Security NEXTJuly 24, 2026🇯🇵Translated from Japanese

IPA Reports Record High Fake Warning Scam Consultations in Q2 2026

The Information Processing Promotion Agency (IPA) has reported that personal security consultations received through its Information Security Relief Consultation Window reached 3,832 cases in the second quarter of 2026. This represents an approximate 8.5 percent increase compared to the 3,533 cases recorded in the previous quarter, continuing an upward trend that began in the third quarter of 2025.

Among the consultation topics, fake warning incidents stood out with a significant rise. These scams involve fraudulent pop-up screens claiming to detect malware on a user's device, designed to create panic and prompt victims to call supposed support numbers. In Q2 2026, such consultations totaled 1,428 cases, up 23.7 percent from 1,154 in the prior quarter and marking the highest volume in the last two years.

Victims of these fake warning schemes face risks of financial extortion or device infection when they engage with the criminals posing as technical support staff. Although consultations temporarily declined following arrests in a major support fraud case in May 2025, the numbers have rebounded and now exceed the 1,084 cases seen in the first quarter of 2025, before those arrests occurred.

Separately, phishing consultations increased modestly to 146 cases, a 5.0 percent rise from 139 in the previous quarter. Various tactics were observed, including schemes impersonating the National Tax Agency and other trusted organizations to steal personal or financial information.

The IPA continues to emphasize the importance of remaining alert to these evolving social engineering threats, as the upward trend in fake warning reports shows no signs of abating after three consecutive quarters of growth.

Related articles

AntiMalwareFraud & Social Engineering

macOS Users Encounter Phishing and Scams More Often Than Windows Users but Adopt Fewer Protections, Kaspersky Study Reveals

A new study from Kaspersky Lab shows that macOS users report higher rates of phishing encounters and various scams compared to Windows users, yet they are less likely to implement basic security measures. Over the past year, 12 percent of macOS users faced phishing attempts versus 9 percent of Windows users, while 16 percent encountered investment fraud schemes compared to 13 percent. Privacy violations and personal data theft were also reported more frequently by Mac owners at 11 percent and 12 percent respectively, against 8 percent and 7 percent for Windows. Security habits differ notably, with only 51 percent of macOS users avoiding suspicious links and emails versus 62 percent of Windows users, and just 35 percent installing additional protection tools compared to 42 percent. Password practices and multi-factor authentication usage follow the same pattern, with Mac users trailing in creating unique or complex passwords and enabling 2FA. Kaspersky notes that while macOS built-in defenses handle many threats effectively, they offer limited protection against social engineering and platform-specific attacks, underscoring that the Apple brand does not serve as automatic security.

AntiMalwareFraud & Social Engineering

Scammers Impersonate Russian Post to Lure Victims into Fake Telegram Bots

Fraudsters have developed a new scheme targeting Russian citizens by impersonating Russian Post over the phone. They claim that a registered letter or parcel requires additional address details and direct victims to a counterfeit Telegram bot. The bot then requests personal information, bank card data, or SMS verification codes. State Duma deputy Anton Nemkin highlighted how the criminals exploit trust in the well-known postal service and create urgency around expected deliveries. Victims are advised to avoid any links or contacts provided by callers and instead verify information directly through official Russian Post channels. The scheme relies on automatic reactions from people who may be expecting packages, making them more likely to follow instructions without suspicion. No actual parcel exists, but the risk of account takeover or financial loss remains very real.

AntiMalwareFraud & Social Engineering

From Free Game Cheats to Arson: Cybercriminals Recruit Children for Espionage and Violent Crimes

Cybercriminals are increasingly targeting children not only to steal money from parents but also to turn them into unwitting accomplices in dangerous criminal activities. During school holidays, teenagers spend more time in games and messengers where scammers offer free in-game currency, mods, cheats, and pirated game versions to build trust. Once access is gained, fraudsters extract SMS codes, bank card details, or device control, escalating to threats and blackmail when initial tactics fail. Kaspersky Lab recorded over 19 million attempts to distribute malware disguised as popular games between April 2024 and April 2025, installing spyware and RAT trojans that monitor chats, keystrokes, cameras, and microphones. In severe cases, children are manipulated into believing they assist law enforcement, leading to real-world crimes such as photographing apartments, handing over keys, setting fires, or attacking people. Specific incidents include a 12-year-old boy from Leningrad Oblast forced to assault a police officer and a 13-year-old from Podolsk ordered to ignite a gas pump at a filling station. Izvestia reporting highlights that parents should watch for signs like hidden screens or strange tasks and teach children that no stranger can demand codes, money, or secret missions.

AntiMalwareFraud & Social Engineering

Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud

Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.