Fixing digital fraud feels a lot like making socks that never get unpaired and lost in the laundry. Maybe there just isn’t a fix?
We added email filters, banners, AI, DMARC, BIMI and enough inbox “don’t trust” warning labels to wrap a Boeing 737. Scammers scoff at our efforts.
According to Bitdefender’s Global Scam Intelligence Report 2026 (PDF), fraud is booming, and so are the techniques used to scam us. The report says modern-day inbox scams have matured. Fraud today operates like a cross-channel customer acquisition campaign, with victims treated like leads in a sales funnel.
“Email remains a foundational tool in the scammer playbook. It simply evolved alongside everything else,” Bitdefender said.
The report identified a trifecta of fraud that now includes online tools such as ads, WhatsApp and voice calls. Together, the three create a single sequential pipeline: a victim enters via an ad, gets nurtured on WhatsApp, then is closed on a call.
Scammers now operate with “staffing schedules, regional targets, marketing budgets, and performance metrics.” That’s the kind of operational discipline that security defenders have long seen with RaaS and APT groups. Scammers are less interested in the spoof-and-run ploys and now focus on the long con.
The report, published Tuesday, is based on Bitdefender telemetry and analysis from 2025, including web threats, SMS campaigns, malicious social media ads, WhatsApp conversations, voice-call activity, honeypots and consumer-facing scam patterns.
Top of the scam funnel: Scam Gen
Today, mainstream advertising ecosystems — specifically Meta, Google, and YouTube — have become the primary front lines for high-yield consumer fraud. Rather than waiting for a user to open a spam email, threat actors are leveraging highly sophisticated paid ad campaigns to deliver malicious content directly into legitimate feeds.
Paid scam ads actively targeted 60 million people globally in 2025, according to the report. The reach and trust gap exploited in these attacks are massive. Over 18 million Americans, 11.1 million Germans, and 8.5 million individuals in the UK were exposed to malicious ads in their feeds.
“Paid advertisements exploit platform trust to bypass standard verifications and slip directly into user feeds where regular users interact with them out of curiosity or by accident,” Bitdefender wrote.
These campaigns succeed because they bypass platform verifications to exploit established trust. Scammers rely heavily on lookalike domains, compromised accounts of friends or family, or high-profile celebrity endorsements (including Elon Musk, Zendaya, and Cristiano Ronaldo) to manufacture authenticity, Bitdefender said.
WhatsApp adds the trust layer
Researchers said criminals are shying away from inboxes and now prefer SMS and messaging apps like WhatsApp that give them social proximity rather than mass “spray-and-pray” email blasts. Peer-to-peer forwarding on social messaging apps allows malicious content to be shared rapidly through high-trust ecosystems.
“The most effective attacks don’t come from strangers,” Bitdefender wrote. “They come from compromised accounts of friends and family, from brands people recognize, from platforms they use daily.”
Scammers actively abuse legitimate business infrastructure (specifically WhatsApp Business accounts, which account for 60% of risky conversations globally) because it allows them to leverage normal commercial trust signals. This includes spoofing techniques such as replacing random numbers with corporate names, product catalogs, and blue verification checkmarks to reduce skepticism.
Scammers run this like a call center. Quick replies, auto-greetings, CRM and chatbot integrations let one crew juggle hundreds of chats at once, with scripts triaging victims at machine speed. Lures like the “Vote for Me” competition or the viral Sephora Advent Calendar scam do the hooking; bots handle the early back-and-forth. Humans only step in to close the high-value targets.
A.B.C.s of a scam: Always be closing
The last stop in the scam funnel is the phone call.
Bitdefender describes voice fraud as systematic, persistent and “heavily domestic in origin.”
Leaked data from robocall leads shows call scripts moving targets through the scam pipeline. Victims who engage are escalated to human “closers” trained to extract credentials, remote access or direct payment.
Modern fraud call centers contradict the offshore boiler-room stereotype. In many cases, the operation looks less like a lone scammer in the shadows and more like a crooked outbound sales floor with desks, headsets, supervisors, KPIs and shift rotations.
Instead of selling insurance, subscriptions or software, the floor is selling the lie, Bitdefender said.
The more complicated the lie, the more time the scammer needs to build a story, lower resistance and extract value.
Trust is the vulnerability
Bitdefender said the big-picture takeaway is that trust is really the biggest exploitable vulnerability.
The report said the most effective scams do not always come from obvious strangers. They come from familiar brands, compromised accounts, platform-native ads, business profiles, caller ID and channels people already use every day.
That requires defenders to rethink the mantra “Don’t click suspicious email links.” In a threat environment where a sponsored post may contain malicious links, a WhatsApp message from your neighbor might not be what it appears, and a phone call from someone who sounds like customer support requires new scrutiny – the advice of “don’t click” is no longer sufficient.
Scams cannot be treated as isolated abuse on separate channels. The criminal model is connected. Bitdefender argues the defense has to be, too.
Photo by Vitaly Gariev on Unsplash