SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
MrBeast tops impersonation scams, Malwarebytes says

MrBeast tops impersonation scams, Malwarebytes says

Mon, 7th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

MrBeast has become the most impersonated public figure in online scams, according to Malwarebytes. The cyber security company also found that scam texts in the US peak on Fridays and around lunchtime.

Malwarebytes analysed global threat data collected over three months and found that criminals are increasingly matching scam types to the platforms, brands and times of day that give them the best chance of success.

The findings point to a more selective approach to online fraud. Rather than sending the same messages across every channel, scammers are choosing specific routes for specific schemes. Toll scams are heavily concentrated in email and text messages, while romance scams more often appear on social media.

Nine in 10 toll scams arrive via email or text. By contrast, roughly six in 10 romance scams take place on social platforms, where unsolicited contact may seem less unusual.

Malwarebytes tracked more than 20 scam categories, including tech support, refund, sextortion, scareware, job and tax-related fraud. Many now follow predictable channel patterns: job scams largely appear through email, phone calls remain a common route for IRS scams, and fake giveaway schemes are more likely to surface in social feeds.

Impersonation targets

Among public figures, MrBeast ranked first in person-impersonation scams, appearing in about 30% of cases measured by Malwarebytes. Elon Musk and Donald Trump followed.

Familiar names remain central to fraud attempts because recognisable figures can make unsolicited messages or posts seem more believable. Scams using MrBeast's image ranged from fake cryptocurrency giveaways to transfer-fee schemes.

Brand impersonation was also widespread. Google topped the list of the most impersonated brands, ahead of Microsoft, Apple, Roblox and Amazon. In the user reports Malwarebytes analysed, Google's name appeared at least twice as often as Amazon's.

The ranking underlines how fraudsters continue to exploit mainstream consumer technology brands to gain trust. Fake emails, copied logos, lookalike websites and misleading messages remain common tools.

Timing patterns

The research also identified clear timing trends in text-based scams. Friday saw the highest level of scam text activity, with about 50% more fraudulent messages sent than on Sunday, the quietest day in the dataset.

In the US, noon Eastern Time was the busiest point for scam texts. Activity at 12pm ET was roughly 874% higher than at 1am ET.

That pattern suggests criminals are not only selecting the right channel but also choosing moments when people may be busy, distracted or more likely to glance quickly at a message. Lunchtime and the end of the working week may create openings for texts that rely on urgency, such as fake fines, delivery alerts or account warnings.

Web still dominant

Despite the growth of social media and messaging apps, the web remains the main route for scams, according to Malwarebytes. Fake websites, phishing pages, malicious adverts and counterfeit online shops continue to outnumber other forms of scam delivery in user reports.

Email ranked second behind the web, followed by text messaging. Malwarebytes says it blocks about 500,000 phishing attempts on the web each day through its own systems.

The figures indicate that while newer platforms are drawing more attention, established online channels still account for a large share of fraud attempts. Social media may be important for some categories, but websites and email remain central to the scam economy.

Gaming pressure

Gaming platforms are also attracting more fraudulent activity. About half of the gaming scams reviewed carried the potential for losses of USD $1,000 or more.

The most impersonated gaming-related services were Roblox, Steam, Discord and Minecraft. Scam activity involving Roblox rose 15% over one month during the study period, while Steam-related scam activity increased 19%.

Those figures suggest gaming communities have become a more valuable hunting ground for fraudsters, particularly where users trade digital items, make in-game purchases or respond quickly to offers and account messages. Roblox's place among the top five most impersonated brands also points to overlap between brand abuse and gaming-focused scams.

Malwarebytes described the overall pattern as evidence of increasing specialisation in online fraud. Criminals are adapting their methods to the environments where users are most likely to trust a message, click a link or respond before checking whether the contact is genuine.

The data came from Malwarebytes' internal threat research systems and covered activity observed globally between mid-April and mid-July. The company said all the information used in the analysis was anonymised and based on what it could see through its own infrastructure.

One of the clearest conclusions from the dataset is that scam delivery is no longer treated as a single mass-market exercise. Instead, scammers are choosing the person to impersonate, the brand to mimic, the platform to use and the time to strike with greater precision.