Social media phishing statistics for 2026 show a threat that has moved well beyond fake friend requests and obvious spelling mistakes. Criminals now use artificial intelligence to write flawless, personalised messages, hide malicious links inside QR codes, and build convincing fake profiles on LinkedIn, Facebook and Instagram to steal credentials and money. This article sets out the current social media phishing statistics for the UK and Ireland, covering which platforms are most targeted, how AI has changed the tactics used, what these scams are costing businesses, and what the new Online Safety Act means for how these scams are reported and removed. We will also cover the practical steps you can take to protect yourself and your accounts.
Understanding these social media phishing statistics matters because the platforms themselves have become the starting point for a growing share of everyday fraud, not just a secondary channel used after an initial email attempt. A message that arrives through a trusted-looking profile, a comment thread, or a direct message carries a level of built-in credibility that a stranger’s email never will, and criminals have adapted their entire approach around that fact.
Table of Contents
Key Findings: Social Media Phishing Statistics in 2026
Before going into detail, here are the headline social media phishing statistics from the most recent UK data available.
- The UK’s National Cyber Security Centre (NCSC) received more than 10.9 million reports through its Suspicious Email Reporting Service in the year to August 2025, taking the running total past 45 million reports since the service launched in April 2020.
- The NCSC’s Takedown Service removed over 1.2 million phishing and scam campaigns in the same period, with half taken down within an hour of detection.
- UK Finance recorded £629.3 million stolen through fraud and scams in the first half of 2025 alone, a rise of 3% on the same period the year before, with 66% of authorised push payment fraud cases starting online.
- Reports of QR code phishing, known as quishing, to Action Fraud rose from around 100 in 2019 to 1,386 in a single year, according to reporting reviewed by TechRadar.
- Check Point Research’s Q1 2026 Brand Phishing Report found LinkedIn was the fifth most impersonated brand in phishing attempts globally, with social networks the second most targeted sector after technology companies.
Ireland tells a more mixed story. An Garda Síochána’s provisional 2025 figures show overall fraud offences up 137% compared with 2024, driven largely by deception and online shopping fraud, yet reports specifically categorised as phishing, smishing and vishing actually fell by 11% over the same period, suggesting many social media-related scams are now being recorded under other fraud categories rather than as phishing itself.
Platform-Specific Phishing Success Rates
Not every social media platform faces the same level of risk, and the types of scams vary from one platform to the next. Understanding which platforms attackers favour, and why, helps explain where the greatest exposure lies for individuals and businesses alike.
LinkedIn: A Favoured Target for Professional Impersonation
LinkedIn has repeatedly featured among the most impersonated brands in global phishing campaigns. Check Point Research’s Q1 2026 data placed LinkedIn fifth overall, behind Microsoft, Apple, Google and Amazon, with social networks as a sector ranking second only to technology companies for brand impersonation. The professional nature of LinkedIn works in an attacker’s favour: job titles, employers and connections are all publicly visible, which allows criminals to build detailed, believable profiles of potential victims before making contact. Fake recruiter messages, fraudulent job offers, and impersonated executive accounts used to request payments are among the most common tactics seen on the platform.
These social media phishing statistics also reflect a wider pattern in how criminals research their targets. A public profile that lists an employer, a job title, recent projects and a network of named colleagues gives an attacker everything needed to draft a message that references real people and real events, which is precisely what makes LinkedIn-based scams so difficult to spot compared with a generic email.
Instagram, Facebook and the Rise of Quishing
Instagram and Facebook remain popular targets because of their scale and the amount of personal information users share through posts, photos and direct messages. Alongside traditional fake links and cloned login pages, QR code phishing, or quishing, has become a fast-growing tactic across social platforms and the wider internet. Action Fraud reporting reviewed by TechRadar shows quishing reports climbing from around 100 in 2019 to 1,386 in a recent 12-month period, with scammers placing fraudulent QR codes over legitimate ones on parking machines and posters, then linking them from social posts or messages to widen their reach.
Fake giveaway posts and cloned brand pages remain common on both platforms, too, often promising a prize or discount in exchange for personal details or a small upfront payment. Because Instagram and Facebook rely heavily on visual content, these scams are frequently harder to distinguish from genuine advertising at a glance, which is part of why quishing has spread so quickly on both networks.
X and WhatsApp: Direct Messaging as an Entry Point
X (formerly Twitter) and WhatsApp are increasingly used for direct, one-to-one phishing attempts rather than mass messaging. On X, impersonation of brands and public accounts remains a common tactic, while WhatsApp’s private, trusted nature makes it an effective channel for scammers posing as a friend, family member, or colleague in urgent need of money. Reviewing your privacy settings and account security on these platforms is one of the simplest ways to reduce your exposure, and our guide to privacy settings on social media covers the specific steps for each major platform.
The AI Revolution: How Generative AI Has Changed Social Media Phishing Statistics
Generative AI has changed the shape of social media phishing statistics more than any other single factor over the past two years. Where phishing messages were once identifiable by poor grammar and awkward phrasing, AI tools now allow criminals to produce fluent, personalised messages in any language, at scale and at almost no cost.
The NCSC’s Annual Review 2025 confirms that threat actors have used AI, including large language models, to improve the efficiency of their attacks, including generating fully automated spear-phishing campaigns. On social media specifically, this means scammers can now scrape a target’s public posts, job history, and connections, then generate a tailored message referencing real colleagues, real events, or a recent post, all without any human writing a single word of it. This removes the obvious red flags that awareness training has spent years teaching people to spot.
The practical effect on social media phishing statistics is that volume and quality are no longer a trade-off for attackers. A criminal running a manual campaign once had to choose between sending thousands of generic messages or a handful of carefully researched ones. AI tools have removed that constraint, allowing convincing, tailored messages to be generated automatically for every target on a list, which helps explain why reporting volumes to services like the NCSC’s Suspicious Email Reporting Service have continued to climb even as public awareness of phishing has grown.
Deepfakes and Synthetic Media on Social Platforms
Beyond text, AI-generated audio and video, commonly known as deepfakes, are increasingly used to add credibility to social media scams. A cloned voice note or short video clip purporting to be from a trusted contact or public figure can be used to support a fraudulent request, particularly in investment scams and impersonation fraud that begin on social platforms before moving to messaging apps or phone calls. Ofcom’s own enforcement activity under the Online Safety Act has already addressed AI-generated deepfake content, underscoring how seriously the regulator now treats this category of harm.
For most individuals, the practical risk is lower than for public figures or senior executives, whose voices and likenesses are widely available online and therefore easier to clone convincingly. Even so, the same underlying principle applies across every case: a message should never be trusted purely because it looks or sounds like it came from someone familiar, and any request involving money or sensitive information deserves independent verification through a separate channel before acting on it.
Social Media Phishing Statistics: UK and Ireland Regional Focus
The UK and Ireland each have their own reporting bodies and legal frameworks for tackling phishing, and the data from each paints a slightly different picture of how the threat is evolving.
In the UK, the NCSC’s Suspicious Email Reporting Service and Takedown Service, between them, handled over 45 million reports and removed more than 1.2 million scam campaigns in the year covered by the NCSC’s Annual Review 2025, with half of all takedowns completed within an hour of detection. UK Finance’s half-year fraud report for 2025 recorded £629.3 million stolen through fraud and scams, alongside a 17% rise in confirmed fraud cases compared with the same period in 2024, giving a clear sense of scale even where individual social media platforms are not broken out separately in the published figures.
In Ireland, An Garda Síochána’s provisional 2025 figures show overall fraud offences rising sharply, up 137% on 2024, with online shopping and auction fraud increasing by 183% and deception offences by 273%. Reports specifically logged as phishing, smishing or vishing fell by 11% over the same period, which may reflect a shift in how frontline reports are categorised as fraud types increasingly blend social media contact, messaging apps and phone calls into a single scam.
The Impact of the UK Online Safety Act on Reporting
The Online Safety Act’s illegal content duties came into force on 17 March 2025, requiring social media platforms and other user-to-user services to risk-assess and take proportionate steps against illegal content, including fraud, which is listed as priority content under the Act. Ofcom, as the regulator, can fine non-compliant platforms up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.
This gives UK regulators a direct route to hold social media platforms accountable for the fraudulent content and fake profiles that enable phishing campaigns in the first place, rather than leaving enforcement solely to individual reporting through Action Fraud or the NCSC.
The Corporate Cost of Social Media Phishing
For businesses, the cost of a successful phishing attack that begins on social media rarely ends with a single stolen password. UK Finance’s data shows that 66% of authorised push payment fraud cases in the first half of 2025 started online, and while not all of this originates on social platforms specifically, impersonation of executives and colleagues on LinkedIn and other networks is a well-documented entry point for business email compromise style fraud, where a convincing message leads to a fraudulent payment request.
Beyond the direct financial loss, businesses incur the costs of investigating an incident, restoring affected accounts, and managing any reputational damage if customers or partners were targeted with a spoofed company profile. Fake company pages and cloned executive profiles can remain live for some time before they are reported and removed, during which they continue to be used to approach employees, customers or job applicants, compounding the eventual cost of the incident.
Our guide to preventing data breaches covers the wider steps organisations can take to reduce their exposure, many of which apply directly to social media accounts used for business purposes.
Psychological Triggers: Why People Still Click
Even with widespread awareness of phishing as a concept, people continue to click on malicious links and respond to fraudulent messages on social media. Understanding why helps explain why these scams remain so persistent despite years of warnings.
Urgency Versus Authority
Two of the most consistently effective psychological triggers in phishing are a sense of urgency and a false sense of authority. A message warning that an account will be suspended within hours, or one that appears to come from a manager, a bank or a well-known brand, short-circuits the normal pause-and-check instinct that might otherwise catch a scam. On social media specifically, this is compounded by the appearance of familiarity: a message from what looks like an existing connection or a verified-looking account carries an inherent trust that a message from an unknown email address would not.
This combination of urgency and borrowed trust is precisely why AI-personalised messages are so effective. A generic urgent message is easy to dismiss, but one that references a real project, a real mutual connection or a real recent event, delivered with genuine urgency, is far harder to pause and question in the moment, which is reflected in the continued rise in reports to UK reporting services even as public awareness of phishing as a general concept has grown.
Protecting Yourself and Your Organisation
Reducing your exposure to social media phishing does not require specialist tools, though it does require consistent habits applied across every platform you use.
Start by reviewing and tightening the privacy settings on each of your social media accounts, since limiting how much personal information is publicly visible reduces the material scammers can use to craft a convincing message. Our step-by-step guide to privacy settings on social media platforms walks through the specific settings to check on Facebook, Instagram, X and LinkedIn.
Enabling two-factor authentication on every account, being cautious of unsolicited messages or connection requests, and verifying any urgent request through a separate channel before acting on it are among the most effective everyday defences, and our broader guide on how to prevent cybercrime and avoid being a victim sets these out in more detail. If you use X specifically, our Twitter and X safety guide covers account protection features unique to that platform.
If you believe you have been targeted, do not click any links or scan any QR codes in the message. Change your password immediately, enable two-factor authentication if it is not already active, and report the message to the platform directly. In the UK, suspicious emails and scam attempts can be reported to the National Cyber Security Centre, which operates the Suspicious Email Reporting Service and can act to have malicious sites taken down. A wider background on how phishing fits into the broader picture of online crime is available in our guide to what cybercrime is.
Social media phishing statistics for 2026 show a threat that has become faster, more personalised and harder to spot by eye alone, driven largely by AI and the rise of tactics like quishing. The good news is that the fundamentals of protection have not changed: tighten your privacy settings, question unsolicited or urgent messages, and report anything suspicious rather than ignoring it. With UK regulators now able to hold platforms directly accountable under the Online Safety Act, the responsibility for tackling this problem no longer rests solely with individual users.
FAQs
Which social media platform has the most phishing?
Check Point Research’s Q1 2026 Brand Phishing Report found LinkedIn to be the fifth most impersonated brand overall, with social networks as a category ranking second only to technology companies for brand impersonation attempts.
What is quishing?
Quishing is phishing carried out using a QR code rather than a text link. Scammers place a fraudulent QR code over a legitimate one, or share one directly through a social media post or message, so that scanning it leads to a fake website designed to steal login or payment details.
How do I report social media phishing in the UK?
Report the message or profile directly to the platform first, then report any suspicious emails to the NCSC’s Suspicious Email Reporting Service. If you have lost money, report it to Action Fraud, or to Police Scotland if you are in Scotland.
Are deepfakes used in social media phishing?
Yes. AI-generated audio and video are increasingly used to add credibility to scams that begin on social platforms, particularly impersonation and investment fraud, though text-based messages remain the most common format overall.
Can a business be held liable for social media phishing linked to its platform?
Under the Online Safety Act, social media platforms have a legal duty to risk-assess and address illegal content, including fraud, and Ofcom can fine non-compliant platforms up to £18 million or 10% of global revenue.
What percentage of fraud starts online?
UK Finance’s half-year 2025 fraud report found that 66% of authorised push payment fraud cases started online, underlining how central digital channels, including social media, have become to modern fraud.