HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium ThreatIntel

Scammers Tailor Tactics to Platform: Email, SMS, Social Media, and Phone Drive Targeted Social‑Engineering Campaigns

Malwarebytes’ 2026 research reveals scammers now match scam types to the delivery channel—toll‑scams via email/SMS, romance scams via social media, IRS scams via phone—while the web remains the top vector. This underscores the need for continuous security‑awareness programs that generate audit‑ready evidence.

Verisq™ Intelligence · 📅 September 03, 2026 · 📰 malwarebytes.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Scammers Tailor Tactics to Platform: Email, SMS, Social Media, and Phone — Rise of Targeted Social‑Engineering Campaigns

What Happened – Malwarebytes’ threat research (April 15 – July 14 2026) shows scammers are now matching each scam type to the channel where it is most effective. Toll‑scam messages arrive 90 % via email or SMS, romance scams 60 % via social media, and IRS‑related scams 50 % by phone. The web remains the top delivery vector, with ~500 k phishing sites blocked daily.

Why It Matters for Trust & Control Assurance

  • The pattern illustrates a classic people‑risk scenario that a continuous security‑awareness program is built to detect, train against, and document.
  • Evidence of regular phishing‑simulation results, training completion, and policy acknowledgment provides the audit‑ready proof points demanded by control‑assurance frameworks.
  • Verisq’s Security Awareness capability helps you capture, monitor, and report that evidence in a single, defensible view.

Who Is Affected – Consumers and employees across all sectors; the data is especially relevant to organizations that handle customer‑facing communications (financial services, e‑commerce, telecom, etc.).

Recommended Actions

  1. Map the “Security Awareness and Training” control objective to your framework of record (e.g., NIST CSF 2.0 Identify → Protect).
  2. Deploy continuous phishing‑simulation and social‑engineering testing; collect completion and result logs as evidence.
  3. Review channel‑specific policies (email, SMS, social media) and ensure they are reinforced in training curricula.

Source: Malwarebytes Labs – Scammers are getting smarter about where they target you

Technical Notes – The research aggregates over 20 scam categories, highlighting platform preference (web > email > SMS) and a “golden hour” (12 pm ET) for U.S. targets. No specific CVEs or malware families are involved; the threat vector is social‑engineering (phishing, impersonation, vishing).

📰 Original Source
https://www.malwarebytes.com/blog/scams/2026/09/scammers-are-getting-smarter-about-where-they-target-you

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →