Surge in Crimes Exploiting Brand Trust; NordVPN Warns Against Phishing Impersonating Netflix, Google, and More
TECHWORLD · · 1 views
✦ AI Summary
In its "Consumer Cybersecurity Report," NordVPN analyzed generative AI, advanced attack methods, and attacks targeting consumers’ daily lives.
The report said that in 2026 the most exploited target would be human trust rather than system vulnerabilities, and warned users to be careful about phishing attempts impersonating Netflix, Google, and others.
It also found that 99% of more than 4.4 million blocked phishing links impersonated 300 well-known brands, while threats such as session cookies and scam calls were also identified.
Phishing attacks that exploit people’s trust by using familiar brands as bait are on the rise. These attacks are raising concern because they can undermine existing defenses by abusing personal trust. Industry watchers warn that cyberattacks are becoming more sophisticated, trust is being weaponized as an attack vector, and the resulting damage is becoming more severe.
On the 9th, NordVPN released its "Consumer Cybersecurity Report." The report, the company’s first flagship report, analyzed cyber threat trends in the first half of the year. It covered the use of generative AI and advanced attack methods, the continued targeting of consumers’ daily lives, and attacks at unprecedented scale. NordVPN said users need to be careful about phishing attempts impersonating Netflix, Google, and others.
The report said that in 2026, the most exploited target would be human trust rather than system vulnerabilities. It also analyzed that cybercrime is moving away from mass, indiscriminate technical exploitation. It added that the pattern is shifting toward sophisticated, targeted campaigns that exploit urgency and greed and weaponize consumers’ trust in familiar brands.
The analysis found that readily available scam kits and unrestricted AI models have dramatically lowered the barrier to entry for criminals, creating a serious threat to ordinary consumers’ finances, personal information, and digital security. In response, the report presented practical guidelines for consumer protection, aimed at building both technical defenses and behavioral resilience.
NordVPN also said it processes more than 12 million unique URLs every day and analyzes about 360 million web addresses each month, blocking an average of 130,000 malicious pages daily. The most frequently blocked threat type was malware, with more than 5 million malware blocks in January 2026, and the spread pattern pointed to information-stealing malicious code. By region, the U.S. accounted for more than 4.89 million blocks and the U.K. for more than 2 million, while expansion centered on Western Europe was also identified.
The analysis found that phishing attacks are increasingly being precisely targeted at specific victims. Of more than 4.4 million blocked phishing links analyzed, 99% of all phishing attacks were found to impersonate 300 well-known brands. Microsoft ranked first in brand impersonation at 16.12%, followed by Roblox at 12.32%, Google at 9.94%, and Netflix at 5.99%.
Scam crimes were also found to exploit public trust. Of scam-blocking cases, 43.2% were tied to abuse of the ".com" domain, and the company blocked 29,000 scam calls from launch through June 16, 2026. During the same period, it sent spam warnings to more than 525,000 people.
Meanwhile, information leaks via the dark web and session hijacking threats were found to be at a serious level. Over 90 days, 8.4 million compromised accounts were identified, and more than 47% of the leaked data contained real addresses and names. Information containing addresses and names was described as data that can be used to identify and exploit victims.
Session hijacking threats are surging as cybercrime evolves. From January to May this year, 94 billion cookies were exposed online, of which 1.2 billion were session cookies. Session cookies can be exploited to bypass MFA or hijack accounts without a password, making session hijacking a serious threat because it can circumvent existing security defenses.
Marijus Briedis, CTO of NordVPN, said malicious actors are exploiting humans’ instinctive trust in what they see and hear. He explained that such attacks do not require advanced technical skills or massive resources, and that anyone with an internet connection can launch an attack. He added that damage from a single human error can become more devastating than ever before.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406711
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.