As cybercriminals leverage generative artificial intelligence, sophisticated social engineering, and targeted social media campaigns, public advisories and intelligence reports published in September 2026 highlight a sharp rise in complex fraud schemes. According to data from international banking groups, fraud watchdogs, and law enforcement agencies, mobile-driven and identity-focused attacks now account for the majority of financial scam attempts.
Below are the top ten frauds and scams reported across consumer protection, banking, and law enforcement channels during September 2026.
1. GENERATIVE AI VOICE CLONING AND DEEPFAKE CALLS
Scammers are increasingly utilizing synthetic media to impersonate bank representatives, corporate executives, or family members in distress. By analyzing a short audio sample scraped from social media or public videos, generative voice engines create hyper-realistic phone interactions to pressure victims into granting immediate wire transfers or authorizing multi-factor authentication (MFA) prompts.
2. IMPERSONATION OF FINANCIAL SERVICES AND BANK “PUMP-AND-DUMP” GROUPS
Major banking institutions issued widespread warnings in September 2026 regarding fake investment opportunities circulating on messaging apps and social platforms. Scammers clone legitimate financial group logos (such as CommSec and major retail banks) to recruit individuals into closed chat groups, coercing them to invest in high-yield vehicles or artificial “pump-and-dump” stock schemes.
3. REMOTE WORK & ONLINE EMPLOYMENT SCAMS
Tracking reports indicate that recruitment and employment fraud grew by over 250% in 2026. Candidates are contacted via instant messaging or professional networks regarding lucrative remote job offers. Applicants are then instructed to purchase home office equipment using fake checks, submit sensitive personal data for identity verification, or deposit cryptocurrency to clear “training modules.”
4. QR CODE PHISHING (“QUISHING”)
Malicious QR codes placed over legitimate codes on public parking meters, restaurant tables, and outdoor advertisements remain a persistent threat. Once scanned, these altered codes redirect users to counterfeit payment gateways designed to harvest credit card information or install silent malware onto mobile devices.
5. COUNTERFEIT SOCIAL MEDIA ADS AND MARKETPLACE FRAUD
Consumer protection agencies issued formal alerts regarding targeted social media advertisements promoting deeply discounted items from fake e-commerce brands. After completing the purchase, buyers receive either low-quality counterfeit goods or nothing at all, while their payment card details are sold on illicit online forums.
6. PEER-TO-PEER (P2P) PAYMENT AND FAKE REFUND SCAMS
As mobile payment apps dominate daily transactions, scammers are exploiting “mistaken transfer” mechanics. Targets receive notification of a deposit followed by a message claiming the transfer was accidental and asking for a return payment. The original deposit is eventually reversed by the bank as stolen or fraudulent, leaving the victim out of pocket for the “returned” balance.
7. AUTOMATED SUBSCRIPTION AND TELECOM BILLING TRAPS
Telecommunications regulators and fraud units reported a surge in unauthorized premium-rate subscription charges applied directly to cellular accounts. Victims are drawn in by subtle “free trial” prompts or silent background scripts on unverified web pages, resulting in recurring charges billed directly to their monthly phone accounts.
8. CORPORATE INVOICE SPOOFING & BUSINESS EMAIL COMPROMISE (BEC)
Invoice spoofing continues to inflict high financial losses on small-to-medium businesses. Fraudsters monitor compromise vector feeds, intercept legitimate corporate billing emails, and re-issue invoices with updated banking and wire instructions right before payment deadlines.
9. CRYPTO “MULTIPLICATION” AND FAKE TRADING PLATFORMS
Unregulated investment portals promising guaranteed high returns through AI-driven cryptocurrency trading saw heavy reporting in September 2026. These dashboards often display fake capital gains to encourage larger deposits; however, once victims attempt to withdraw their funds, the platform demands non-existent “tax verification fees” or blocks access completely.
10. SMISHING EMERGENCY AND LAW ENFORCEMENT IMPERSONATION
Text message scams (“smishing”) using personal details retrieved from data breaches remain a primary delivery system for fraudsters. Scammers send urgent text messages pretending to represent traffic departments, tax agencies, or police services, threatening immediate arrest or account suspension unless a fine or settlement is paid immediately via external links.
KEY PROTECTIVE STEPS
- Verify Independently: Always disconnect suspicious incoming calls or texts and contact institutions directly using verified phone numbers listed on official websites or physical bank cards.
- Inspect Links and QR Codes: Check preview URLs carefully before entering payment details or downloading files.
- Enable Multi-Factor Authentication (MFA): Use app-based authenticator tools or biometrics rather than SMS-based verification codes where possible.
This BBB Consumer Alert video offers a practical look at how social media platforms are exploited by scammers and provides additional consumer tips for staying safe.
