Malwarebytes telemetry collected from April 15 to July 14 found that fraudsters increasingly match scam types to the channels most likely to produce victims. The web remained the largest overall delivery route, followed by email and SMS; job scams favored email, romance scams social media, tech-support and IRS lures phone calls, and toll scams email or text messages. U.S.-targeted scam texts peaked around noon Eastern Time and on Fridays, indicating deliberately timed campaigns rather than random delivery.
Impersonation operations commonly exploited MrBeast, Elon Musk, Donald Trump, and brands including Google, Microsoft, Apple, Amazon, Roblox, and Steam. Gaming-platform impersonation increased from mid-June to mid-July, and Malwarebytes assessed roughly half of gaming scams as carrying a potential victim loss of at least $1,000. Organizations should reinforce channel-specific phishing awareness, particularly for SMS and social-media lures, and alert users to unsolicited messages invoking prominent brands or personalities.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes' analyzed scam-telemetry collection period ended on July 14, 2026. Its findings included scam-text peaks at noon Eastern Time and on Fridays, plus widespread impersonation of MrBeast and major technology and retail brands.
During the mid-June to mid-July 2026 period, Roblox-related scam activity increased 15% and Steam-related activity increased 19%. Malwarebytes identified Roblox, Steam, Discord, and Minecraft as the most impersonated gaming services.
Malwarebytes collected anonymized global scam telemetry covering more than 20 scam categories from April 15 through July 14, 2026. The data showed the web as the leading overall scam-delivery channel, with scam types tailored to channels such as email, social media, and phone calls.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.