Scam Texts Surge at Noon on Fridays, Study Shows Targeted Timing Across Platforms
What Happened — Malwarebytes analyzed threat data from April 15 to July 14 2026 and found that scam text messages peak at 12:00 pm ET, a volume 874 % higher than the quietest hour (1:00 am ET). The volume climbs through the week, reaching its highest level on Friday, about 50 % more than the start‑of‑week baseline. Impersonated public figures and major brands drive a large share of these campaigns.
Why It Matters for Trust & Control Assurance
- The pattern shows threat actors deliberately align campaigns with user behavior, testing the effectiveness of security‑awareness controls that rely on users recognizing phishing attempts.
- Continuous monitoring of inbound SMS/email and documented training completion provide a defensible audit trail for control‑assurance programs.
- Mapping this behavior to the control objective of security awareness and training helps satisfy multiple frameworks (e.g., NIST CSF 2.0 Identify / Protect functions).
Who Is Affected — Consumers and employees across all sectors; especially relevant for organizations with large mobile workforces and customer‑facing messaging services.
Recommended Actions
- Review and update security‑awareness curricula to include midday‑and‑Friday phishing simulations.
- Deploy automated monitoring of inbound SMS/email for known scam signatures and log incidents for audit evidence.
- Validate that incident‑response playbooks capture social‑engineering attempts originating from mobile channels. Source: https://www.helpnetsecurity.com/2026/09/04/scam-texts-peak-research/
Technical Notes — The study aggregates over 20 scam categories (tech‑support, sextortion, impersonation) and identifies the web as the top delivery method, followed by email and SMS. No specific CVEs or software flaws are involved; the vector is social engineering via phishing‑style messages. Source: https://www.helpnetsecurity.com/2026/09/04/scam-texts-peak-research/