A short message. A familiar name. An everyday tone. That is how most messaging scams begin in 2026 — and how they end, in under 30 minutes, with an average loss of $733 per victim. This is not a problem of naivety. It is a problem of industrial scale.

The report The Great Messaging Heist, published by Kaspersky in June 2026, documents for the first time the real structure behind the daily flood of fraudulent messages: organised scam cartels operating with AI infrastructure, specialised divisions of labour and coordinated campaigns across multiple platforms simultaneously. And the 2026 FIFA World Cup, taking place this summer, has become their latest testing ground.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

The scale of the problem: numbers that change the picture

The Kaspersky report starts with a calculation that illustrates the magnitude of the phenomenon. If just 10% of the three billion messaging app users worldwide fell victim to a scam with the documented average loss, the total damage would amount to $220 billion — comparable to the GDP of Greece, and greater than that of Morocco, Serbia or Côte d'Ivoire.

More than 52% of successful scams are completed in under 30 minutes from first contact. Speed is part of the design: the less time the victim has to think, the less likely they are to detect the fraud.

63% of scams span multiple platforms, jumping from SMS to WhatsApp, from WhatsApp to Telegram, mimicking the natural flow of real conversations to evade each platform's filters and obscure the origin of the attack.

Scam cartels: the industry behind the message

What Kaspersky calls "scam cartels" are not groups of lone hackers. They are organisations with corporate structure: copywriting teams that craft the messages, technicians managing the infrastructure, operators handling conversations with victims and collection managers moving money through cryptocurrency or mule accounts.

AI has transformed their operational capacity. Language models allow them to personalise messages at scale — adapting tone, context and content to each potential victim without manual intervention for each case. A message that previously required manual drafting is now generated in seconds, personalised with the victim's name, their bank or their mobile operator.

The result is a fraud industry that operates on the same efficiency principles as any digital marketing company: audience segmentation, message personalisation, conversion rate optimisation. Except in this case, the "conversion" is theft.

The 2026 World Cup: the latest hook

Major events with mass audiences never go unnoticed by scammers, and the 2026 World Cup is no exception. Kaspersky has documented several active campaigns exploiting interest in the tournament:

Fake ticket sales websites: Sites that replicate the official FIFA 2026 colour scheme and offer tickets at competitive prices. After completing the registration and payment process, the victim receives no tickets — but the attackers obtain their bank card details and personal information.

The $500,000 "prize" scam: Email and WhatsApp campaigns in which attackers inform the victim that they have "won" a $500,000 grant to cover tickets, flights and accommodation at the World Cup. To claim the prize, the victim must contact an "official representative" — who is in reality the scam operator.

Fake official representative emails: Messages impersonating tournament representatives about decisions from dispute resolution chambers, with links leading to credential-harvesting pages.

Merchandise spam: Campaigns selling counterfeit official products that in some cases include malicious attachments or redirect to data theft sites.

The pattern is identical to any other messaging scam — only the hook changes. The World Cup provides the trust context: millions of people are expecting news about tickets, draws and related events. That expectation is the fuel for fraud.

Why messaging is the perfect channel for fraud

The Kaspersky report identifies three structural characteristics of messaging apps that make them especially vulnerable:

Speed and immediacy: Messaging is designed for fast responses. The instinct in a chat is to reply, not to analyse. Scammers exploit exactly that dynamic — a message demanding immediate action in a channel where quick responses are the norm.

Inherited trust: WhatsApp, Telegram and SMS carry a level of trust associated with the channel that email lost years ago. A WhatsApp message is perceived as more personal and less likely to be fraud than an email. The cartels know this and have migrated there.

Difficulty of verification: Unlike email, where you can inspect the technical headers of the message, verifying the origin of a message in a messaging app is much harder for the average user. There is no equivalent of SPF or DKIM in WhatsApp.

The most revealing data point in the report: 99% of scam victims say they no longer trust any incoming notifications on messaging channels. This is not a drift in consumer behaviour — it is a near-total collapse of confidence in channels that brands have spent years using as a direct line to their customers.

Warning signs in fraudulent messages

Regardless of the hook used — World Cup tickets, a retained parcel, a bank alert, a job offer — fraudulent messages share a recognisable pattern of signals:

How to analyse a suspicious SMS or WhatsApp message

The ORTSLAB engine includes a dedicated forensic analyser for SMS and WhatsApp that detects the scam cartel patterns documented by Kaspersky: brand impersonation via alphanumeric alias, links to external domains, URL shorteners, suspicious international numbers, social engineering patterns and homoglyphs in URLs.

If you receive a suspicious message related to the World Cup, a bank, a mobile operator or any official body, paste it into the ORTSLAB scanner before clicking any link.

If you need to document a messaging scam for a formal complaint or legal proceedings, Oscar Orts — a certified judicial computer expert — issues forensic reports on digital fraud with full legal validity.