AntiMalwareJuly 23, 2026🇷🇺Translated from Russian

macOS Users Encounter Phishing and Scams More Often Than Windows Users but Adopt Fewer Protections, Kaspersky Study Reveals

A recent study conducted by Kaspersky Lab highlights a concerning trend among macOS users, who report encountering cyber threats more frequently than Windows users while simultaneously adopting fewer protective measures.

According to the findings, 12 percent of surveyed macOS users experienced phishing attacks in the past year, compared to only 9 percent of Windows users. Complaints about fraudulent investment schemes reached 16 percent among Mac owners versus 13 percent for Windows users.

Privacy-related incidents were also more common on macOS, with 11 percent reporting violations of confidentiality against 8 percent on Windows, and 12 percent noting theft of personal data compared to 7 percent.

Behavioral differences further illustrate the gap. Only 51 percent of macOS users refrain from opening suspicious emails and links, while 62 percent of Windows users do so. Additional security solutions are installed by 35 percent of Mac users versus 42 percent of Windows users.

Password hygiene shows similar disparities: 35 percent of macOS users create unique credentials for each account compared to 38 percent on Windows. Complex passwords are chosen by 45 percent versus 52 percent, and multi-factor authentication is enabled by 46 percent against 51 percent.

Kaspersky Lab emphasizes that built-in macOS protections provide solid defense against many threats but fall short against social engineering, supply-chain attacks, and malware specifically designed for Apple platforms. The perception of macOS as inherently secure has apparently led to complacency among users.

Related articles

AntiMalwareFraud & Social Engineering

WhatsApp Begins Limited Beta Testing of On-Device Scam Alert to Detect Fraud While Preserving End-to-End Encryption

WhatsApp has started limited beta testing of its Scam Alert feature, which uses an on-device machine learning model to analyze message patterns and linguistic indicators of fraud. The system runs entirely locally on the user's smartphone, ensuring that conversation content is never sent to WhatsApp or Meta. Users receive warnings about suspicious messages from unknown contacts and can choose to block, report, ignore, or mark the chat as trusted. To maintain transparency, each model release is logged in an immutable journal managed by Cloudflare with Ed25519 signatures and SHA-256 hashes. The company receives only anonymized statistics on detections and user actions. In parallel, Signal has introduced automatic key verification using a cryptographically verifiable log audited by Cloudflare and Trail of Bits.

AntiMalwareFraud & Social Engineering

Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android

Google reported that its Chrome protection systems blocked more than 7 billion unwanted notifications every day on Android during the first quarter of 2026. Websites increasingly use browser notifications to deliver phishing attempts, fraudulent payment requests, and malware. Chrome applies a multi-layer "Swiss cheese" defense model where several overlapping filters compensate for each other's weaknesses. The browser automatically revokes notification permissions from sites that have not been visited recently or that trigger repeated security warnings, and it can also cancel associated subscriptions. For particularly noisy resources, Chrome enforces a hard limit of 1,000 messages per minute and returns HTTP 429 responses to excess traffic. Google also made permission prompts less intrusive on Android, which reduced background activity and improved battery life. Users can review and manage notification permissions through Safety Hub on both desktop and mobile versions of Chrome.

AntiMalwareFraud & Social Engineering

Mail.ru Blocks Phishing Wave Using Password-Protected RAR Archives

Mail.ru's antispam team has stopped a new phishing campaign that relies on password-protected RAR archives. These messages accounted for 13% of all blocked emails over the past month. The attackers impersonate business correspondents by sending contracts, signature requests, and tax-related notifications during the reporting season. Each email contains the archive password in plain text, allowing the recipient to open a malicious executable hidden inside. The malware is designed to steal credentials, grant remote access, or exfiltrate personal and corporate data. Mail.ru's filtering system uses more than 30 machine-learning models and antispam checks to detect such threats. Users are advised to verify senders carefully and avoid launching files from unexpected attachments even when a password is supplied.

AntiMalwareFraud & Social Engineering

Kaspersky Adds Call Filtering to Kaspersky Secure Mobility Management for Android Devices

Kaspersky has introduced call control capabilities into the expanded version of Kaspersky Secure Mobility Management. The new feature allows corporate Android devices running Kaspersky Endpoint Security for Android to check incoming call numbers against both local offline databases and global online reputation sources. Depending on company policy, the system can display warnings to employees or automatically block suspicious calls. Administrators gain the ability to define rules by call category, maintain black and white lists, and apply different policies to specific employee groups. The update targets risks from telephone fraud and social engineering attempts that aim to extract confidential corporate information or funds. It also helps reduce unwanted spam calls that disrupt staff who handle high volumes of incoming communications. Kaspersky Secure Mobility Management provides full lifecycle control over corporate mobile devices, applications, data, and security policies.