Bitdefender Report Reveals How Scams Operate Across Digital Channels

Scams increasingly operate as coordinated campaigns that follow people across the digital services they use each day. A deceptive advertisement may lead to a fraudulent website before the interaction continues through a messaging app, phone call or payment request. This movement between channels makes scams harder to identify and exposes the limitations of controls designed around a single point of contact.
The Bitdefender Global Scam Intelligence Report 2026, based on the company’s telemetry and analysis from 1 January to 31 December 2025, documents this shift across web traffic, SMS, social media advertising, WhatsApp and voice calls. Its findings suggest that scam operations are becoming more organised, more adaptive and better able to exploit the trust people place in familiar platforms, brands and communication methods.
Scam Delivery Is Becoming Omnichannel
Web links remain a central part of scam infrastructure. Bitdefender scanned 2.8 trillion URLs during 2025 and found phishing to be the largest scam category, accounting for 24.5% of incidents in its dataset. Financial and investment scams accounted for 10.7%, followed by fake shops and advertising scams at 9.3% and job scams at 8.7%.
However, these categories should not be understood as separate threats confined to individual channels. The same financial scam can be promoted through a paid social media advertisement, continued through a messaging app and reinforced by a call from someone impersonating a financial institution. The lure changes to fit the platform while the underlying objective remains the same.
This model gives scammers several opportunities to establish credibility. Each interaction can make the next one appear more legitimate, particularly when the victim encounters consistent branding, account names and explanations across different services.
Paid Advertising Places Scams Within Everyday Content
The report identifies malicious advertising as a major scam delivery mechanism. Rather than arriving as an unsolicited email, scam advertisements appear alongside legitimate posts, videos and search results. Sponsored placement can give fraudulent content an appearance of legitimacy, even though a paid or promoted label is not a guarantee of safety.
Bitdefender estimates that scam advertisements reached 60 million people across social media and video platforms during the period analysed. The company recorded exposure among 18.2 million people in the United States, 11.1 million in Germany and 8.5 million in the United Kingdom. In Romania, more than 40% of the population was exposed to at least one scam advertisement, according to the report’s telemetry.
Some campaigns display the characteristics of coordinated commercial operations. In one case documented by Bitdefender, a single page launched more than 100 malicious advertisements on Meta platforms within 24 hours. Coordinated accounts promoted pages impersonating cryptocurrency and trading services, with advertisements localised for audiences across several regions.
The campaign later expanded from desktop devices to Android, showing how scam infrastructure can be adapted as opportunities change. Bitdefender also observed campaigns using technical measures to identify security analysis and display legitimate content instead of a malicious payload when scrutiny was detected.
These tactics were examined during Trusted Channels, Hidden Threats, a Bitdefender-hosted workshop at the Global Anti-Scam Summit Europe 2026. Bitdefender researchers described a malvertising campaign involving more than 60,000 malicious advertisements, over 3,000 domains and subdomains and thousands of coordinated social media accounts. The campaign operated across Meta, Google and YouTube and targeted Windows, Mac and Android users. Its advertisements impersonated trusted brands, news organisations and public figures while adapting their content around major entertainment, sporting and cultural events.
Familiar Trust Signals Are Being Repurposed
Across channels, scammers use features that normally help people judge whether an interaction is credible. These include caller ID, business account labels, verification marks, sponsored placements, familiar branding and messages received from known contacts.
Bitdefender found that 61% of the risky WhatsApp conversations it analysed originated from business accounts. More than 310,000 risky conversations were detected in India alone.
Business profiles can display a company name, logo and description while also supporting automated replies and other tools that allow operators to manage conversations at scale. These features are useful for legitimate organisations but can also help scam operations present themselves as established businesses and manage large numbers of prospective victims.
Account takeover adds another layer of credibility. The report describes a voting scam in which recipients are directed to a professional-looking website and asked to enter a phone number and verification code. The code is actually used to take over the victim’s WhatsApp account. The compromised account can then be used to approach the victim’s contacts, allowing the scam to spread through an existing relationship rather than an unknown sender.
Other campaigns turn recipients into distributors without taking over their accounts. Fake promotions may require a message to be forwarded to multiple contacts before a supposed reward can be claimed. In both cases, the scam uses social proximity to overcome the caution people may apply to unsolicited contact.
Financial Scams Adapt to Each Communication Channel
Financially motivated scams remain prominent throughout the report. Finance accounted for 36% of the risky SMS campaign categories identified by Bitdefender. Across all SMS traffic analysed, 5.16% was associated with risky campaigns, equivalent to approximately one in 20 messages.
Voice calls show a similar concentration. Bitdefender analysed nearly 150 million incoming calls during 2025 and classified 23.5 million as unwanted. This represents more than 15% of calls reaching protected devices, or approximately one in six.
Financial institution impersonation accounted for around one quarter of the scam calls classified by theme, while investment scams made up a further 8%. In Bitdefender’s US honeypot data, malicious calls lasting more than 30 seconds continued for an average of three minutes and 36 seconds. Phishing calls were the longest category, with an average duration of eight minutes and eight seconds.
The communication method shapes how pressure is applied. SMS messages often use delivery, government or financial impersonation to prompt an immediate click. Social advertisements place investment or shopping lures within normal browsing. Calls allow an operator to adjust the script in real time, answer objections and create urgency. Messaging apps provide space for longer conversations and repeated contact.
The report also shows that scam categories vary between countries. Phishing leads across the markets analysed, but delivery scams, romance scams, crypto fraud and other categories fluctuate by region. Scammers retain a broadly consistent operational model while adapting the narrative to local habits, institutions and current events.
Scam Activity Reflects Organised Working Patterns
The data indicates that many scam campaigns are run as structured operations rather than isolated attempts. Bitdefender’s call telemetry shows activity peaking between Tuesday and Thursday, with declines of 70% to 80% on Sundays. It also records patterns around holidays that resemble the schedules of legitimate organisations.
Voice operations can combine robocalls, spoofed local numbers and human operators. Automated systems generate or qualify leads before engaged targets are transferred to operators trained to obtain credentials, remote access or payments.
Advertising campaigns similarly use coordinated accounts, localisation, technical evasion and rapid testing across devices. Scammers also adapt quickly to news, entertainment releases, major events and seasonal shopping periods, inserting fraudulent offers into topics already attracting attention.
This industrial structure helps explain the scale and persistence of scam activity. Operators can refine scripts, reuse infrastructure and shift resources towards the channels and themes that generate the strongest response.
Prevention Must Follow the Full Scam Journey
The findings demonstrate why channel-specific warnings are no longer sufficient. People still need to recognise suspicious emails, but they also need to question promoted posts, unexpected business messages, caller ID and payment requests that appear to follow a legitimate interaction.
For organisations, prevention requires visibility across the full path from initial exposure to financial loss. Platforms, telecommunications providers, financial institutions, cybersecurity companies and public authorities each observe different parts of that path. Faster intelligence sharing can help connect an advertisement, domain, phone number, messaging account and beneficiary account before the same campaign reaches more people.
Controls should also account for the transfer of trust between channels. Removing a fraudulent website may have limited effect if the associated advertisements, messaging accounts and phone numbers remain active. Coordinated disruption is more likely to constrain an operation than action against a single asset.
The report’s figures reflect Bitdefender’s own products, services and analytical models rather than a complete measure of global scam activity. Even with that limitation, the patterns are consistent: scams are being delivered through interconnected systems, using familiar trust signals and organised infrastructure. Effective prevention increasingly depends on recognising and disrupting the campaign as a whole.
Latest blogs & research
Nearly three in four Danish adults encountered scams as estimated losses reach DKK 10.1 billion
New State of Scams Denmark 2026 report finds scam exposure is rising, while victims face repeated financial and emotional harm.
Building a More Trusted Digital Philippines: New Report Underscores the Need for Collective Action as Scam Exposure Continues to Rise
GASA’s State of Scams in the Philippines 2026 Report, in collaboration with Mastercard and Gogolook, highlights the growing scale of the scam challenge in the Philippines.
Global Anti-Scam Summit America 2026: Highlights, Insights and Resources
Explore GASS America 2026 highlights and insights, with the Summit summary, photos, presentation slides, transcripts and session recordings from San Francisco.
State of Scams in Kenya 2026: A Comparative Review Across Africa
Kenyan experts examine scam trends, data sharing, digital trust and the need for stronger cross-sector prevention.
State of Scams in South Africa 2026: A Comparative Review Across Africa
South African experts examine scam trends, AI, consumer protection and the need for stronger cross-sector collaboration.
More than one in five adults in Japan encountered scams in the past year
New State of Scams Japan 2026 report examines how scams are reaching consumers and where stronger prevention and collaboration can make a difference
GASA Brings Stakeholders Together in Brussels for First Europe Chapter Meeting
GASA Europe brings 50+ stakeholders together in Brussels to discuss scam trends, data sharing and cross-sector priorities.
Research Working Group Meeting: Fraudulent Tickets and Robocall Scam Tactics
Research presented to GASA examines consumers’ ability to spot fraudulent tickets and tactics found across 4.49 million scam and spam robocalls.