevention increasingly depends on recognising and disrupting the campaign as a whole.

Sign up for the GASA newsletter to receive regular updates on scam prevention, research, and best practices.

Jul 21, 2026
10 minute read
Category
Research Region - Europe Topic - Fraud Prevention Region - Global Scam Trends Presentations Topic - Fraud Research Topic - Scam Detection Industry - Big Tech / Social Media Event - GASS Europe 2026
Written by
Global Anti-Scam Alliance (GASA)
Global Anti-Scam Alliance (GASA)
Share article

Latest blogs & research

GASA Mexico Brings Journalists Together to Strengthen Digital Scam Prevention

GASA Mexico Workshop Examines the Role of Journalism in Digital Scam Prevention

GASA Mexico brought together journalists and editors to discuss digital scams, victim-centred reporting and the role of media in scam prevention.

News Best Practices Topic - Data Sharing Topic - Scam Awareness
Brazil Anti-Scam Forum 2026

Brazil Anti-Scam Forum 2026: Key Takeaways on Strengthening Scam Prevention in Brazil

Key insights from the Brazil Anti-Scam Forum 2026 on scam trends, prevention, intelligence sharing and cross-sector collaboration.

Best Practices Industry - Telecom Operators / Hosts Topic - Fraud Prevention Topic - Data Sharing
Consumer Education Working Group's 5-Step Scam Response Plan

GASA Consumer Education Working Group Develops 5-Step Response Plan for Scam Victims

GASA’s Consumer Education Working Group sets out a five-step response plan that organisations can use and share to support people affected by scams.

Best Practices Industry - National Cyber Security Centers (NCSCs) Topic - Scam Reporting Topic - Scam Awareness
GASA and UNODC Strengthen Global Cooperation Against Organised Fraud

GASA and UNODC Partner to Strengthen Global Response to Organised Fraud

GASA and UNODC sign an MoU to strengthen international cooperation on fraud prevention, research, criminal justice responses and awareness.

News Region - Global Topic - Fraud Policy Industry - Policy Makers
Recognising excellence in combating scams at the Scam Fighter Awards in America

Meet the Winners – Scam Fighter Awards at the Global Anti-Scam Summit America 2026

Meet the winners of the Scam Fighter Awards at the Global Anti-Scam Summit America 2026 and learn about their work in education, research, collaboration and technology.

News Topic - Data Sharing Topic - Scam Awareness Region - Global
truthscan joins scam.org

Global Anti-Scam Alliance Partners with TruthScan to Integrate Deepfake Detection on scam.org

Users of scam.org will now be able to upload an image to the website for analysis to determine whether the image is authentic, edited, or generated by artificial intelligence.

News Region - Global Topic - Scam Detection Region - North America
Turning Fraud Data Into Actionable Intelligence

From Information Sharing to Intelligence Production: GASA Mexico in Forbes

Sissi de la Peña, Director of the GASA Mexico Chapter, examines in Forbes México what the U.S. memorandum on cyber operations against fraud networks means for the country.

Best Practices Topic - Fraud Prevention Topic - Data Sharing Industry - Financial Authorities
GASA Africa Chapter & Google South Africa Trust & Safety Workshop

GASA and Google Trust & Safety Workshop Sets Priorities for Anti-Scam Cooperation Across Africa

GASA Africa Chapter and Google South Africa brought anti-fraud leaders together to strengthen cross-border cooperation and scam prevention.

News Topic - Fraud Prevention Topic - Data Sharing Topic - Scam Detection