2026-06-08 · Google

Our latest fraud and scams advisory

securitycapital

read at source ↗ blog.google

Our latest fraud and scams advisory

Source: Google Date: 2026-06-08 URL: https://blog.google/innovation-and-ai/technology/safety-security/fraud-scams-advisory-june-2026/

Summary

Google’s June 2026 fraud advisory catalogs four scam categories gaining traction: adversary-in-the-middle phishing (including QR-code “quishing” and calendar-based lures that bypass MFA by stealing session cookies), AI-branded cryptocurrency investment fraud, malicious mobile finance apps that extort victims through stolen data, and “digital arrest” police impersonation scams targeting South Asian and Gulf diaspora communities. Google cites global fraud losses of roughly $580 billion for 2025, with US cryptocurrency fraud alone at $11 billion. Mitigations include Device Bound Session Credentials to harden cookie theft, post-install app behavior monitoring, and identity verification requirements for Android developers.

Implications

  • Fraud/safety. The AITM + session cookie pattern is the most technically significant item here — MFA bypass via cookie hijack doesn’t require a compromised endpoint, just a convincing pre-auth intercept. As AI lowers the cost of generating convincing phishing pages at scale, this attack surface grows faster than org-level MFA rollout can contain it.
  • AI-adoption-ROI discourse. “AI cryptocurrency investments” as a named scam category signals that the AI brand is now a primary trust vector for fraud, not a secondary one. Organizations pitching AI-enabled products to non-technical buyers now share reputational space with crypto grifters — a headwind for enterprise adoption narratives that hasn’t fully priced in.
  • Lab governance. Google framing its own AI tooling as a fraud-detection mechanism (predictive analytics, coordinated impersonation detection) while publishing the advisory is a soft governance move: it positions the platform as both the threat surface and the mitigation, which is a recurring pattern in platform-era safety discourse worth tracking for credibility.

← all signals