Scammers Shift Lures to Email, Text, and Social

Malwarebytes · Medium sophistication
Last updated September 3, 2026

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast) and suggests scammers time campaigns for maximum response, such as lunchtime and Fridays in the U.S.

How the attack worked

Malwarebytes data shows scammers are not using a one-size-fits-all approach. Instead, they tailor scam type to the channel where it performs best. Toll scams, which threaten fines or license suspension, arrive by email or text in nine out of ten cases. Romance scams tend to start on social media, where trust can be built over time through a profile and ongoing messages. IRS scams frequently use a phone call, with about half of all reported IRS scams arriving that way. This channel matching lets scammers exploit the specific dynamics of each platform, whether it is the immediacy of a text message or the perceived authority of a phone call.

Why it succeeded

Impersonation of trusted names adds credibility to these lures. Malwarebytes found that MrBeast is currently the most impersonated person in its data, used in scams ranging from crypto giveaways to transfer fee swindles that ask victims to send money as part of a fake verification step. Major brands including Google, Microsoft, Apple, Roblox, and Amazon are also frequently impersonated. Timing plays a role too: scam texts to Americans peak around 12:00 pm ET and are highest on Fridays, suggesting scammers schedule campaigns for when people are more likely to respond quickly, such as during a lunch break or at the start of a weekend.

What to watch for

  • Unsolicited toll or fee notices that threaten fines or license suspension and push you to click a link
  • Social media posts or messages claiming to be from a well known figure asking for money as a "verification" step before a giveaway
  • Unexpected phone calls claiming to be from a tax authority that request personal details, PINs, passwords, payment information, or verification codes
  • Messages that arrive at predictable high-traffic times, such as midday or Friday, designed to catch people when they are distracted

How to build resistance

Malwarebytes' guidance centers on verifying independently rather than trusting the message or call itself. If a toll or billing notice seems suspicious, go directly to the official website or account instead of using the link in the message. For unsolicited calls, avoid sharing PINs, passwords, or verification codes, and hang up to call back using an official number. For social media posts claiming a celebrity giveaway, remember that legitimate prizes do not require sending money first. Gaming communities such as Roblox and Steam have also seen notable spikes in scam activity, so users in those communities should apply the same skepticism to unsolicited offers and requests for payment.

Key findings

  • Toll scams most often arrive by email or text, while romance scams often start on social media.
  • Different scam types show strong channel preferences (e.g., IRS scams often arrive by phone call).
  • The web remains the largest delivery channel overall; Malwarebytes says it blocks around 500,000 phishing websites per day.
  • Impersonation is common: “MrBeast” was the most impersonated person in Malwarebytes data, used in scams including crypto giveaways and transfer-fee swindles.
  • Scam texts to Americans peak around 12:00 pm ET and are highest on Fridays.
  • Major brands are frequently impersonated, with Google, Microsoft, Apple, Roblox, and Amazon listed as top targets.
  • Gaming communities are increasingly targeted; Roblox and Steam saw notable spikes in scam activity in the observed period.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, HR/Recruiting, Customer Support.
  • Affected industries: Consumers/Public, Technology platforms (social media, email, web), Gaming communities.
  • Attack channels: email, smishing, website, vishing.
  • Impersonated: Toll road/transportation authority, MrBeast (Jimmy Donaldson), IRS (tax authority).

Red flags to watch for

  • Threatening consequences like fines or license suspension to create urgency
  • Arrives unexpectedly via email/text
  • Pushes you to act from the message instead of using official billing channels
  • Asks for money to 'verify' before receiving winnings
  • Relies on a famous person’s identity to build trust
  • Presented through a feed/post rather than an official verified channel
  • Unsolicited call claiming to be a government agency
  • Pressure to respond immediately during the call
  • Requests for personal details, PINs, passwords, payment info, or verification codes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Why do toll scams mostly arrive by email or text?

Malwarebytes found that nine in ten toll scams, which threaten fines or license suspension, arrive by email or text because those channels create urgency and push victims to click a payment link quickly.

How are scammers using MrBeast's identity?

Malwarebytes data shows MrBeast is the most impersonated person, with scammers using his likeness for crypto giveaways and transfer fee swindles that ask victims to send money as a verification step.

What channel do IRS scams typically use?

According to Malwarebytes, half of all IRS scams arrive via a phone call, often pressuring the target to share personal details, PINs, passwords, or payment information immediately.

When are scam texts most active?

Malwarebytes reports that scam texts to Americans peak around 12:00 pm ET and are highest on Fridays, suggesting scammers time messages for maximum response.

Read the video transcript

Scams aren’t random anymore, they’re customized to where you are: text, email, socials, even gaming. Example one: A fake unpaid-toll email or text saying, “Pay now or your license gets suspended,” with a link to “resolve it.” Nine in ten of these toll scams arrive exactly like that, by email or SMS. Example two: A fake giveaway site using a MrBeast-style thumbnail in your feed, telling you you’ve won, but you must send crypto or a “verification fee” first. Malwarebytes says “MrBeast” is now the most impersonated person for these swindles. Here’s the move: if any message says “pay this toll” or “send money to verify a prize,” don’t tap the link, go to the official site or app yourself and check there instead.

Similar attacks

ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026