Trusting your gut is no longer enough
Nearly half of the surveyed Americans said they felt highly confident in their ability to spot online fraud. But when researchers tested their responses, the results showed a gap between confidence and skill.
In one test, 74% respondents failed to recognize a fake URL with a small typo that mimicked a real website. In another, 82% didn’t realize that both CAPTCHA prompts were fake.
Online fraud is harder to spot than it used to be. Many scams no longer contain the obvious spelling mistakes or awkward wording that people expect. Criminals now use AI to write convincing messages, copy trusted brands, personalize scams with breached data, and create fake websites that look real at a glance.
Americans are confident, but scams are getting harder to spot
Confidence can help people act quickly. Too much confidence can also make people skip basic checks that help keep them safer online.
NordVPN’s survey found that 71% of respondents believe common sense alone is enough to stay safe online. While common sense helps, it doesn’t always catch fake messages written with AI, fake login pages, links that lead to malicious websites, or scam calls that use personal details to sound real.
The survey also showed that scams are common, costly, and often underreported:
- 73% of respondents recently encountered a scam.
- 13% lost or nearly lost money to a scam.
- Only 17% reported the scam.
When people don’t report scams they encounter, platforms, banks, and law enforcement receive less information about active threats. Scammers can then keep using the same tactics for longer, often against new targets.
The survey also found that just over half of respondents would be more likely to trust a message if it included their real name and recent purchase history. Only less than a quarter said that kind of personalization would make them more suspicious. Scammers can exploit this trust because breached personal data can make fake messages feel familiar.
The more confident people feel, the more risk they may take
NordVPN’s research shows a pattern: People who feel more confident online can also take more risks. People who see themselves as highly aware of online risks or very tech savvy often assume they’re harder to fool. That belief can make them less cautious.
The same pattern appears in everyday security habits. For example, 51% of respondents reuse the same or similar passwords. People who felt confident online reused passwords more often, even though one breached password can put multiple accounts at risk. If criminals get a reused password from one breached account, they can try the same login details on email, banking, shopping, or social media accounts.
Links create a similar problem. Around half of the respondents had clicked potentially harmful links without verifying them first. Younger users were more likely to interact with risky links, while older users were generally more cautious.
The same age split appears in identity theft concerns. Among 18-24-year-olds, only 37% said they worry about identity theft, which made them the least concerned age group. Respondents aged 45 and older were more likely to worry about their online identities.
Why a polished website can still be a scam
Many people still judge websites by surface-level signs. A polished design, a familiar brand name, a padlock icon, or a “.com” domain can make a page feel trustworthy. Scammers know that.
A fake site can copy the look of a real brand. A phishing page can use a secure connection. A scam domain can introduce tiny spelling changes that are easy to miss. In NordVPN’s typosquatted URL test, 74% of respondents failed to spot the fake URL.
People also tend to trust websites they’ve used before. But 49% of respondents said they had received breach notifications from websites they once believed were safe.
That finding points to another problem — security fatigue. When trusted services suffer breaches, people can start to feel that staying safe online takes too much effort. Attackers exploit this reaction. They want people to click quickly, trust familiar-looking details, and move on without checking.
A traditional antivirus can’t catch every threat
Antivirus software can help detect and block viruses and other types of malware. Malware is software designed to damage devices, steal data, or spy on users. But many online threats no longer behave like traditional viruses.
A fake shopping website doesn’t need to infect your device to steal your card details. In a phishing scam, entering your password on a fake login page can be enough. Scammers can use personal information during a call to convince you to share a security code. A malicious link can lead to a login page that looks almost identical to the real one.
NordVPN’s research found that 47% of respondents rely on antivirus software to protect them from nearly all threats. Among users who describe themselves as “very tech savvy,” 40% say an antivirus is “all they need.”
People who treat antivirus software as a complete safety net may skip the checks that help them spot fake shopping websites, phishing links, and scam calls. Traditional antivirus software can help with known malware, but scams, phishing pages, malicious links, and exposed personal data often require broader protection.
What the next-gen antivirus does differently
NordVPN’s next-gen antivirus goes beyond traditional malware scanning. It helps protect users from dangerous websites, harmful files, phishing pages, and scam links before they cause damage.
According to NordVPN’s Consumer Cybersecurity Report 2026, NordVPN analyzes 12 million unique URLs every day. On average, it blocks 130,000 malicious pages daily before they can load for a user. In the first half of 2026, NordVPN also blocked more than 4.4 million phishing attempts.
Phishing is a common way criminals try to steal passwords, payment details, and personal information. These scams often copy well-known brands to make fake messages and websites look legitimate. NordVPN found that 99% of phishing attacks impersonate just 300 brands, with Microsoft, Roblox, Google, and Netflix among the most commonly copied.
Scammers also rely on familiar-looking web addresses. The “.com” domain appeared in 43.2% of intercepted scam cases, likely because many users associate “.com” websites with trust.
Personal details can make scams harder to spot. NordVPN’s dark web monitoring tools identified 8.4 million compromised accounts in 90 days. More than 47% of exposed records included physical addresses and full names. Criminals can use those details to make scam messages feel more personal and harder to dismiss.
Session hijacking is another concern. In session hijacking, criminals use stolen browser cookies to access accounts without needing the account password. Between January 1 and May 26, 2026, 94 billion cookies were exposed online. Around 1.2 billion of those were session cookies that attackers could use to access accounts and, in some cases, bypass multi-factor authentication.
The data shows why the “just don’t click suspicious links” advice is no longer enough. Good habits still matter, but users also need tools that can help block dangerous pages, flag phishing attempts, monitor exposed data, and reduce the risk of account theft.
Shaquille O’Neal took online protection to Times Square
NordVPN joined forces with Shaquille O’Neal to bring its “Go big on your online protection” message to Times Square on October 7, 2026.
Shaq is known for going big on the court, in business, and across pop culture. In this campaign, he helped NordVPN show why online protection needs to match the scale of today’s scams. His role also mirrored the idea behind a next-gen antivirus — blocking threats before they reach people.
The stunt turned cybersecurity into a live basketball challenge, where New Yorkers took shots against basketball pros. The court became a metaphor for online protection — the red basketball represented a digital threat, and every block showed how NordVPN’s next-gen antivirus helps stop threats before they can cause harm.
Times Square gave NordVPN a high-visibility setting to turn invisible digital threats into a public, easy-to-understand message. The stunt was built around the same issue highlighted in NordVPN’s research — many people feel confident online, even when scams are becoming harder to spot.
A scam link, phishing page, or fake message can be easy to underestimate until it asks you to click, log in, or share payment details. By turning digital threats into shots that had to be blocked, NordVPN showed why relying on instinct alone is no longer enough.
How to protect yourself
Security tools can’t replace careful behavior. But users shouldn’t have to spot every scam on their own. A stronger approach combines safer habits with tools that help block threats in the background.
Start with these steps:
- 1. Check links before you click. Look for misspellings, strange domains, and unexpected redirects. A familiar brand name doesn’t guarantee that a page is real.
- 2. Use strong, unique passwords. Don’t reuse passwords across accounts. A password manager can help you create and store secure logins.
- 3. Turn on multi-factor authentication. Multi-factor authentication adds a second login step, such as a code or app prompt. It can stop many account takeovers even if a password is exposed.
- 4. Treat personalized messages with caution. A message that includes your name or recent purchase details is not automatically trustworthy. Breached data can help scammers personalize fake messages.
- 5. Report scams. If you receive a scam message, report it to the platform, your bank, your phone carrier, or the relevant authority. Reporting helps other people and organizations respond faster.
- 6. Use next-gen security tools. NordVPN’s next-gen antivirus can help block malicious pages, phishing attempts, scam links, and harmful files before they reach you.
Online threats have changed, so protection needs to change too
Americans are not careless. Many are aware of online threats and want to avoid them. But NordVPN’s research shows that confidence doesn’t always match everyday behavior.
AI-powered scams can look polished. Fake websites can look familiar. Scam messages can use real personal details. Old habits and traditional antivirus software alone can leave gaps that attackers know how to exploit.
NordVPN’s next-gen antivirus helps close those gaps by giving users stronger protection against threats that are harder to spot at first sight. The smartest move isn’t to rely on instinct alone, but to give that instinct better backup.
Go big on your online protection.
Try NordVPN’s next-gen antivirus
Methodology
The survey findings in this article come from “Cyber confidence and cyber risks in the US — August 2026,” a nationally representative survey of 2,010 US internet users. The survey examined cybersecurity awareness, online habits, scam exposure, and vulnerability to AI-powered phishing attacks.
Fieldwork took place from August 17-26, 2026. The target group included US residents aged 18-74. The sample was nationally representative among internet users, with quotas for age, gender, and place of residence. Respondents were recruited through Cint panels.
NordVPN’s Consumer Cybersecurity Report is based on internal security signals analyzed by NordVPN experts and compared with relevant external threat intelligence sources. NordVPN analyzed the data at an aggregated level and did not use information that could be linked to individual users. The full methodology is available in the report opens in a new tab.
Access event materials: