The most dangerous scam is no longer the one that looks fake.

It is the one that contains enough truth to feel routine.

A message refers to your real hotel reservation. A WhatsApp request comes from a known contact. Software is downloaded from an official website. An artificial intelligence agent acts using permissions you knowingly granted.

The context is legitimate.

The request is not.

That distinction sits at the centre of Gen Digital’s Threat Report H1 2026. Its most important finding is not that attackers have invented a revolutionary technique. It is that they are moving closer to the systems, relationships and workflows people already trust.

The 46 per cent figure needs context

Gen says scams made up almost 46 per cent of threat detections across its ecosystem during the first half of 2026.

That does not mean scams represented 46 per cent of all malware or cybercrime worldwide.

Gen Digital owns brands including Norton, Avast, LifeLock and MoneyLion. The company says its products and services reach nearly 500 million users in more than 150 countries.

That gives Gen significant visibility into consumer threats. Its findings are still vendor telemetry, shaped by its customers, products, detection methods and geographic coverage.

The direction of travel is nevertheless difficult to dismiss.

Gen reported blocking 114.2 million fake online-store attacks, an increase of 109 per cent from the previous six-month period. Technology-support scam detections reached 20.3 million, although Gen acknowledges that expanded detection coverage contributed to the increase. Malicious advertising accounted for almost 30 per cent of detections.

The individual percentages matter less than the pattern.

Fraud is becoming embedded in ordinary digital activity.

Attackers are borrowing legitimate context

Gen’s reservation-hijacking research shows how effective this can be.

Rather than sending a generic travel message, attackers use genuine booking information to contact real travellers about real reservations. Gen connected the activity to more than 350 compromised accommodations.

The attacker does not need to invent the trip.

The trip is real. Only the request for payment or verification is fraudulent.

The same principle appears in Gen’s GhostPairing research.

Victims were tricked into completing WhatsApp’s legitimate device-pairing process, adding the attacker’s browser as a linked device. No password theft or SIM swap was required.

The victim authorized the access.

Trust can also be inherited from software distribution. On May 6, attackers compromised the official JDownloader website and replaced selected download links with malicious installers. The clean files were restored, but the incident demonstrated how quickly an established distribution channel can become hostile.

In each case, the attacker benefits from an existing trust decision:

  • I recognize this reservation.
  • I know this contact.
  • I approved this device.
  • I trust this website.
  • I trust this software.

The attack succeeds before anything looks obviously malicious.

Artificial intelligence turns trust into action

Artificial intelligence agents raise the stakes because they do more than interpret information.

They can read files, access email, install software, call application programming interfaces and execute commands.

Unit 42 has documented indirect prompt injection being used in the wild. Attackers placed instructions in web content designed to manipulate artificial intelligence systems that later processed it.

The fundamental risk is not simply that a model may produce an incorrect answer.

It is that the model may hold real authority when it does.

An agent with access to files, email, credentials or administrative tools is not merely a productivity application. It is a privileged identity capable of acting at machine speed.

It must be governed accordingly.

What organizations should change

The Canadian Centre for Cyber Security has warned that criminals are increasingly using voice phishing, brand impersonation, credential harvesting and help-desk manipulation to compromise cloud services.

These attacks may involve no malware, reducing the effectiveness of conventional endpoint detection.

Security controls must move closer to the point where trust becomes authority.

Organizations should:

  • Independently verify requests involving money, credentials, account recovery or sensitive information.
  • Continuously review linked devices, active sessions, delegated access and application authorizations.
  • Protect software publishing tokens, signing keys and update systems as privileged identities.
  • Give artificial intelligence agents unique identities, narrowly scoped permissions and short-lived credentials.
  • Require human approval before an agent performs destructive, irreversible or high-value actions.
  • Record what an agent accessed, decided and executed.

Security awareness must also evolve.

Accurate personal information, a familiar brand or a legitimate platform can no longer be treated as proof of authenticity.

In some cases, accurate information may indicate that another account or system has already been compromised.

The bottom line

Attackers are not merely breaking trust.

They are borrowing it, inheriting it and persuading people and systems to extend it.

The question is no longer only whether a message, website or application appears legitimate.

The more important question is:

What authority am I being asked to grant?

That is the moment security must protect.

Ethics and Transparency Statement

This article was written independently. I received no compensation, products, services or editorial direction from Gen Digital, IT Security Guru or any other organization referenced.

Gen Digital has commercial interests in cybersecurity, identity protection, privacy and artificial intelligence security. Its report combines product telemetry, company research and discussion of its own initiatives. I have therefore treated its statistics as vendor findings rather than universal measures of cybercrime.

Generative artificial intelligence assisted with source discovery, cross-referencing and editorial review. The analysis, conclusions and final editorial decisions are my own. I remain responsible for the published article and will correct any verified error promptly and transparently.

Disclaimer

The views expressed are personal and do not necessarily represent those of my employer, clients, business partners or affiliated organizations.

This article is provided for informational and educational purposes. It is not legal, cybersecurity, privacy, regulatory or other professional advice. Threat activity, technologies and product capabilities may change and may vary by organization, jurisdiction and operating environment.

Organizations should conduct their own risk assessments and consult qualified professionals before making security or technology decisions.

Sources and further reading