Fake ads were the top cyber threat consumers faced last year, with deepfake scams surging on social media, and over 45 million fake shop attacks blocked, according to the latest analysis from Gen.
The cyber firm’s Q4 2025 Threat Report highlights a shift from sophisticated hacks to the exploitation of ordinary digital actions targeting browsers, social feeds, messaging apps, and money management tools.
Gen, the company behind Norton, Avast, and LifeLock, found that scammers are zeroing in on social platforms like Facebook and YouTube with fake shopping clicks, a tactic which saw a 62% increase over 2024 and accounted for two-thirds of all threats blocked on social media.
Likewise, Gen’s data shows that “malvertising”, fake advertisements, accounted for 41% of all attacks over the last quarter, with scam delivery increasingly indistinguishable from ordinary ads.
These malverts, which reports indicate may account for about $16 billion in Meta’s overall sales in 2024, are being exploited for a “first click” that eventually leads consumers to part with their money or credentials, with lures spread broadly across platforms, led by Facebook (77%), YouTube (13%) and Reddit (4%).
YouTube is also home to the most dangerous deepfakes, according to the report, with the platform seeing the largest share of blocked AI scam videos at 65%, followed far behind by Facebook (11%) and X (0.5%), with most blocked content tied to financial, investment, and cryptocurrency lures.
Gen said it had detected more than 159,000 unique deepfake video scam attempts over Q4, with attackers using cloned images and voices, stock footage, and trusted brands to convince victims to move their money.
The study found that criminals are also pushing victims to move back and forth between platforms, asking them to complete small, familiar actions that, when put together, greatly expand an attack surface.
Recommended reading
- Too Authentic to be Synthetic: The Psychology Behind AI Voice Scams
- Deepfake Fraud Explodes 2,000% In Three Years
- Darcula Phishing Scam Claims 800K+ Victims
For example, some campaigns started on desktop with fake tutorial pages, then pushed victims to scan the screen with their phone, shifting the next steps onto mobile, where permissions, sideloading, or verification were more likely.
Others moved in the opposite direction. GhostPairing attacks, for instance, see victims enter a numeric code in WhatsApp on their phone, unknowingly linking an attacker-controlled browser as a trusted device that can spread further attacks through a phone’s contacts.
“Increasingly throughout 2025, scams did not announce themselves as threats. They blended into everyday digital routines,” said Siggi Stefnisson, Cyber Safety CTO at Gen. “Attackers leaned on familiar platforms, trusted interfaces, and automated persuasion, then scaled those tactics across devices and channels.”





