Security NEXTJuly 24, 2026🇯🇵Translated from Japanese

IPA Reports Record High Fake Warning Scam Consultations in Q2 2026

The Information Processing Promotion Agency (IPA) has reported that personal security consultations received through its Information Security Relief Consultation Window reached 3,832 cases in the second quarter of 2026. This represents an approximate 8.5 percent increase compared to the 3,533 cases recorded in the previous quarter, continuing an upward trend that began in the third quarter of 2025.

Among the consultation topics, fake warning incidents stood out with a significant rise. These scams involve fraudulent pop-up screens claiming to detect malware on a user's device, designed to create panic and prompt victims to call supposed support numbers. In Q2 2026, such consultations totaled 1,428 cases, up 23.7 percent from 1,154 in the prior quarter and marking the highest volume in the last two years.

Victims of these fake warning schemes face risks of financial extortion or device infection when they engage with the criminals posing as technical support staff. Although consultations temporarily declined following arrests in a major support fraud case in May 2025, the numbers have rebounded and now exceed the 1,084 cases seen in the first quarter of 2025, before those arrests occurred.

Separately, phishing consultations increased modestly to 146 cases, a 5.0 percent rise from 139 in the previous quarter. Various tactics were observed, including schemes impersonating the National Tax Agency and other trusted organizations to steal personal or financial information.

The IPA continues to emphasize the importance of remaining alert to these evolving social engineering threats, as the upward trend in fake warning reports shows no signs of abating after three consecutive quarters of growth.

Related articles

BoletimSecFraud & Social Engineering

Password Spraying Campaign Targets AWS Root Accounts in Over 150 Organizations

A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers performed repeated login attempts against identities holding maximum privileges in the cloud environment. The root account is created with every AWS account and grants full access to resources, configurations, billing, and sensitive administrative functions. Researchers observed a median of two attempts per organization, with some targets receiving up to eight attempts. No successful authentications linked to the campaign have been identified so far. The attacks leveraged distributed proxies across multiple countries and networks, including hosting infrastructure and residential proxies, while using user agents that mimicked older versions of Microsoft Edge and Firefox. Since June 2025, AWS has required MFA for root users, significantly raising the bar for account takeover even if a password is discovered.

AntiMalwareFraud & Social Engineering

Unsolicited iPhone 15 Pro Max Delivery to Reddit User Sparks Fears of Targeted Cyber Attack

A Reddit user received an unexpected iPhone 15 Pro Max in a sealed box that was never ordered. Apple’s service identified the serial number as belonging to a device purchased or activated in December 2023, with its warranty already expired in 2024, creating a clear mismatch between the new-looking packaging and the device’s documented history. The included FedEx label contained a tracking number that does not exist in the carrier’s system. Discussion on the platform raised the possibility of a targeted attack, potentially a form of whaling, in which the phone could have been pre-modified to steal data or credentials once connected to a network or Apple ID. No concrete evidence confirms the package originated from an attacker, and alternative explanations such as a delivery error or order fraud remain possible. Experts recommend that recipients avoid powering on the device, inserting a SIM card, or entering any account credentials, and instead consider returning it to Apple for inspection or disposing of it as electronic waste.

AntiMalwareFraud & Social Engineering

Scammers Embed Phishing Inside Telegram Mini Apps After August Update

Cybercriminals are increasingly abusing Telegram's Mini Apps and WebView features to deliver phishing attacks that mimic legitimate banking, payment, and cryptocurrency services. Following the platform update on August 25, attackers can now present fake interfaces for transfers, airdrops, and voting systems directly inside the messenger. Victims are tricked into entering confirmation codes, connecting wallets, or pasting commands into PowerShell under the guise of fixing errors or claiming bonuses. The attacks rely heavily on social engineering rather than automated malware, requiring users to actively authorize actions such as signing transactions or providing phone verification details. Fake voting schemes are used to harvest account credentials, while crypto-related lures prompt users to link wallets to malicious services. Experts emphasize that simply opening a Mini App does not lead to immediate theft, but authorizing or connecting assets does expose users to significant risk.

AntiMalwareFraud & Social Engineering

Google Introduces Multi-Step Verification for Android APK Sideloading to Combat Fraud

Google has begun rolling out an enhanced installation flow for Android apps installed outside of Google Play. Users must first confirm that no one is coercing them to enable unknown sources, then reboot their device and wait 24 hours before the option becomes available. The new process includes explicit warnings about scammers who pressure victims into enabling sideloading, noting that legitimate organizations never require this setting. After the waiting period, users can grant the permission for seven days or indefinitely. The change does not affect ADB installations, preserving a workaround for advanced users. Google states the delay is intended to give people time to reconsider before enabling potentially risky settings. An Android Authority poll showed 88 percent of respondents expect further restrictions in the future.