E-commerce scams phishing attacks represent 85% of financial phishing attempts in the Middle East, according to a new report from Kaspersky released on April 13, 2026. The findings reveal a significant shift in how attackers target users’ financial accounts across the region, with fraudsters increasingly moving away from traditional banking malware toward credential theft and social engineering tactics.

More than one million online banking accounts were compromised by infostealers in 2025, marking a major escalation in financial cybercrime. Attackers are leveraging dark web marketplaces to aggregate, repackage, and sell stolen credentials and payment card data, creating what Kaspersky describes as a self-sustaining ecosystem of financial fraud.

Phishing Landscape Shifts Toward E-commerce Targets

Traditional financial phishing remains prevalent, but the distribution has changed significantly. Pages mimicking e-shops dominated the financial phishing landscape in 2025, accounting for 48.5% of detections, up 10.3% from 2024. Bank phishing pages declined to 26.1%, down 16.5% from the previous year, while payment system phishing rose to 25.5%, up 6.2% year-over-year.

The decline in bank phishing suggests these services are becoming harder to impersonate successfully. Fraudsters are adapting their strategies to target easier entry points, particularly e-commerce platforms where user security awareness may be lower.

Regional Variations in Attack Strategies

Attack patterns vary significantly by region. In the Middle East, e-commerce scams dominate with 85.8% of financial phishing attempts, reflecting heavy reliance on online retail lures. Africa shows a different pattern, with bank-related phishing leading at 53.75%, suggesting insufficient account security measures in that region.

Latin America displays more balanced distribution across all three categories, while Asia-Pacific and Europe show more diversified attack strategies spread evenly across banks, e-shops, and payment systems. This regional variation indicates attackers tailor campaigns to local digital habits and security vulnerabilities.

Mobile Banking Malware Surges While PC Threats Decline

Financial PC malware detections continued declining in 2025 as users increasingly rely on mobile devices for banking. However, mobile banker attacks grew 1.5 times compared to 2024, indicating attackers are shifting focus to smartphones and tablets where security may be less robust.

Infostealers played a critical role in enabling financial crime on both platforms by harvesting login credentials, cookies, bank card numbers, cryptocurrency wallet seed phrases, and autofill data from browsers and applications. Kaspersky detected a 59% global surge in infostealer detections from 2024 to 2025, with increases of 53% in Africa and 26% in the Middle East on PCs.

Dark Web Marketplace Fuels Credential-Based Attacks

According to Kaspersky Digital Footprint Intelligence, over one million online banking accounts from the world’s 100 largest banks had credentials exposed on dark web marketplaces in 2025. India, Spain, and Brazil recorded the highest median numbers of compromised accounts per bank.

Notably, 74% of payment cards stolen by infostealer malware and published on dark web resources remained valid as of March 2026. This means attackers could still use cards stolen months or even years earlier, extending the window of vulnerability for victims.

“The dark web has become a central hub for financial cybercrime,” said Polina Tretyak, Kaspersky Digital Footprint Intelligence analyst. “Stolen credentials and bank cards harvested by infostealers are aggregated, repackaged, and sold there, while phishing kits targeted at users of financial products are offered as ready-to-use services. This creates a self-sustaining ecosystem where data theft and fraud operations reinforce each other, making attacks scalable and easy to carry out by fraudsters with minimal experience.”

Protection Measures for Users and Organizations

Kaspersky recommends several steps for individual users to reduce risk. Users should avoid following links in suspicious messages and verify web pages before entering credentials or banking details. Implementing multifactor authentication, creating strong unique passwords, and storing them securely in a password manager provide additional layers of protection.

For organizations, Kaspersky advises comprehensive infrastructure assessments to identify and fix vulnerabilities. Deploying integrated cybersecurity platforms that monitor all attack vectors with rapid detection and response capabilities across the organization is essential. Continuous monitoring of dark web resources significantly improves threat coverage and allows organizations to track threat actor plans and activity trends.

The full report is available on Securelist, Kaspersky’s threat intelligence platform, providing detailed analysis of current financial cyberthreat trends and regional variations in attack patterns.