Home › Fraud News › Scam trends in 2026: what has actually changed
ANALYSIS · CYBER FRAUD NEWS

Scam trends in 2026: what has actually changed

Cheap fluent text, copied voices, and organised operations have changed how fraud arrives. The structure underneath has not.

Last reviewed 13/09/2026 · Written and maintained by the cyberhygiene.tools team

In this article

  • The three shifts that matter
  • Where the money is actually going
  • Techniques worth understanding this year
  • What has not changed
  • What to do about it

The three shifts that matter

Cyber fraud does not change as quickly as headlines suggest. The underlying goals have been the same for twenty years: get a password, get a payment, or get a person to act against their own interest. What changes is cost and scale, and over the past two years three shifts have altered both.

Writing became free. Generative tools produce fluent, personalised, idiomatic text in dozens of languages at effectively no cost. The practical consequence is that the standard advice — look for bad spelling and awkward grammar — has stopped working. A fraudulent message can now read better than a genuine one from your bank.

Voice became cheap to copy. Cloning a recognisable voice needs a short sample of ordinary speech, easily taken from a social media video or a voicemail greeting. The assumption underneath decades of everyday trust, that recognising a voice confirms identity, no longer holds.

Fraud became industrial. Much of what reaches you is produced by organised operations with scripts, shift patterns, training material and quality control. Some are run from compounds where the operators are themselves trafficked. This matters for how we talk about victims: being deceived by a professional operation working from a tested script is not a failure of intelligence.

Where the money is actually going

Losses cluster in a small number of categories, and they are not the ones people expect.

Payment redirection remains the largest single cause of business loss. Someone reads a real email thread — often from a supplier's compromised mailbox rather than yours — and sends a message changing the bank details on a genuine invoice. There is no malware, no suspicious link and no spelling error, because nothing about it is fake except the account number.

Investment fraud, usually introduced through a relationship built over weeks, produces the largest individual losses. The platform displays convincing growing returns. Withdrawals are blocked by fees and taxes that never end.

Impersonation of banks and authorities continues to work because caller ID is trivial to falsify and because the scripts are refined constantly. The request is always one of a small set: move money to a "safe account", read out a code, or install software.

Marketplace and delivery scams are individually small and enormous in aggregate, and they are the category most likely to be someone's first experience of fraud.

Techniques worth understanding this year

Attacks that use your own computer's tools

The approach commonly called ClickFix shows a fake error or verification failure, then walks the visitor through pasting a command into a system tool. Because the victim runs it themselves using software already on the machine, there is no suspicious download for a filter to inspect. Our explainer covers the detail; the one-line defence is that no legitimate website ever asks you to paste a command into a terminal or Run box.

QR codes as a delivery method

A QR code is a link you cannot read, which removes the single most useful defence people have. Stickers placed over genuine codes on parking meters and payment machines have become common enough that councils in several countries have issued warnings.

Session theft rather than password theft

Information-stealing malware increasingly targets session cookies rather than passwords, because a stolen session token can bypass both the password and the two-factor prompt. This is why signing out of all sessions matters after any compromise, and why passkeys — which are bound to the real site's address — are the strongest defence available.

Recovery fraud

Victim lists are traded, and a second approach offering to recover lost funds for an upfront fee is now routine. It is frequently the same network returning for whatever is left.

What has not changed

Every one of these still requires the target to do something: send money, hand over a code, install something, or approve a prompt. The polish sits on the surface. The structure underneath is unchanged, and so are the defences that address structure rather than appearance.

What to do about it

The practical response to all of the above is unglamorous and short. Turn on two-factor authentication for your email first, because it resets everything else. Use a password manager so a breach at one site stays at one site. Agree a family check word so an urgent call can be verified without relying on recognising a voice. Let your devices update automatically.

None of that responds to a specific trend, which is precisely the point. Defences tied to a technique expire when the technique does. Defences tied to structure keep working.


Frequently asked questions

Has AI made scams fundamentally different?

No. It has made them cheaper, more fluent and more personalised, at far greater scale. The goals and the structure are unchanged, which is why verification-based defences still work while spotting-bad-English does not.

What causes the largest losses?

For businesses, payment redirection on genuine invoices. For individuals, investment fraud introduced through a relationship built over weeks. Both are patient, low-technology attacks rather than dramatic hacks.

Why do stolen session cookies matter?

A session cookie keeps you logged in, so an attacker holding one can enter an account without the password or the two-factor code. Signing out of all sessions after a compromise is what invalidates them.

What is recovery fraud?

A second approach to someone who has already lost money, offering to retrieve it for an upfront fee. It is often the same network working from a traded victim list. No legitimate service charges in advance to recover scammed funds.

What single change helps most against current trends?

Two-factor authentication on your email account. It is the reset mechanism for nearly everything else you own, so protecting it protects everything downstream.