Gen, a global leader powering Digital Freedom with a family of trusted brands including Norton, Avast, and more, has released its Q1/2025 Gen Threat Report, highlighting the most significant shifts shaping the global Cyber Safety landscape observed between January and March 2025.
Key report findings include a 186% surge in breached personal information, a 466% increase in phishing reports, growth in fake browser update scams by 17 times the previous quarterโs levels, and more than 4 million people protected from Scam-Yourself Attacks, alongside the rise of mobile financial fraud and crypto-related US presidential inauguration scams.
โOnline threats are evolving at a startling pace,โ said Siggi Stefnisson, Cyber Safety CTO at Gen.
โAttackers are moving away from broad, indiscriminate campaigns to highly personalised, AI-enhanced deception. Breached data and AI tools are giving cybercriminals just enough personal information and design sophistication to more easily manipulate people. Thatโs why we constantly evolve our cybersecurity solutions to be an interactive partner in fighting scams and to be one step ahead of cybercriminals.โ
Notable Trends from the Q1/2025 Gen Threat Report:
Data Breaches Escalate
Data breaches are on the rise, with a 36% increase in the number of breaches faced by companies compared to last quarter. Individual breached records surged by more than 186%, revealing sensitive information such as passwords, emails, and credit card details. Attackers employed more advanced infostealers like Lumma Stealer, making data compromise faster and harder to detect.
Phishing Scams Designed to Bypass Security Filters
Reports of phishing scams rose by a staggering 466% compared to the previous quarter, now making up nearly 32% of all scam submissions to the Norton Genie scam detector. According to the Norton Genie scam detector platform, phishing is the fastest-growing threat, second only to generic scams, which accounted for 51% of reports. The good news is that people are becoming more wary of potential phishing scams and reporting these messages.
Telemetry data reveals a growing number of phishing campaigns that abuse dynamic DNS services and subdomain providers, as well as free website builders to create deceptive login pages. This means, that by mimicking legitimate login portals and leveraging trusted domainsโlike recent scams targeting AT&T, Telstra and Xfinity customersโattackers make phishing attempts harder to detect and more likely to succeed. Many of these campaigns create a sense of urgency for potential victims through emails claiming account issues or prompting people to review sensitive documents. Despite sometimes being poorly written, the use of familiar platforms and subdomain tricks allows these scams to bypass security filters and remain highly effective.
Scam-Yourself Attacks and Fake Browser Updates on the Rise
Gen helped protect over 4 million users from Scam-Yourself Attacks in which individuals, through sophisticated deception, are manipulated into infecting their own devices. In one of the most striking evolutions of this type of scam that we observed this quarter, attackers are using AI-generated personas, deepfake influencers and hired actors. They use these personas to deliver their malicious campaigns. This is primarily done through compromised YouTube accounts, leveraging interactive FakeCAPTCHAs and asking people to verify they are human but instead guiding them to give device permissions or download malware.
Fake Update Scams grew to over 17 times last quarterโs level. This type of Scam-Yourself Attack tricks people into installing malware under the guise of browser updates.
Financial Threats Thrive on Mobile and Crypto
Mobile financial threats continued to rise, fueled by increasingly sophisticated tactics that target people directly through their smartphones. Malware, like banking trojans, now exploit accessibility features to overlay fake login pages, stealing sensitive data such as crypto wallet credentials. Combined with an uptick in credit and transaction fraud alerts, thereโs a growing trend of attackers focusing on mobile devices as gateways to peopleโs financial lives.
Digital currencies continue to be a target for financial threats. CryptoCore executed one of its most successful campaigns in early 2025, hinging on the US presidential inauguration. Attackers leveraged deepfake videos of public figures spread through compromised YouTube accounts to steal close to $4 million spread through more than 2,000 transactions.
Gen is always innovating to stay one step ahead of todayโs evolving cyberthreats. Our trusted family of brands offers powerful solutions to help keep you safeโLifeLock helps people protect their identity, the Norton Cyber Safety lineup comes equipped with Norton Genie scam protection, and products like Avast Mobile Security offer protection for mobile devices, just to name a few.
To learn more about the latest Cyber Safety tips and solutions, visit our blog at https://www.gendigital.com/blog/insights.
The full Gen Threat Report is available now at https://www.gendigital.com/blog/insights/reports/threat-report-q1-2025