Report: Scams Are Surging as Attackers Abuse Trusted Workflows

KnowBe4 Team | Aug 14, 2026

Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital.

“[Attackers] are not only sending malicious links or dropping malware,” the report says. “They are abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority. The attack often succeeds before the victim reaches the obvious danger point, because the surrounding situation already feels legitimate, and in many cases, the victim has actually given their attacker approval.”

Scams accounted for nearly half (46%) of Gen’s threat detections in the first half of 2026, with a notable surge in government impersonation scams targeting users in the U.S.

“Within that broader scam landscape, tech support scam detections reached 20.3 million blocked attacks, while e-shop scams reached 114.2 million,” the researchers write. “Imposter scams rose 387%, with government impersonation driving most of that activity. Gen’s Scam Ad Machine research found that scam-related ads made up nearly 1 in 3 ads analyzed from Meta’s EU and UK ad dataset, generating more than 304 million impressions in less than a month. Financial abuse also appeared closer to the point of payment: Gen blocked 996.3K web skimming attacks in H1 2026, up 212% from H2 2025, showing how attackers continued to target checkout flows where users already expect to enter payment details.”

The researchers also observed a significant rise in family impersonation scams, with some of these incidents assisted by AI tools.

“Family impersonation scams…rose sharply, up 454.2% over the second half of 2025,” the report says. “The activity was concentrated in Western Europe, led by the Netherlands, France, Ireland and Germany. These campaigns mostly reached Android users through SMS, and one SMS campaign accounted for 39% of all blocked family scam attacks in the period. Some documented cases used AI voice cloning, but the core technique remains older than AI: urgency, emotional pressure and a message that appears to come from someone the victim already knows. AI can make that cheaper and more convincing. It does not replace the social engineering; it improves the packaging.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce human risk.

Gen Digital has the story

 

Secure Your Human and AI Workforce

Transform your attack surface into your strongest defense with our AI-driven platform. Request a personalized demo to see how to mitigate social engineering, manage agent risk, and automate your phishing response.

Get a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.