APWG Report: Social Media Phishing is Surging

KnowBe4 Team | Jun 22, 2026

Phishing scams surged across social media platforms during the first quarter of 2026, according to a new report from the Anti-Phishing Working Group (APWG).

“Threat volume increased in Q1 2026 on every social media platform, predominantly in two formats: Scams (27.1 percent of all threats) and Impersonation (43.8 percent of all threats),” the report says. The APWG adds, “Impersonation became more prevalent than in the previous quarter. Impersonation is frequently the opening move in a scam campaign, with threat actors establishing a fake identity before advancing to financial fraud. Seen through that lens, the two categories remain deeply intertwined, and their combined 70.9 percent share still represents the core of the threat landscape.”

Attackers are also using more advanced evasion techniques to hide their websites from security scanners, giving their schemes a longer lifespan.

“Fraudsters appear to be using more intricate and elaborate methods to hide their scam and phishing sites,” the APWG says. “Phishers are still employing well-known techniques such as geo/IP blocking and user-agent blocking. But an increasing number of sites only show fraudulent content when the referrer is a certain site or kind of site. For example, the fraud site is only displayed if the user came from the Bing search engine and had searched for "[bank name]bank login", or visited from a certain social media site (i.e. a user clicked on a comment in a Tiktok video). Otherwise, the visitors will see innocuous-looking content, or may be redirected to another site.”

New-school security awareness training can give your organization an essential layer of defense against phishing and other social engineering attacks. KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

The APWG has the story: https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/apwg-q1-2026-report-phishing-and-scams-rising-on-all-social-media-1170893

Secure Your Human and AI Workforce

Transform your attack surface into your strongest defense with our AI-driven platform. Request a personalized demo to see how to mitigate social engineering, manage agent risk, and automate your phishing response.

Get a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.