Phishing and Fraud Shift Toward Trusted Digital Channels, New Research Shows
Read time: 3 minutes
New research shows phishing and fraud are shifting away from obvious impersonation toward search results, paid ads, business workflows, and online marketplaces.
Bolster AI, a leading brand protection platform, has revealed a fundamental shift in how phishing and online scams are created, distributed, and monetized in its 2026 Fraud Trends and Predictions report.
According to the report, today’s most effective scams are no longer isolated messages or one-off impersonations. Instead, attackers are building full fraud lifecycles that guide victims from discovery to conversion across multiple trusted systems.
“Attackers are designing scams that look and feel real from start to finish,” said Rod Schultz, CEO of Bolster AI. “They are abusing high trust, everyday digital activities to scam people, including search results, paid ads, document approvals, and login prompts. Every step is intentional, and every step is optimized to get someone to act.”
From One-Off Scams to Repeatable Systems
Bolster’s research team tracked more than 11.9 million malicious domains in 2025 tied to phishing, fraud, and misinformation campaigns. This volume reflects how quickly attackers can now stand up, test, and rotate infrastructure once a successful distribution model is identified.
Advances in automation and generative AI have significantly reduced the cost and time required to launch these operations. As a result, attackers are increasingly investing in channels traditionally associated with legitimate marketing, such as search engine optimization (SEO) and paid advertising.
Where the Shift Is Most Visible
The report highlights several areas where this evolution is most evident:
- Search results: Attackers publish realistic informational pages designed to outrank official sources and capture users early in the decision process.
- Paid advertisements: Ads are used to intercept users during high-intent moments, such as account logins, verifications, or issue resolution.
- Business workflows: Document signing, approvals, and shared workflows have become reliable entry points for fraud.
- Online marketplaces: Scams are monetized through counterfeit listings and digital goods, benefiting from built-in trust signals like reviews and familiar checkout processes.
- High-trust sectors: Technology platforms, government services, and financial institutions are increasingly targeted due to existing user trust at scale.
“What we’re seeing is closer to a buyer’s journey than a traditional scam,” Schultz added. “Attackers are planning ahead, choosing channels deliberately, and reusing what converts.”
What This Means for 2026
The report concludes that fraud in 2026 will continue to evolve as engineered systems rather than isolated attacks. Campaigns will be timed around predictable events, scaled rapidly, and distributed through channels where legitimacy is assumed.
“Defending against this kind of fraud requires understanding how these operations are built,” Schultz said. “If security teams only look for suspicious messages at the end of the chain, they’re already too late.”
