Intelligence analysis: February - April 2026
5 minute read
Fraud is no longer a peripheral risk. It is now a primary threat affecting citizens, customers, employees, public bodies, banks, digital platforms and law enforcement agencies at the same time.
This month, we released our Quarter Fraud Intelligence report. Between February and April 2026, PORGiESOFT Security’s threat intelligence monitoring tracked and analysed hundreds of news signals across fraud and scam typologies, spanning over 12 countries. The picture that emerged was not simply one of increased fraud volume. It showed a more coordinated, more repeatable and more industrialised model of social engineering.
The defining feature of this quarter was not technical complexity. It was the exploitation of trust at scale. Threat actors continued to weaponise the everyday moments people rely on: a call from someone claiming to be the police, a courier arriving at the door, a QR code on a parking meter, a ticket resale listing, or a job interview that appears legitimate. These attacks succeed because they are designed to look normal, urgent and familiar.
Five Emerging Fraud Trends We Tracked This quarter
Our analysis focused on five key typologies observed globally during the reporting period:
- Police impersonation
- Courier fraud
- Ticket scams
- Fake QR code scams
- Employment scams
Each typology showed signs of cross-border repeatability, with similar playbooks adapted to local authorities, brands, languages and social conditions.
1. Police Impersonation: Authority as the Attack Vector
Police and authority impersonation remained one of the dominant fraud typologies this quarter. Campaigns were observed across the US, UK, Canada, New Zealand, Sri Lanka and the UAE.
The tactic is powerful because it exploits the psychological imbalance between the citizen and the state. Victims are contacted by someone claiming to be a police officer, federal agent, immigration officer, bank fraud team or investigator. They are then pressured into complying with instructions under the threat of legal consequences, arrest, investigation or account compromise.
Common tactics included references to bank cards, PINs, fraudulent banknotes, foreign currency, FBI investigations, immigration status, undercover operations and “evidence collection”.
People most at risk included elderly residents, homeowners, bank customers, mobile users and immigrant communities. In several cases, the goal was to move victims from fear into immediate action before they could verify the story.
2. Courier Fraud: The Physical Extraction Layer
Courier fraud continued to operate closely alongside police and bank impersonation. In this model, the phone call establishes credibility and compliance. The courier then completes the extraction.
Victims are coached to withdraw cash, hand over bank cards, provide PINs or package valuables for collection. Fraudsters may claim that the victim’s bank card has been compromised, that cash is needed for an investigation, or that the courier is collecting evidence on behalf of police or a bank fraud team.
This quarter’s reporting showed courier fraud affecting victims in the UK, US and Canada, with estimated losses ranging from thousands of dollars to hundreds of thousands in some incidents.
The threat is particularly difficult because it blends digital deception with a physical handover. It also abuses the public’s familiarity with modern courier and delivery services. In an economy where parcels, collections and doorstep interactions are normal, the arrival of a courier may not feel suspicious until it is too late.
3. Ticket Scams: Fraud Follows the Public Events Calendar
Ticket fraud surged around major cultural and sporting events, including Coachella, the FIFA World Cup and BTS-related events in Seoul.
Threat actors exploited scarcity, fan emotion and urgency. Fake or overpriced tickets were promoted through social media, WhatsApp groups, resale pages and third-party websites. In some cases, victims bought counterfeit passes. In others, the same digital ticket was resold multiple times.
This typology reflects a wider intelligence lesson: the fraudster calendar mirrors the public events calendar. When demand spikes, scammers move quickly. Concerts, tournaments, festivals, school events and theatre shows all create the same conditions: emotional investment, limited supply and pressure to act before someone else buys.
By the time many victims discover the fraud, often at the gate or after the event has passed, recovery is difficult.
4. Fake QR Codes: Low-friction Technology, High-harm
Fake QR code scams expanded globally this quarter. Reports included QR stickers placed on parking machines, fake government letters, fake windshield notices, smishing messages and fraudulent payment portals.
The risk is not the QR code itself. The risk is the trust users place in the context around it.
A QR code on a parking meter, council notice, bike rental stand or traffic violation letter may appear legitimate because it is physically attached to a real-world process. Fraudsters exploit that trust by overlaying official QR codes or creating fake notices that redirect victims to scam websites.
Motorists, commuters, cyclists, tourists and mobile users were among the groups most exposed. The estimated losses ranged from small payments to much higher amounts where card details or personal information were harvested.
The lesson for organisations is clear: public infrastructure is now part of the fraud attack surface.
5. Employment Scams: Recruitment - An Emerging Primary Attack Surface
Employment fraud showed some of the most significant evolution this quarter. The normalisation of remote hiring has created a world where a candidate can apply, interview, receive forms and accept an offer without ever meeting a verified person face to face.
Threat actors exploited that shift through fake Google Forms, recruiter impersonation, fake technical interviews, fake calendar invites, social media job adverts and messaging app migration from TikTok to WhatsApp or Telegram.
The risk affected job seekers, graduates, young adults, redundant workers and software developers. In the most advanced cases, fake interviews were linked to malware delivery and state-sponsored activity. This confirms that recruitment fraud is no longer only a consumer scam issue. It is also a cyber, HR, security and national resilience issue.
For organisations, the threat is two-sided. Candidates can be defrauded by fake employers, while companies can also be impersonated by criminals using their brand to harvest credentials, payments or personal data.
What we learnt this quarter
- The biggest lesson from the quarter is that trust is the attack surface. Fraudsters are not always trying to hack systems. They are trying to hack assumptions. They exploit the belief that a police officer is genuine, a courier is legitimate, a QR code is safe, a job advert is real or a ticket seller is trustworthy
- The second lesson is that AI is already operational. It is not a distant or theoretical risk. AI-generated personas, deepfake-enabled deception and more convincing recruitment scams are already appearing in the fraud landscape
- The third lesson is that fraud is increasingly event-driven. Public events, labour market pressure, travel demand, ticket releases and economic uncertainty create moments of vulnerability that threat actors can anticipate
- The final lesson is that vulnerability is situational. The victim profile this quarter included elderly homeowners, teenagers, sports fans, immigrants, bank customers, job seekers and software developers. Fraud does not affect one demographic. It adapts to pressure, context and opportunity
What organisations should do next
Fraud prevention now requires a more intelligence-led model. Static awareness content and annual training are not enough when fraud tactics change weekly.
Fraud, risk, security, HR, customer protection, communications and policy teams should work from the same intelligence picture. This means monitoring emerging typologies, mapping affected groups, preparing event-led alerts, and treating fraud as a cross-functional operational risk rather than a narrow financial crime problem.
Organisations should also review the points where trust is created: customer messages, staff recruitment, payment journeys, QR-enabled services, public notices, social media pages and third-party channels.
Where possible, teams should use real examples, recent incidents and explainable fraud intelligence to help people understand not just that something is a scam, but why it is suspicious.
Outlook
The fraud landscape is becoming faster, more adaptive and more international. The typologies observed between February and April 2026 show that social engineering is being industrialised across borders, sectors and digital channels.
The response must therefore be proactive rather than reactive.
Fraud intelligence should help organisations anticipate the next scam wave before victims come forward. It should support safer products, better customer protection, stronger public awareness and more coordinated operational response. At PORGiESOFT Security, we believe smarter awareness leads to safer products, safer services and safer people.





