Fake shop scams more than double in first half of 2026
Mon, 20th Jul 2026 (Yesterday)
Fake online shop scams more than doubled in the first half of 2026, with Gen blocking 114.2 million e-shop scam attacks during the period.
Western Europe was a major target. The UK, Germany, France, Italy and Spain accounted for 30.9 million blocked attacks, according to the company behind Norton and Avast.
The figures are part of Gen's latest threat research, which argues that online fraud is increasingly designed to blend into everyday digital activity rather than stand out as obviously malicious. In e-shop scams, that has meant cloned retail sites built to resemble genuine online stores closely enough to mislead shoppers.
One scam template identified by Gen, known as FakeShop, was responsible for more than 10.1 million blocked attacks. The finding illustrates how fraud operations can reuse a working design across multiple brands and markets instead of building separate sites from scratch.
The rise in fake stores comes as discount periods and seasonal sales create favourable conditions for fraudsters. Shoppers searching for lower prices or buying from unfamiliar retailers may be more exposed to websites that copy logos, product images and reviews from legitimate businesses.
Broader shift
The increase in fake e-shop attacks fits a wider pattern across cybercrime. Gen's report found that many of the most effective attacks no longer depend on malware or direct technical compromise, but instead exploit trusted services, recognised brands and routine online behaviour.
Some scams were delivered through booking platforms while referencing genuine reservations. In other cases, messaging accounts were compromised by persuading users to approve an attacker's browser as a linked device. In financial crime, verified bank accounts were used after their owners were recruited through social media offers of quick cash.
"The most effective attacks in the first half of 2026 didn't look like attacks," said Vita Santrucek, Chief Technology & Development Officer at Gen.
"They arrived through booking platforms, family message threads, software update channels and AI agent workflows - all places people already trust. As attackers blend into everyday digital experiences, protection has to move closer to the moments where confidence is earned, exploited or broken."
Scam growth
Beyond fake shops, Gen reported sharp increases in several other forms of fraud and abuse. Government impersonation scams rose 387% over the previous six months, while family impersonation scams increased by more than 454%.
Tech support scams remained widespread, with 20.3 million attacks blocked in the half year. Gen also identified more than 304 million scam ad impressions across the EU and UK in less than a month, underlining the reach fraudulent advertising can achieve through established online platforms.
Other findings pointed to growing pressure on privacy and identity protection. Gen blocked roughly 1.9 billion tracking attempts during the period, while breach notification alerts with attributed leak sources linked to Norton and LifeLock rose 628.1% to 3.3 million. More than 10 million breach notifications were sent in total.
Financial monitoring alerts also climbed. Bank account activity alerts increased 734%, which Gen attributed to broader monitoring coverage as well as a rise in flagged transactions. It also reported blocking 1 million web skimming attacks, up 212%, as criminals continued to target payment pages where consumers expect to enter card details.
AI concerns
The report also highlighted risks linked to AI agents that can browse the web, install software, access files and connect to online services on a user's behalf. Gen said attackers are beginning to focus on the permissions and delegated trust these systems rely on.
Early telemetry from Sage, the company's security platform for AI agents, found that the most common high-risk actions included attempts to run dangerous system commands, open remote command channels, download and execute code from the internet, read credential files without authorisation, create persistent remote access and override the agent's instructions.
Gen argues that attacks are moving deeper into systems and experiences that users already regard as legitimate. In that environment, fake retail websites are one visible example of a broader trend in which deception increasingly depends on familiarity rather than crude technical tricks.