NordVPN report reveals how AI accelerates consumer fraud

NordVPN has published its first flagship threat intelligence study, warning that generative AI and industrialised fraud techniques are reshaping the consumer cybersecurity landscape at speed. The Consumer Cybersecurity Report: Dismantling the Evolving Threat Landscape analyses data from January to June 2026 and highlights how cybercriminals are exploiting trust, urgency and brand familiarity to target individuals with unprecedented precision.

Drawing on millions of daily threat signals, NordVPN argues that the most exploited vulnerability this year is human trust. Rather than relying on broad technical exploits, attackers are increasingly deploying AI‑driven, highly personalised campaigns designed to mimic legitimate brands, services and behaviours. The report notes that ready‑made fraud kits and unrestricted AI tools have lowered the barrier to entry, enabling even inexperienced actors to launch convincing attacks at scale.

Marijus Briedis, CTO at NordVPN, says the shift represents a fundamental change in consumer risk. “Bad actors are weaponising our instinct to believe what we see and hear. These attacks no longer require advanced skills or significant resources. Anyone with an internet connection can launch them. A single human error is now more likely than ever and likely to be more devastating than ever.”

NordVPN’s telemetry shows the company analysing around 12 million unique URLs each day, blocking an average of 130,000 malicious pages before they reach users. Malware remains the most common threat by volume, with more than 5 million attempts intercepted in January alone as attackers targeted post‑holiday shoppers. Infostealers dominated these campaigns, particularly in the US (4.89m), UK (2m) and Germany (1.32m).

Phishing attempts exceeded 4.4 million in the first half of the year, with 99% of attacks impersonating just 300 brands. Microsoft (16.12%), Roblox (12.32%), Google (9.94%) and Netflix (5.99%) were the most frequently spoofed. Scam activity also continues to rise, with .com domains accounting for 43.2% of intercepted cases due to their perceived legitimacy. Since launch, NordVPN’s scam‑blocking tools have intercepted nearly 29,000 scam calls and flagged more than 525,000 spam calls.

Dark web monitoring identified 8.4 million compromised accounts in 90 days, with more than 47% of exposed data containing physical addresses and full names. NordVPN warns that this blending of digital and real‑world identifiers enables attackers to build detailed victim profiles. The report also highlights the scale of session hijacking risks, noting that 94 billion cookies were exposed online between January and late May. Around 1.2 billion of these could allow attackers to access accounts without passwords, in some cases bypassing MFA.

Alongside its analysis, NordVPN includes practical guidance to help consumers strengthen both their technical defences and behavioural awareness. The company argues that resilience now requires a combination of secure tools, sceptical digital habits and continuous vigilance as AI‑enabled threats evolve.

The full report is available here: https://a-us.storyblok.com/f/1001711/x/e393e7f999/nordvpn-consumer-cybersecurity-report.pdf

Check Also

Omdia research highlights widening ‘immutability gap’

A new Omdia study commissioned by Object First suggests technology leaders are losing ground in …