IPA Reports Record High Fake Warning Scam Consultations in Q2 2026
The Information Processing Promotion Agency (IPA) has reported that personal security consultations received through its Information Security Relief Consultation Window reached 3,832 cases in the second quarter of 2026. This represents an approximate 8.5 percent increase compared to the 3,533 cases recorded in the previous quarter, continuing an upward trend that began in the third quarter of 2025.
Among the consultation topics, fake warning incidents stood out with a significant rise. These scams involve fraudulent pop-up screens claiming to detect malware on a user's device, designed to create panic and prompt victims to call supposed support numbers. In Q2 2026, such consultations totaled 1,428 cases, up 23.7 percent from 1,154 in the prior quarter and marking the highest volume in the last two years.
Victims of these fake warning schemes face risks of financial extortion or device infection when they engage with the criminals posing as technical support staff. Although consultations temporarily declined following arrests in a major support fraud case in May 2025, the numbers have rebounded and now exceed the 1,084 cases seen in the first quarter of 2025, before those arrests occurred.
Separately, phishing consultations increased modestly to 146 cases, a 5.0 percent rise from 139 in the previous quarter. Various tactics were observed, including schemes impersonating the National Tax Agency and other trusted organizations to steal personal or financial information.
The IPA continues to emphasize the importance of remaining alert to these evolving social engineering threats, as the upward trend in fake warning reports shows no signs of abating after three consecutive quarters of growth.
Related articles
WhatsApp Begins Limited Beta Testing of On-Device Scam Alert to Detect Fraud While Preserving End-to-End Encryption
WhatsApp has started limited beta testing of its Scam Alert feature, which uses an on-device machine learning model to analyze message patterns and linguistic indicators of fraud. The system runs entirely locally on the user's smartphone, ensuring that conversation content is never sent to WhatsApp or Meta. Users receive warnings about suspicious messages from unknown contacts and can choose to block, report, ignore, or mark the chat as trusted. To maintain transparency, each model release is logged in an immutable journal managed by Cloudflare with Ed25519 signatures and SHA-256 hashes. The company receives only anonymized statistics on detections and user actions. In parallel, Signal has introduced automatic key verification using a cryptographically verifiable log audited by Cloudflare and Trail of Bits.
Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android
Google reported that its Chrome protection systems blocked more than 7 billion unwanted notifications every day on Android during the first quarter of 2026. Websites increasingly use browser notifications to deliver phishing attempts, fraudulent payment requests, and malware. Chrome applies a multi-layer "Swiss cheese" defense model where several overlapping filters compensate for each other's weaknesses. The browser automatically revokes notification permissions from sites that have not been visited recently or that trigger repeated security warnings, and it can also cancel associated subscriptions. For particularly noisy resources, Chrome enforces a hard limit of 1,000 messages per minute and returns HTTP 429 responses to excess traffic. Google also made permission prompts less intrusive on Android, which reduced background activity and improved battery life. Users can review and manage notification permissions through Safety Hub on both desktop and mobile versions of Chrome.
Mail.ru Blocks Phishing Wave Using Password-Protected RAR Archives
Mail.ru's antispam team has stopped a new phishing campaign that relies on password-protected RAR archives. These messages accounted for 13% of all blocked emails over the past month. The attackers impersonate business correspondents by sending contracts, signature requests, and tax-related notifications during the reporting season. Each email contains the archive password in plain text, allowing the recipient to open a malicious executable hidden inside. The malware is designed to steal credentials, grant remote access, or exfiltrate personal and corporate data. Mail.ru's filtering system uses more than 30 machine-learning models and antispam checks to detect such threats. Users are advised to verify senders carefully and avoid launching files from unexpected attachments even when a password is supplied.
Kaspersky Adds Call Filtering to Kaspersky Secure Mobility Management for Android Devices
Kaspersky has introduced call control capabilities into the expanded version of Kaspersky Secure Mobility Management. The new feature allows corporate Android devices running Kaspersky Endpoint Security for Android to check incoming call numbers against both local offline databases and global online reputation sources. Depending on company policy, the system can display warnings to employees or automatically block suspicious calls. Administrators gain the ability to define rules by call category, maintain black and white lists, and apply different policies to specific employee groups. The update targets risks from telephone fraud and social engineering attempts that aim to extract confidential corporate information or funds. It also helps reduce unwanted spam calls that disrupt staff who handle high volumes of incoming communications. Kaspersky Secure Mobility Management provides full lifecycle control over corporate mobile devices, applications, data, and security policies.