Bitdefender Report Reveals How Scams Operate Across Digital Channels

Inside Bitdefender’s 2026 Global Scam Findings

Scams increasingly operate as coordinated campaigns that follow people across the digital services they use each day. A deceptive advertisement may lead to a fraudulent website before the interaction continues through a messaging app, phone call or payment request. This movement between channels makes scams harder to identify and exposes the limitations of controls designed around a single point of contact.

The Bitdefender Global Scam Intelligence Report 2026, based on the company’s telemetry and analysis from 1 January to 31 December 2025, documents this shift across web traffic, SMS, social media advertising, WhatsApp and voice calls. Its findings suggest that scam operations are becoming more organised, more adaptive and better able to exploit the trust people place in familiar platforms, brands and communication methods.

Scam Delivery Is Becoming Omnichannel

Web links remain a central part of scam infrastructure. Bitdefender scanned 2.8 trillion URLs during 2025 and found phishing to be the largest scam category, accounting for 24.5% of incidents in its dataset. Financial and investment scams accounted for 10.7%, followed by fake shops and advertising scams at 9.3% and job scams at 8.7%.

However, these categories should not be understood as separate threats confined to individual channels. The same financial scam can be promoted through a paid social media advertisement, continued through a messaging app and reinforced by a call from someone impersonating a financial institution. The lure changes to fit the platform while the underlying objective remains the same.

This model gives scammers several opportunities to establish credibility. Each interaction can make the next one appear more legitimate, particularly when the victim encounters consistent branding, account names and explanations across different services.

Paid Advertising Places Scams Within Everyday Content

The report identifies malicious advertising as a major scam delivery mechanism. Rather than arriving as an unsolicited email, scam advertisements appear alongside legitimate posts, videos and search results. Sponsored placement can give fraudulent content an appearance of legitimacy, even though a paid or promoted label is not a guarantee of safety.

Bitdefender estimates that scam advertisements reached 60 million people across social media and video platforms during the period analysed. The company recorded exposure among 18.2 million people in the United States, 11.1 million in Germany and 8.5 million in the United Kingdom. In Romania, more than 40% of the population was exposed to at least one scam advertisement, according to the report’s telemetry.

Some campaigns display the characteristics of coordinated commercial operations. In one case documented by Bitdefender, a single page launched more than 100 malicious advertisements on Meta platforms within 24 hours. Coordinated accounts promoted pages impersonating cryptocurrency and trading services, with advertisements localised for audiences across several regions.

The campaign later expanded from desktop devices to Android, showing how scam infrastructure can be adapted as opportunities change. Bitdefender also observed campaigns using technical measures to identify security analysis and display legitimate content instead of a malicious payload when scrutiny was detected.

These tactics were examined during Trusted Channels, Hidden Threats, a Bitdefender-hosted workshop at the Global Anti-Scam Summit Europe 2026. Bitdefender researchers described a malvertising campaign involving more than 60,000 malicious advertisements, over 3,000 domains and subdomains and thousands of coordinated social media accounts. The campaign operated across Meta, Google and YouTube and targeted Windows, Mac and Android users. Its advertisements impersonated trusted brands, news organisations and public figures while adapting their content around major entertainment, sporting and cultural events.

Familiar Trust Signals Are Being Repurposed

Across channels, scammers use features that normally help people judge whether an interaction is credible. These include caller ID, business account labels, verification marks, sponsored placements, familiar branding and messages received from known contacts.

Bitdefender found that 61% of the risky WhatsApp conversations it analysed originated from business accounts. More than 310,000 risky conversations were detected in India alone.

Business profiles can display a company name, logo and description while also supporting automated replies and other tools that allow operators to manage conversations at scale. These features are useful for legitimate organisations but can also help scam operations present themselves as established businesses and manage large numbers of prospective victims.

Account takeover adds another layer of credibility. The report describes a voting scam in which recipients are directed to a professional-looking website and asked to enter a phone number and verification code. The code is actually used to take over the victim’s WhatsApp account. The compromised account can then be used to approach the victim’s contacts, allowing the scam to spread through an existing relationship rather than an unknown sender.

Other campaigns turn recipients into distributors without taking over their accounts. Fake promotions may require a message to be forwarded to multiple contacts before a supposed reward can be claimed. In both cases, the scam uses social proximity to overcome the caution people may apply to unsolicited contact.

Looking to contribute to collaborative anti-scam initiatives? GASA Working Groups bring members together to develop practical, real-world solutions.

Financial Scams Adapt to Each Communication Channel

Financially motivated scams remain prominent throughout the report. Finance accounted for 36% of the risky SMS campaign categories identified by Bitdefender. Across all SMS traffic analysed, 5.16% was associated with risky campaigns, equivalent to approximately one in 20 messages.

Voice calls show a similar concentration. Bitdefender analysed nearly 150 million incoming calls during 2025 and classified 23.5 million as unwanted. This represents more than 15% of calls reaching protected devices, or approximately one in six.

Financial institution impersonation accounted for around one quarter of the scam calls classified by theme, while investment scams made up a further 8%. In Bitdefender’s US honeypot data, malicious calls lasting more than 30 seconds continued for an average of three minutes and 36 seconds. Phishing calls were the longest category, with an average duration of eight minutes and eight seconds.

The communication method shapes how pressure is applied. SMS messages often use delivery, government or financial impersonation to prompt an immediate click. Social advertisements place investment or shopping lures within normal browsing. Calls allow an operator to adjust the script in real time, answer objections and create urgency. Messaging apps provide space for longer conversations and repeated contact.

The report also shows that scam categories vary between countries. Phishing leads across the markets analysed, but delivery scams, romance scams, crypto fraud and other categories fluctuate by region. Scammers retain a broadly consistent operational model while adapting the narrative to local habits, institutions and current events.

Scam Activity Reflects Organised Working Patterns

The data indicates that many scam campaigns are run as structured operations rather than isolated attempts. Bitdefender’s call telemetry shows activity peaking between Tuesday and Thursday, with declines of 70% to 80% on Sundays. It also records patterns around holidays that resemble the schedules of legitimate organisations.

Voice operations can combine robocalls, spoofed local numbers and human operators. Automated systems generate or qualify leads before engaged targets are transferred to operators trained to obtain credentials, remote access or payments.

Advertising campaigns similarly use coordinated accounts, localisation, technical evasion and rapid testing across devices. Scammers also adapt quickly to news, entertainment releases, major events and seasonal shopping periods, inserting fraudulent offers into topics already attracting attention.

This industrial structure helps explain the scale and persistence of scam activity. Operators can refine scripts, reuse infrastructure and shift resources towards the channels and themes that generate the strongest response.

Prevention Must Follow the Full Scam Journey

The findings demonstrate why channel-specific warnings are no longer sufficient. People still need to recognise suspicious emails, but they also need to question promoted posts, unexpected business messages, caller ID and payment requests that appear to follow a legitimate interaction.

For organisations, prevention requires visibility across the full path from initial exposure to financial loss. Platforms, telecommunications providers, financial institutions, cybersecurity companies and public authorities each observe different parts of that path. Faster intelligence sharing can help connect an advertisement, domain, phone number, messaging account and beneficiary account before the same campaign reaches more people.

Controls should also account for the transfer of trust between channels. Removing a fraudulent website may have limited effect if the associated advertisements, messaging accounts and phone numbers remain active. Coordinated disruption is more likely to constrain an operation than action against a single asset.

The report’s figures reflect Bitdefender’s own products, services and analytical models rather than a complete measure of global scam activity. Even with that limitation, the patterns are consistent: scams are being delivered through interconnected systems, using familiar trust signals and organised infrastructure. Effective prevention increasingly depends on recognising and disrupting the campaign as a whole.

Sign up for the GASA newsletter to receive regular updates on scam prevention, research, and best practices.

Jul 21, 2026
10 minute read
Category
Research Region - Europe Topic - Fraud Prevention Region - Global Scam Trends Presentations Topic - Fraud Research Topic - Scam Detection Industry - Big Tech / Social Media Event - GASS Europe 2026
Written by
Global Anti-Scam Alliance (GASA)
Global Anti-Scam Alliance (GASA)
Share article

Latest blogs & research

Bitdefender Report Reveals How Scams Operate Across Digital Channels

Bitdefender’s Global Scam Intelligence Report 2026 shows how organised scam campaigns move across advertising, websites, SMS, messaging apps and voice calls to exploit trust at scale.

Research Region - Europe Topic - Fraud Prevention Region - Global
What the NDPC-Meta Initiative Means for Data Protection in Nigeria

Beyond Compliance: Why Organisational Accountability is Critical for Consumer Protection

How the NDPC-Meta initiative could strengthen data protection, organisational accountability, scam prevention and consumer trust across Nigeria’s digital economy.

Industry - National Cyber Security Centers (NCSCs) Topic - Fraud Policy Region - Africa Industry - Policy Makers

Why Mexico’s Anti-Scam Response Needs Cross-Sector Coordination

GASA Mexico Chapter's Sissi De la Pena explains why scam prevention in Mexico requires stronger coordination across finance, telecoms, platforms, government and civil society.

Best Practices Topic - Fraud Prevention Topic - Fraud Policy Industry - Financial Authorities

GASA Mexico Shares Scam Prevention Tips During the 2026 FIFA World Cup

GASA Mexico shares practical advice for football fans on avoiding ticketing, travel, phishing and payment scams during the 2026 FIFA World Cup.

Best Practices Video Region - Latin America Industry - Consumer Protection & Authorities

Watch the Global Anti-Scam Summit Europe 2026 Session Recordings

Watch keynotes, panels, workshops, working group sessions and Scam Fighter Awards recordings from the Global Anti-Scam Summit Europe 2026 in Lisbon.

Best Practices Region - Europe Topic - Fraud Prevention Topic - Data Sharing

Public-Private Partnerships in Action: Key Takeaways From the Global Anti-Scam Summit Europe 2026

Key takeaways from the Global Anti-Scam Summit Europe 2026 on how public-private partnerships can strengthen scam prevention, intelligence sharing, regulation and victim protection.

Best Practices Region - Europe Region - Global Video
nomorobo joins scam.org

Nomorobo Joins Scam.org to Shield Consumers from Fraudulent Calls and Texts

Nomorobo has joined Scam.org as a member partner, bringing call and text blocking technology into the platform to help consumers protect themselves from fraudulent communications.

News Topic - Scam Awareness Region - Global Region - North America

Scams Continue to Rise in Germany: Two in Three Adults Encountered a Scam in the Past Year

The Global Anti-Scam Alliance (GASA), in collaboration with Worldline, has released the State of Scams Germany 2026 Report.

Report Topic - Scam Reporting Scam Trends Topic - Fraud Research