STOCK TITAN

Gen Half-Year Threat Report: Attackers are Moving Closer to the Systems People Trust

(Neutral)
(Neutral)
Tags

Gen (NASDAQ: GEN) released its H1 2026 Threat Report, showing attackers increasingly exploit trusted digital experiences instead of obvious malware or technical exploits. According to Gen, scams and fraud are increasingly delivered via booking platforms, messaging apps, software update channels, financial services, and AI agent workflows that people already trust.

Key telemetry highlights include 114.2 million e‑shop scam attacks blocked (up 109%), a 387% rise in government impersonation scams, over 304 million scam-ad impressions in the EU and UK in under a month, and roughly 1.9 billion tracking attempts blocked. Gen also reports a 628.1% increase in Norton and LifeLock breach notification alerts with attributed leak sources to 3.3 million (over 10 million total notifications sent) and a 734% increase in bank account activity alerts. The report identifies agentic AI as an emerging frontier, with Gen’s Sage platform detecting high-risk AI agent behaviors such as running dangerous commands, opening remote channels, downloading and executing code, and creating persistent remote access.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

News Market Reaction – GEN

-0.45%
-0.45% Session close to close

In the Jul 15 session, GEN declined 0.45%, reflecting a mild negative market reaction.

Data tracked by StockTitan Argus on the day of publication.

Market Context

Set against low short-interest readings and recent net insider selling over the last 90 days, this t...
Analysis

Set against low short-interest readings and recent net insider selling over the last 90 days, this threat-report publication fits a pattern of frequent consumer security updates where past price reactions have been mixed. Investors may watch how effectively Gen monetizes rising scam and breach volumes without triggering governance or dilution concerns.

Key Figures

E-shop scam attacks blocked: 114.2 million E-shop scam attack increase: 109% Government impersonation scam increase: 387% +5 more
8 metrics
E-shop scam attacks blocked 114.2 million H1 2026, Gen telemetry on fake online stores
E-shop scam attack increase 109% Growth in e-shop scam attacks over last six months
Government impersonation scam increase 387% Rise in scams impersonating government entities
Family impersonation scam increase 454% Increase in family impersonation scams over last six months
Tech support scam attacks blocked 20.3 million Attempts to gain remote device or financial access
Scam-ad impressions identified 304 million+ EU and UK, in less than one month
Tracking attempts blocked 1.9 billion Online tracking attempts blocked during H1 2026
Breach notification alerts 3.3 million Norton and LifeLock alerts in H1 2026, up 628.1%

Historical Context

5 past events · Latest: Jun 30 (Positive)
Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Jun 30 AI product integration Positive -0.6% Norton Genie scam detector integrated directly into Claude for real-time analysis.
Jun 18 Consumer survey release Neutral -0.9% MoneyLion survey on summer 2026 financial stress across U.S. adults and Gen Z.
Jun 05 Scam campaign launch Positive -0.9% Norton launched 2026 Scam Free Summer campaign and Summer Scam Forecast.
Jun 04 AI assistant beta Positive +0.1% External beta of Norton Family Assistant, a secure AI agent for families.
May 26 Marketing giveaway Positive -0.2% MoneyLion Summer Break Giveaway offering daily $500 awards to consumers.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

Recent product and campaign headlines have often been followed by flat to mildly negative next‑day moves, indicating frequent divergence between news tone and price reaction.

Key Terms

reverse shell, agentic ai, remote command channel, ssh key, +1 more
5 terms
reverse shell technical
"AI agents, running with permissions the user had already granted, were stopped before executing a reverse shell"
A reverse shell is a type of unauthorized remote access where a compromised computer opens an outgoing connection to an attacker’s system and provides a command-line session, allowing the attacker to run commands as if sitting at the machine. It matters to investors because reverse shells are a common technique in cyberattacks that can lead to data theft, operational disruption, regulatory fines, and reputational damage—like an insider opening a door that lets intruders control parts of a company’s operations.
agentic ai technical
"The report also identifies agentic AI as an emerging security frontier."
Agentic AI refers to computer systems that can make their own decisions and take actions without needing someone to tell them what to do each time. It's like giving a robot a degree of independence to solve problems or achieve goals on its own, which matters because it could change how we work and interact with technology in everyday life.
remote command channel technical
"Attempting to open a remote command channel, which could let an attacker control the system"
A remote command channel is a communication pathway that lets someone or some program send instructions to a computer, server, or device from a different location. Think of it like a TV remote for IT systems: it can be used for legitimate tasks such as maintenance and updates or for unauthorized control in a cyberattack, so its presence and security affect operational continuity, regulatory compliance, and technological risk for businesses.
ssh key technical
"Creating persistent remote access, such as adding a trusted SSH key"
A ssh key is a pair of cryptographic keys used to securely authenticate a user or system when connecting to a remote computer over a network. Think of it as a uniquely coded lock and matching key that lets authorized machines log in without a password; it matters to investors because SSH keys protect access to corporate servers, trading systems, and sensitive data, affecting operational security and the risk of breaches.
breach notification technical
"Norton and LifeLock breach notification alerts with attributed leak sources increased 628.1%"
A breach notification is a formal public or regulatory notice issued when sensitive data or systems have been accessed, disclosed, lost, or otherwise compromised. It explains what was exposed, who is affected, and what steps the organization is taking, like a public bulletin after a security incident. Investors track these notices because they signal potential legal, regulatory, financial and reputational consequences that can affect revenue, costs and share value.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

New research finds cybercriminals are increasingly exploiting trusted digital experiences rather than relying on obvious malware or technical exploits

TEMPE, Ariz. and PRAGUE, July 15, 2026 /PRNewswire/ -- Gen (NASDAQ: GEN) today published its H1 2026 Threat Report to help people understand what cyber threats are emerging and what risks are shaping digital life today. A common thread runs through the report: attackers are moving closer to the trusted parts of digital life. Not only are they sending malicious links or dropping malware, they're also abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.

Gen Digital H1 2026 Threat Report

Trust Has Become the New Attack Surface
The Threat Report's central finding is a shift in how attacks work. The most effective threats in the first half of 2026 did not rely on technical exploits or obvious deception, they succeeded because they were hard to distinguish from normal digital life. Scams arrived through hotel booking platforms, referencing a real reservation. WhatsApp accounts were compromised not through stolen passwords but by tricking people into approving an attacker's browser as a linked device. Fraud flowed through real, verified financial accounts whose owners were recruited on social media with promises of quick cash. And AI agents, running with permissions the user had already granted, were stopped before executing a reverse shell.

"The most effective attacks in the first half of 2026 didn't look like attacks," said Vita Santrucek, Chief Technology & Development Officer at Gen. "They arrived through booking platforms, family message threads, software update channels and AI agent workflows – all places people already trust. As attackers blend into everyday digital experiences, protection has to move closer to the moments where confidence is earned, exploited or broken."

Across scams, identity breaches, and privacy violations, the pattern is the same: the attack moved inside trusted systems before the danger became visible.

Threat Report Highlights
Gen telemetry and research findings show the following trends across key threat areas over the last six months:

  • 114.2 million e-shop scam attacks blocked, up 109% – highlighting the growing risk of fake online stores targeting shoppers
  • A 387% increase in government impersonation scams – showing criminals are increasingly exploiting trust in public institutions to steal money and information
  • A more than 454% increase in family impersonation scams, while separate "GhostPairing" activity showed how WhatsApp's linked-device feature can be abused to gain persistent access to an account and allow people to impersonate loved ones
  • 20.3 million tech support scam attacks blocked – reflecting continued attempts to trick people into giving scammers remote access to their devices or financial information
  • More than 304 million scam-ad impressions identified across the EU and UK in less than one month, underscoring how easily fraudulent ads can reach people
  • Roughly 1.9 billion tracking attempts blocked during H1 2026 – demonstrating the scale of online tracking that can erode consumer privacy
  • Norton and LifeLock breach notification alerts with attributed leak sources increased 628.1% up to 3.3 million, with more than 10 million breach notifications sent in total – proving more people's personal information is being exposed in data breaches
  • Bank account activity alerts increased 734% – reflecting both expanding monitoring coverage and a sharp rise in flagged financial activity
  • 1 million web skimming attacks blocked, up 212% – showing how attackers continued to target checkout flows where users already expect to enter payment details
  • More than 15.7 million breached records containing email addresses identified, giving cybercriminals more opportunities to target consumers with phishing, scams, and account takeover attempts

The report also identifies agentic AI as an emerging security frontier. As AI systems gain the ability to browse, install software, access files, connect to services and take action on behalf of users, attackers are increasingly targeting the permissions and trust these systems rely on. Early telemetry from Sage, Gen's agentic security platform behind features like Norton and Avast's AI Agent Protection, found the most common high-risk AI agent behaviors involved:

  1. Trying to run dangerous system commands
  2. Attempting to open a remote command channel, which could let an attacker control the system
  3. Downloading and running code from the internet
  4. Reading credential files without authorization
  5. Creating persistent remote access, such as adding a trusted SSH key
  6. Working to override the agent's instructions

The full Gen H1 2026 Threat Report is available at https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026 

About Gen
Gen (NASDAQ: GEN) is a global company dedicated to powering Digital Freedom through its trusted consumer brands including Norton, Avast, LifeLock, MoneyLion and more. The Gen family of consumer brands is rooted in providing financial empowerment and cyber safety for the first digital generations. Today, Gen empowers people to live their digital lives safely, privately and confidently for generations to come. Gen brings award-winning products and services in cybersecurity, online privacy, identity protection and financial wellness to nearly 500 million users in more than 150 countries. Learn more at GenDigital.com.

Media Contact:
Brittany Posey
press@gendigital.com

 

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/gen-half-year-threat-report-attackers-are-moving-closer-to-the-systems-people-trust-302826372.html

SOURCE Gen Digital Inc.

FAQ

What is the focus of Gen (NASDAQ: GEN) H1 2026 Threat Report?

Gen’s H1 2026 Threat Report focuses on how attackers exploit trusted digital experiences instead of obvious malware. According to Gen, threats increasingly abuse booking platforms, messaging apps, update systems, brands, financial accounts, advertising platforms, and AI agent workflows that people already use and trust.

How many scam and tracking attempts did Gen block in H1 2026?

Gen blocked 114.2 million e-shop scam attacks and about 1.9 billion tracking attempts in H1 2026. According to Gen, it also identified more than 304 million scam-ad impressions across the EU and UK in under one month, underscoring large-scale exposure to fraudulent content and tracking.

What did Gen report about Norton and LifeLock breach notifications in 2026?

Gen reported Norton and LifeLock breach notification alerts with attributed leak sources rose 628.1% to 3.3 million in H1 2026. According to Gen, more than 10 million breach notifications were sent in total, indicating more people’s personal information is being exposed in data breaches.

How are bank accounts and payment flows being targeted according to Gen’s H1 2026 report?

Gen observed a 734% increase in bank account activity alerts and blocked 1 million web skimming attacks, up 212%. According to Gen, attackers increasingly target checkout flows and use real, verified financial accounts to route fraud, often recruiting account owners through social media.

What risks from agentic AI did Gen highlight in its H1 2026 Threat Report?

Gen highlighted agentic AI as an emerging security frontier, where attackers target permissions and trust granted to AI systems. According to Gen, telemetry from its Sage platform shows risky behaviors like running dangerous commands, opening remote channels, downloading code, reading credentials, and creating persistent remote access.

Where can investors and users access Gen’s H1 2026 Threat Report for GEN?

Gen’s full H1 2026 Threat Report is available on its website at the specified insights and reports URL. According to Gen, the report details telemetry trends, scam statistics, privacy tracking figures, and emerging risks around agentic AI for consumers and organizations to review.