Scammers Tailor Tactics to Platform: Email, SMS, Social Media, and Phone — Rise of Targeted Social‑Engineering Campaigns
What Happened – Malwarebytes’ threat research (April 15 – July 14 2026) shows scammers are now matching each scam type to the channel where it is most effective. Toll‑scam messages arrive 90 % via email or SMS, romance scams 60 % via social media, and IRS‑related scams 50 % by phone. The web remains the top delivery vector, with ~500 k phishing sites blocked daily.
Why It Matters for Trust & Control Assurance
- The pattern illustrates a classic people‑risk scenario that a continuous security‑awareness program is built to detect, train against, and document.
- Evidence of regular phishing‑simulation results, training completion, and policy acknowledgment provides the audit‑ready proof points demanded by control‑assurance frameworks.
- Verisq’s Security Awareness capability helps you capture, monitor, and report that evidence in a single, defensible view.
Who Is Affected – Consumers and employees across all sectors; the data is especially relevant to organizations that handle customer‑facing communications (financial services, e‑commerce, telecom, etc.).
Recommended Actions
- Map the “Security Awareness and Training” control objective to your framework of record (e.g., NIST CSF 2.0 Identify → Protect).
- Deploy continuous phishing‑simulation and social‑engineering testing; collect completion and result logs as evidence.
- Review channel‑specific policies (email, SMS, social media) and ensure they are reinforced in training curricula.
Source: Malwarebytes Labs – Scammers are getting smarter about where they target you
Technical Notes – The research aggregates over 20 scam categories, highlighting platform preference (web > email > SMS) and a “golden hour” (12 pm ET) for U.S. targets. No specific CVEs or malware families are involved; the threat vector is social‑engineering (phishing, impersonation, vishing).