Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time — Threadlinqs Intelligence
As of 2026-09-02, Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time is a low-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-2289 · Severity: LOW · Status: ACTIVE · Category: THREAT_INTEL
Malwarebytes threat-research telemetry (April 15-July 14, 2026) shows scam operators deliberately match scam type to delivery channel and timing: toll-fee scams arrive almost entirely by email/SMS,
Malwarebytes' Scam Guard threat-research systems analyzed anonymized global scam telemetry collected April 15 through July 14, 2026, and found that scam operators consistently pair a scam narrative with the delivery channel most likely to make it credible rather than spraying a single lure across every channel. Toll-fee scams (fake unpaid-toll notices threatening late fees or license suspension) arrive by email or SMS in roughly nine out of ten cases; romance scams surface first on social media roughly six times out of ten; IRS/tax-impersonation scams are delivered by phone call about half the time; job/employment scams arrive through ordinary work channels (email); and giveaway scams are more likely to appear in social-media feeds than in email or text. Malwarebytes also blocks approximately 500,000 phishing websites per day, and its Scam Guard tool flags roughly one in five analyzed sessions as high-risk.
The report identifies a sharp temporal pattern in SMS-based scam delivery: the busiest hour for scam texts on the US East Coast is 12:00pm ET, which is 874% busier than the quietest hour (1:00am ET), and scam-text volume climbs steadily across the week to peak on Fridays, roughly 50% higher than the Sunday low. This channel-and-timing discipline mirrors patterns independently documented elsewhere: the FBI IC3 issued a nationwide alert in April 2024 (PSA240412) describing an ongoing unpaid-toll smishing campaign that directs victims to lookalike toll-payment domains (e.g., myturnpiketollservices[.]com-style URLs) to harvest payment and personal information, and the IRS's 2026 'Dirty Dozen' scam list (IR-2026-30, March 2026) separately warns that IRS-impersonation phone scams increasingly use AI-generated voice synthesis and spoofed caller ID to sound authoritative.
On impersonation, the report finds MrBeast is the most-impersonated public figure, used in roughly 30% of impersonation-based scams-well ahead of Elon Musk and Donald Trump, who round out the top three-typically via crypto-giveaway lures and 'transfer fee' swindles that demand an upfront payment to 'unlock' a prize that never materializes. This matches independently reported MrBeast-impersonation campaigns that use AI deepfake video and compromised Discord accounts (Bitdefender documented a stolen-Discord-account MrBeast giveaway wave on July 3, 2026) to push victims toward fake investment/gambling sites. Among brands, Google, Microsoft, Apple, Roblox, and Amazon are the five most-impersonated names, with Google's brand abused at least twice as often as Amazon's.
The report also flags a mid-June to mid-July 2026 spike in gaming-platform scam activity, with Roblox scam activity up 15% and Steam scam activity up 19% over that window, and about half of all gaming-related scams causing a financial hit of $1,000 or more to the victim. This aligns with independent 2026 reporting: Bitdefender warned on March 30, 2026 of a fake game-playtest-invitation campaign spreading malware and stealing Steam/Discord credentials via spoofed developer accounts and lookalike login pages, and Guardio's Q1 2025 phishing-brand report already ranked Steam as the #1 and Roblox as the #4 most-imitated brand in phishing overall, indicating the mid-2026 spike sits on top of an already-elevated baseline for these platforms.
This is a threat-research trend/awareness report from Malwarebytes' own proprietary telemetry rather than a specific exploited vulnerability, malware family, or attributed campaign; there is no CVE, PoC, or nation-state TTP associated with it. Its value is defensive: it lets SOC/fraud teams and consumer-protection programs tune channel-specific detection and user-education messaging (e.g., treat unsolicited toll/IRS/brand-alert messages as high-risk regardless of surface plausibility, and expect scam-text volume to spike around midday Friday ET).
Target sectors: consumer, gaming, financial services, government services, technology
Target regions: united states of america, Global
Timeline
- FBI IC3 issues nationwide PSA240412 warning of an ongoing unpaid-toll smishing campaign, establishing the toll-scam channel/domain pattern later confirmed by Malwarebytes telemetry.
- IRS publishes its 2026 'Dirty Dozen' scam list (IR-2026-30), warning that IRS-impersonation phone scams increasingly use AI-generated voice synthesis and spoofed caller ID.
- Bitdefender warns of a fake game-playtest-invitation campaign spreading malware and stealing Steam/Discord accounts, preceding the gaming-platform scam spike Malwarebytes later measures.
- Malwarebytes begins the telemetry collection window analyzed in the report.
- Approximate start of the mid-June gaming-platform scam-activity spike (Roblox +15%, Steam +19%) observed in Malwarebytes telemetry.
- Bitdefender documents a MrBeast-impersonation giveaway scam spread via stolen/compromised Discord accounts.
- Malwarebytes telemetry collection window closes; mid-July marks the approximate end of the gaming-platform scam-activity spike.
- Malwarebytes publishes 'Scammers are getting smarter about where they target you,' disclosing the channel-matching, timing, and impersonation findings documented in this record.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, LOW, threat intelligence, cybersecurity, T1566.002, T1566.004, T1598.003, T1598.004, T1660, T1684.001, T1585.001, T1585.002, T1583.001, T1204.001