The finding comes from a Kaspersky study, which also examines how AI is making scams more convincing and eroding trust in everyday digital communications.
Most read
Messaging scams are no longer isolated incidents, but an increasingly widespread threat, as perpetrators use artificial intelligence (AI) to impersonate well-known companies, craft convincing messages and place victims under greater emotional pressure.
Kaspersky examines this evolving threat in its new report, “The Great Messaging Heist”, which draws on a Censuswide survey conducted in April among 2,806 messaging-scam victims across eight European countries, the United States, Morocco, Senegal and Côte d’Ivoire.
The study finds that fake delivery notifications are the most common type of messaging scam across the countries surveyed, accounting for 38% of cases, closely followed by investment fraud at 37%. Brand impersonation ranks third, at 31%.
AI enables cybercriminals to refine their attacks and has become an important tool in crafting these scams. According to the report, two-thirds of victims (66%) believe the technology played a role in the fraud they experienced, whether through AI-generated messages (43%), synthetic voices (31%) or deepfake images and videos (25%).
“AI has accelerated brand impersonation scams to the point where trust in everyday messages is slowly eroding,“ warns Maria Isabel Manjarrez, Senior Security Researcher at Kaspersky’s Global Research & Analysis Team (GReAT).
The report’s findings illustrate the extent of that loss of confidence. Virtually all victims surveyed (99%) say that, after falling victim to a scam, they no longer trust notifications received through messaging channels. The fallout also affects companies, whose legitimate communications now share the same space as fraudulent messages that reproduce their identity, language and familiar formats.
Repeated scams compound the problem. More than a quarter of respondents (28%) say they have been scammed on three or more occasions. According to the study, this recurrence perpetuates a cycle in which distrust continues to grow while exposure and risk remain high.
“Businesses need to move beyond reacting to individual incidents and focus on prevention through stronger detection capabilities, clearer communication practices and continuous customer education,” Manjarrez says.
Across the countries surveyed, WhatsApp was the leading entry point, accounting for 43% of messaging scams, followed by SMS/iMessage (40%) and Facebook (27%). Nearly two-thirds of cases (63%) also unfolded across several platforms. This multi-platform approach can make the deception appear more credible and harder to detect.
Another defining feature is the speed at which these scams unfold. More than half of successful cases (52%) were completed within 30 minutes of first contact, by which point money or personal information had changed hands. In 14% of cases, the entire process took less than five minutes.
Across the full sample, 51% of victims lost money and 43% handed over personal information, primarily phone numbers, names and email addresses. The average financial loss was $733, although the impact extended well beyond the loss of money or data.
Immediately after the scam, more than half of victims (54%) said they felt angry, while 42% felt frustrated and 38% upset.
Those emotions can take time to fade. An average of six months later, 48% of victims said they still felt angry, while around a third remained frustrated (33%) or upset (30%).
Kaspersky’s report concludes with recommendations for both individuals and businesses aimed at reducing the risk and limiting the reach of these scams. It advises users to pause before acting on any urgent request and verify the sender’s identity through a separate channel rather than clicking links in the message. If a communication appears to come from a relative, colleague or trusted company, checking it through another route can help expose the deception before any data or money is handed over.
For businesses, Kaspersky recommends making clear what information they will never request through messaging platforms, directing customers to verified channels, running awareness campaigns and strengthening the detection and removal of content that impersonates their brand.
Messaging scams are no longer isolated incidents, but an increasingly widespread threat, as perpetrators use artificial intelligence (AI) to impersonate well-known companies, craft convincing messages and place victims under greater emotional pressure.
Kaspersky examines this evolving threat in its new report, “The Great Messaging Heist”, which draws on a Censuswide survey conducted in April among 2,806 messaging-scam victims across eight European countries, the United States, Morocco, Senegal and Côte d’Ivoire.
The study finds that fake delivery notifications are the most common type of messaging scam across the countries surveyed, accounting for 38% of cases, closely followed by investment fraud at 37%. Brand impersonation ranks third, at 31%.
AI enables cybercriminals to refine their attacks and has become an important tool in crafting these scams. According to the report, two-thirds of victims (66%) believe the technology played a role in the fraud they experienced, whether through AI-generated messages (43%), synthetic voices (31%) or deepfake images and videos (25%).
“AI has accelerated brand impersonation scams to the point where trust in everyday messages is slowly eroding,“ warns Maria Isabel Manjarrez, Senior Security Researcher at Kaspersky’s Global Research & Analysis Team (GReAT).
The report’s findings illustrate the extent of that loss of confidence. Virtually all victims surveyed (99%) say that, after falling victim to a scam, they no longer trust notifications received through messaging channels. The fallout also affects companies, whose legitimate communications now share the same space as fraudulent messages that reproduce their identity, language and familiar formats.
Repeated scams compound the problem. More than a quarter of respondents (28%) say they have been scammed on three or more occasions. According to the study, this recurrence perpetuates a cycle in which distrust continues to grow while exposure and risk remain high.
“Businesses need to move beyond reacting to individual incidents and focus on prevention through stronger detection capabilities, clearer communication practices and continuous customer education,” Manjarrez says.
Across the countries surveyed, WhatsApp was the leading entry point, accounting for 43% of messaging scams, followed by SMS/iMessage (40%) and Facebook (27%). Nearly two-thirds of cases (63%) also unfolded across several platforms. This multi-platform approach can make the deception appear more credible and harder to detect.
Another defining feature is the speed at which these scams unfold. More than half of successful cases (52%) were completed within 30 minutes of first contact, by which point money or personal information had changed hands. In 14% of cases, the entire process took less than five minutes.
Across the full sample, 51% of victims lost money and 43% handed over personal information, primarily phone numbers, names and email addresses. The average financial loss was $733, although the impact extended well beyond the loss of money or data.
Immediately after the scam, more than half of victims (54%) said they felt angry, while 42% felt frustrated and 38% upset.
Those emotions can take time to fade. An average of six months later, 48% of victims said they still felt angry, while around a third remained frustrated (33%) or upset (30%).
Kaspersky’s report concludes with recommendations for both individuals and businesses aimed at reducing the risk and limiting the reach of these scams. It advises users to pause before acting on any urgent request and verify the sender’s identity through a separate channel rather than clicking links in the message. If a communication appears to come from a relative, colleague or trusted company, checking it through another route can help expose the deception before any data or money is handed over.
For businesses, Kaspersky recommends making clear what information they will never request through messaging platforms, directing customers to verified channels, running awareness campaigns and strengthening the detection and removal of content that impersonates their brand.
Become a premium member for free!
Categories
About us
Legal
Suscríbete a la información sanitaria de calidad, totalmente gratis
If you don’t have an account Register
Free access to restricted content. Receive our newsletter.
Already have an account? Login
Enter the email address you use to access the site and we will send you a new access password.
