Security1 distinct publisher3 min readUpdated
Malwarebytes reports seven in ten 18-to-22-year-olds met an AI-related scam last year, against half of the general population. The gap is widest on synthetic media.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Malwarebytes has published survey figures putting 70 percent of 18-to-22-year-olds as having experienced an AI-related scam in the past year, compared with half of the general population [1]. That is a 20 point gap, roughly 1.4 times the rate [2], and it runs against any awareness program that sorts risk by assumed digital fluency.
The company's own reading is exposure rather than carelessness. Malwarebytes argues that the platforms young people depend on for daily life, social feeds where manipulated and real content sit together, marketplaces full of fake storefronts and reviews, and messaging channels where threats can be personalised, now double as entry points for AI-enabled attacks [3]. It describes the result as a new safety burden: use AI, judge its output, protect your identity, and dodge increasingly personalised scams, all at once [4].
The scam-type breakdown is where the argument gets sharper. On deepfake or virtual kidnapping scams, 19 percent of young people report being victims versus 8 percent of the general population [5], and 43 percent report being targeted versus 26 percent [6]. That is about 2.4 times the victimisation rate on about 1.65 times the targeting rate [7][8]. Treating victims as a subset of targets, which the published post does not confirm the questions were structured to do [9], implies roughly 44 percent of targeted young people were victimised against roughly 31 percent of the general population [10].
Compare sextortion, where the pattern flips. Young people are targeted far more often, 38 percent versus 24 percent [11], yet victimisation is almost identical, 8 percent versus 7 percent [12], implying a lower conversion rate for the younger group, roughly 21 percent versus 29 percent [13]. Romance scams behave similarly: 46 percent targeted versus 33 percent [14], 12 percent victimised versus 10 percent [15], again implying slightly lower conversion [16]. Extortion overall runs 56 percent targeted versus 42 percent [17] and 24 percent victimised versus 17 percent [18]; impersonation, 47 versus 35 targeted [19] and 14 versus 10 victimised [20].
Read together, fluency appears to hold up reasonably well against the old emotional plays and to fail specifically against synthetic media. The trust data is consistent with that. Malwarebytes reports 44 percent of young people have seen AI give information they knew or later learned was wrong, against 30 percent of the general population [21]; 23 percent report negative consequences from AI advice versus 16 percent [22]; 18 percent report emotional harm versus 12 percent [23]. Half of 18-to-22-year-olds strongly agree it is getting harder to tell whether content is genuinely human [24].
Behaviour has already moved. Forty-seven percent say AI changed how much they trust reviews or content, against 37 percent [25]; 35 percent changed how they shop, against 26 percent [26]; 32 percent changed how they present themselves professionally, against 20 percent [27]; 19 percent changed how they date, against 10 percent [28]. One respondent told Malwarebytes that dating online is no longer an option because "you just never know what is or isn't AI" [29].
Two things to watch. First, the methodology: the post as published does not state sample size, fielding dates, or how respondents were recruited [9], so treat the point gaps as directional. Second, whether the deepfake conversion gap shows up in incident data rather than self-report. If it does, the training population that needs synthetic-media verification drills first is the one most programs assume already knows.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Malwarebytes reports that 70 percent of 18-to-22-year-olds have experienced an AI-related scam in the last year, compared to half of the general population.
Malwarebytes argues the exposure is not recklessness but platform structure: social feeds where manipulated and real content sit side by side, online marketplaces filled with fake storefronts and reviews, and messaging channels where threats can be personalised now double as entry points for AI threats.
19 percent of young people report being a victim of a deepfake or virtual kidnapping scam, versus 8 percent of the general population.
43 percent of young people report being targeted by a deepfake or virtual kidnapping scam, versus 26 percent of the general population.
The young-cohort AI scam experience rate is 20 percentage points above the general population, about 1.4 times the rate.
Malwarebytes describes a new safety burden in which young people are asked to use AI, judge its output, protect their identities, and avoid increasingly personalised scams all at once.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single interested source, methodology undisclosed
All quantitative content traces to one publisher's own survey, and that publisher sells consumer scam protection. The post as supplied discloses no sample size, fielding window, geography, recruitment method or question wording, and never states whether victim questions were nested inside targeting questions. Internal consistency is good and the figures are reported cleanly, which earns some credit, but there is no independent corroboration, no platform-side incident data and no pre-AI baseline that would isolate the AI attribution in the headline.
Self-reported usage only, no third-party telemetry
There is genuine usage disclosure here — quantified social-platform penetration in the young cohort (89% Instagram, 78% TikTok, 68% Snapchat, 49% Pinterest) and a qualitative assertion that young people use AI across schoolwork, interview prep, relationship advice and shopping. But it is all survey self-report from one vendor, with no platform-published usage data, no incident counts and no measurement of how widely any defensive practice or product has actually been taken up in response. Adoption is therefore evidenced but shallow.
Framing outruns the disclosed method
The direction of the finding is plausible and the post is careful to blame platform structure rather than young people, which is a restrained move. But the headline prevalence claim is presented with the authority of measurement while the measurement itself is undisclosed, the AI attribution has no pre-AI baseline, and the vulnerability narrative is asserted over data that partly cuts the other way: on the nested reading the young cohort converts from target to victim less often than the general population for sextortion and romance scams, and sextortion victimisation is 8 versus 7 percent, effectively level. Overstatement is moderate rather than severe.
Vendor threat research aligned to product sales
The sole source is a consumer cybersecurity vendor publishing prevalence research on exactly the harms its consumer products address — scam, identity and personal-data protection. Higher measured scam prevalence directly supports the commercial case for those products, and the post contains no methodology disclosure or interest statement that would let a reader discount for that alignment. This is not evidence of bad faith; it is an unmitigated structural incentive to publish the largest defensible numbers.
Direction plausible, magnitudes unverified
Confidence is limited by structure rather than by contradiction: one source, one interested publisher, no disclosed method, no replication. The claims are internally consistent and the qualitative attack-chain description is mechanically credible, so the direction of the cohort gap deserves moderate belief. The specific percentages, and any conversion rate derived from them, do not.
product
The Williams estate's answer to AI slop is a live Instagram account, not a takedown queue2 distinct publishers
product
Cinemas, classrooms and ICE: smart glasses now need a venue-policy contingency1 distinct publisher
invest
Meta's Pay Structure, Not Its Policy Page, Is What the States Put on the Stand1 distinct publisher
science
Feeds are triaging patients by engagement, and the proposed defence is literacy, not moderation1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 11, 2026