Fraud is becoming harder to distinguish from legitimate digital activity. AI-generated content is making scams more convincing, major events are creating new opportunities for attackers, and coordinated attacks can build beneath otherwise healthy transaction volumes. Sift’s Q3 2026 Digital Trust Index, AI Scams, Peak Events, and the Cost of a Slow Response, examines how these trends are changing the fraud landscape and what businesses need to watch for as consumer activity shifts.
More than half of consumers have encountered a scam using AI-generated images or video, yet only 36% feel very or extremely confident they could identify one. At the same time, fraud pressure is concentrating around high-volume events and, in some cases, building outside expected peaks. Together, the data shows a fraud landscape that is increasingly difficult for both consumers and businesses to distinguish from legitimate digital activity.
AI Scams Are Outpacing Consumer Confidence
Among consumers who use social media or messaging apps, 53% have encountered a scam using AI-generated images or video. Retailers and e-commerce brands were impersonated most often, at 40%, followed by celebrities or influencers at 39%, and customer support agents at 30%. For businesses, these scams can create disputes, support costs, and lost trust even when the interaction happens entirely outside the company’s own platform.
Consumers are also encountering fraud methods more directly. Thirty-seven percent have seen posts, groups, or channels that teach, sell, or share methods for committing online fraud, while 24% have tried a social media “hack” to exploit a refund, discount, or free-item policy. Yet, only 36% feel very or extremely confident they can spot AI-generated images, video, or text used in a scam, leaving businesses with a growing gap between how convincing scams can be and how confident consumers are in identifying them.
Consumers are taking precautions themselves, led by monitoring bank or card statements, avoiding links from social or messaging apps, and enabling two-factor or multi-factor authentication. But as synthetic content becomes easier to produce, businesses can’t rely on customers to identify every threat themselves.
Peak Events Create More Places for Fraud to Hide
Consumer spending clusters around predictable periods, with 64% saying they spend the most during the holiday and New Year season, 37% during summer, and 25% during back-to-school. Those surges create more legitimate traffic for attackers to blend into, but the highest-risk period varies significantly by industry. Across the Sift Global Data Network, the highest overall fraud-pressure day over the past year was May 14, 2025, while industry-specific peaks ranged from March through June 2026.
Major events can create especially concentrated opportunities. Ahead of this year’s World Cup, iGaming’s payment fraud attack rate grew nearly ninefold year over year, while 32% of consumers said they bet more money or used an iGaming or prediction market platform more frequently during a high-volume event. In Travel & Ticketing, Sift observed Telegram channels impersonating travel-booking and FIFA ticketing services and advertising discounts of up to 50%, showing how event-driven fraud can extend beyond the transaction itself.
But not every attack follows a predictable calendar. In Software & Services, the payment fraud attack rate rose from 2.7% in Q1 2026 to 3.8% in Q2, and one design and creative tools platform recorded 58 critical anomalies across more than 41 consecutive days. Fraud teams need to prepare for known peaks without assuming that activity outside those windows is necessarily normal.
Topline Improvement Can Hide Concentrated Attacks
Across the Sift Global Data Network, the payment fraud attack rate fell 14% year over year to 2.8% in Q2 2026, while the manual review rate declined 13.5% quarter over quarter to 2.1%. But those network-wide improvements don’t show where risk is building at the merchant level. Over six weeks of anomaly monitoring across nine Sift merchants, Sift detected 129 critical anomalies, 82% of which matched a BIN-attack pattern.
At one global fashion marketplace, 47 critical anomalies occurred across 11 consecutive days, all tied to a BIN-attack pattern spanning 34 distinct BINs. At another merchant, card-testing activity appeared across storefronts in six countries over nearly four weeks. In both cases, the individual transactions could look ordinary; the pattern emerged only when teams connected activity across payment instruments, accounts, order values, geography, and time.
The cost of missing or inaccurately blocking transactions also varies significantly by industry. Average order value across the Sift Global Data Network increased 52% year over year to $128, ranging from $14 in Food & Delivery to $391 in Travel & Ticketing, while the average cost of a false positive was $124. Fraud teams therefore need to account for both the cost of fraud getting through and the legitimate revenue lost when controls block the wrong customers.
Fraud Response Is Now a Customer Retention Strategy
The consequences of fraud extend beyond the immediate incident. Fifty-eight percent of consumers say learning that a company experienced a large-scale fraud attack would decrease their trust, while 47% have stopped using or reduced their use of a company after a fraud experience, including 26% who left entirely. At that scale, fraud prevention and customer retention are closely connected.
How a company responds can determine whether that trust recovers. Seventy-three percent of consumers say a clear explanation of what went wrong improves their perception of a company, while 71% say proactive outreach improves it. By contrast, 69% say vague or incomplete explanations worsen their perception, and 59% say the same when resolution takes more than a week.
For fraud and trust teams, the data points toward a more connected approach: understand what normal activity looks like before a peak event, monitor for coordinated attacks during and after it, and connect signals across the customer journey rather than evaluating transactions in isolation. Just as importantly, make incident response part of the fraud strategy itself. Customers want to know what happened, what the company is doing about it, and what comes next.
For more insights into the latest fraud trends, read Sift’s Q3 2026 Digital Trust Index: AI Scams, Peak Events, and the Cost of a Slow Response.





