Gen Z might be the most digitally fluent generation yet, but they’re also becoming one of the most attractive targets for cybercriminals. It’s a paradox that many in the security industry have observed: digital natives who grew up swiping and streaming are often unaware of how deeply integrated cyber threats are into the platforms they use daily.

Unlike older generations, who often treat digital tools as external add-ons to their lives, Gen Z lives inside the internet. They use it to learn, date, shop, and express themselves—and cybercriminals are adapting their methods accordingly. It’s no longer about fake bank emails or Nigerian princes; it’s about social engineering on TikTok, credential stuffing on gaming platforms, and deepfake scams in DMs.

We dug into the tactics used by threat actors against Gen Z—and why technical defenses aren’t enough if behavioral awareness isn’t evolving alongside them.



The Attack Surface Has Shifted

Traditional phishing campaigns via email still exist, but they’re increasingly less effective against a generation that rarely checks their inbox. Gen Z prefers messaging apps, social media, and gaming platforms—so that’s where the attackers have followed.

Malware, credential phishing, and scams now propagate through Instagram Stories, Discord servers, and Reddit threads. A user sharing cracked software in a niche subreddit might include a trojanized installer. A DM from a fake influencer offering a sponsorship deal could contain a link to a phishing page disguised as a login form. And these aren’t hypothetical; they’re happening daily.

The attack surface isn’t just the endpoint anymore—it’s the entire social graph.



How Gamers Are Targeted

In the twelve-month period starting April 1, 2024, Kaspersky’s research team recorded at least 19 million attempts to spread malware disguised as popular video games among Generation Z. The three titles most exploited in these attacks were GTA, Minecraft, and Call of Duty, which alone accounted for 11.2 million attempts. These games boast enormous online communities where content, mods, cheats, and cracked versions are constantly created, making them ideal targets.

One of the most common threats for Gen Z gamers is phishing, where attackers pose as trusted entities and offer free in-game rewards to trick victims into providing personal data. Tempting trade offers and easy ways to make money are among the most exploited techniques.

For example, a phishing site was identified that convincingly imitated an official Riot Games campaign designed to link the world of Valorant and the animated series Arcane. Users were invited to "spin the wheel" to win exclusive skins. In reality, participants unknowingly handed over their game account credentials, banking data, and phone numbers to third parties, receiving no reward in return.

Attractive graphics and recognizable characters: sometimes that's all it takes to fall into the trap.

But it's not just fraud. In November 2024, the Global Research and Analysis Team (GReAT) uncovered a campaign spreading the Hexon stealer, disguised as video game installers. Once executed, the malware exfiltrated data from gaming platforms like Steam, as well as from messaging apps (Telegram, WhatsApp) and social media (TikTok, YouTube, Instagram, Discord).

These malicious installers were distributed through gaming forums, Signal and Telegram chats, Discord channels, and file-sharing sites. Attackers promoted Hexon via a malware-as-a-service (MaaS) model, where more experienced cybercriminals supply malicious tools to less skilled actors for a fee.

Example of a message shared by attackers on a Discord channel.

Shortly after, Hexon's author announced a rebranding of the malware, now called “Leet”, offered with a 50% discount. Unlike its predecessor, Leet is capable of evading sandbox environments by checking the infected system's public IP address and hardware specs. If a virtual environment is detected, the malware terminates itself automatically.



How Fans of Movies, TV Shows, and Anime Are Targeted

Data from the Kaspersky Security Network (KSN) revealed that:

  • The Netflix brand was used as bait in approximately 85,000 attacks — averaging 233 per day.
  • Anime attracts not only Gen Z but also cybercriminals, with 250,000 attacks recorded during the analysis period.
  • Compromised streaming service accounts exceeded seven million.

Alongside Netflix, the most exploited platforms included Amazon Prime Video, Disney+, Apple TV+, and HBO Max. Phishing campaigns remained consistent over time, with no major spikes or drops, relying mainly on classic techniques: links to phishing sites mimicking official portals, often disguised as subscription renewal or payment update requests. Fraudulent communications replicated the visual style of the brands, making detection difficult.

Example of a phishing site mimicking Netflix's official page.

Beyond collecting personal data, these malicious actors also spread various types of malware. The most significant was RiskTool, responsible for about 80% of the attacks. While not directly harmful, it’s often used alongside other payloads like cryptominers, helping them hide within compromised systems.

Many attacks aimed to steal personal information. Given that over 65% of Gen Z watches anime, cybercriminals exploited interest in popular titles like Naruto, One Piece, Demon Slayer, Attack on Titan, and Jujutsu Kaisen. Across just these five titles, more than 250,000 attack attempts were recorded.



Privacy Is No Longer a Priority

Another threat is more cultural: resignation toward privacy. Many believe they have no privacy left to defend. After years of tracking, leaks, and profiling, the widespread attitude is: “They already know everything about me.”

This mindset paves the way for cybercrime. When users no longer value their personal data, they become ideal targets for theft and manipulation.

Even tools meant to simplify life—like login via Google or Apple—create single points of vulnerability. If compromised, they allow access to dozens of services in one go.



Daily Term
Can you guess today’s cybersecurity word in 6 tries?
Play now

What Can Be Done? Technical and Cultural Measures

Protecting Gen Z requires a dual strategy: effective technical defenses and educational outreach.

On the technical side, it's essential to:

  • Monitor anomalous behavior on gaming and social platforms
  • Enable two-factor authentication (2FA) by default
  • Scan in-app messages to detect suspicious links or fraud attempts

But the real challenge is communicating security effectively.
The myth that Gen Z is “born tech-savvy” is dangerous. They know how to use apps, but they don’t always recognize a scam. They install plugins, but don’t read permissions. They understand digital language, but often ignore how cyberattacks work.