Back Sg.Finance.Yahoo Arkose Labs Report Reveals Explosive Growth in SMS Toll Fraud and Precision
Report spotlights a 67% surge in SMS toll fraud, 125% increase in gaming attacks, and 97% rise in fraud targeting the fintech sector
SAN MATEO, Calif., December 17, 2025 --( BUSINESS WIRE )-- Arkose Labs , the leading fraud prevention, device ID and bot management company, today announced the release of its latest threat intelligence report, Enterprises Under Attack: Quarterly Threat Actor Patterns - Industry Trends, Analysis and Benchmarks . The Q4 2025 analysis reveals a dramatic shift in fraudster tactics, marked by an explosion in SMS toll fraud and a move toward highly selective, large-scale attacks.
"Our latest data leaves no room for doubt, fraudsters are not just getting smarter, they’re getting bolder," said Frank Teruel , Chief Operating Officer at Arkose Labs. "Organizations are facing larger-scale, precision-driven attacks, while foundational threats like fake accounts continue to be relentless. This is bound to get worse with Agentic AI attacks. Leaders who understand the evolving playbook will be better equipped to disrupt attacker economics and safeguard their customers."
The new report exposes SMS toll fraud as the breakout threat of Q3 2025, with malicious traffic and monetization scams sharply increasing across key verticals. SMS toll fraud occurs when attackers generate high volumes of fraudulent text messages to premium numbers in order to profit from revenue-sharing arrangements. Highlights include:
67% overall surge in SMS toll fraud malicious traffic, making it the fastest-growing attack type of the quarter
125% increase in SMS toll fraud attacks targeting the gaming sector
97% growth in SMS toll fraud targeting fintech, alongside a major spike in human fraud farm activity
SMS toll fraud now comprises 78% of all attacks on the gig economy, up from 48% a year prior
This dramatic escalation signals a clear move by adversaries toward more direct and profitable monetization schemes.
Shifting Attack Patterns: Fewer, Bigger Strikes
Analysis reveals a new era of fraud characterized by precision campaigns that create outsized impact. Overall attack volume remained nearly steady, but average attack size grew dramatically. The gig economy, in particular, experienced 51% fewer attacks but 49% more malicious traffic , resulting in a 300% increase in average attack size. This demonstrates a move toward concentrated, high-value exploitation. Attackers are increasingly abandoning low-return, widespread attacks in favor of fewer strikes aimed at vulnerable, high-reward entry points.
Persistent Fake Account Problem:
Fake account creation remains the #1 attack type, accounting for 46% of all fraudulent activity. This enduring threat enables a spectrum of downstream abuse, including loyalty program exploitation and romance scams.
Despite substantial security investments, sign-up flows stand out as the weakest link across all nine industries analyzed, making them a primary and persistent target for adversaries.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
