Fake Data Breach Emails on the Rise, Cybersecurity Experts Warn

Fake Data Breach Emails on the Rise, Cybersecurity Experts Warn

Fake Data Breach Emails on the Rise, Cybersecurity Experts Warn

https://www.tovima.com/society/fake-data-breach-emails-on-the-rise-cybersecurity-experts-warn/

Publish Date: 2026-05-28 00:41:00

Source Domain: www.tovima.com

Μake us preferred on Google

With reports of data breaches becoming more frequent, cybersecurity experts are warning that criminals are increasingly using fake breach notifications to deceive unsuspecting users.

What was once considered a rare occurrence has become almost routine. According to the figures cited in the report, 3,322 data breach incidents were recorded in the United States last year, affecting around 280 million people who received notification emails. In Europe, daily data breach incidents increased by 22% year-on-year in 2025, reaching an average of 443 cases per day.

The growing volume of legitimate breach alerts has created an opportunity for cybercriminals. Because many users now expect to receive such notifications, fraudulent emails are less likely to raise suspicion and are more likely to be trusted.

Cybersecurity specialist Phil Muncaster of security company ESET emphasized that while genuine data breaches occur every day and should not be ignored, users should avoid reacting automatically and instead verify whether a notification is authentic before taking any action.

NEWSLETTER TABLE TALK

Never miss a story.
Subscribe now.

The most important news & topics every week in your inbox.

How the Scams Work

Experts identify two common tactics used in fake breach notification campaigns.

In some cases, scammers exploit the publicity surrounding a real data breach by sending counterfeit notifications that appear related to the incident. Victims who are already expecting communication from an affected company may be more likely to believe the message.

In other cases, cybercriminals invent an entirely fictitious breach and create convincing emails that appear to originate from a trusted organization, a company’s IT department, or another legitimate source.

To make these messages more convincing, attackers increasingly rely on phishing kits and artificial intelligence tools. AI can generate highly realistic emails in the recipient’s language,…

Source