Almost every American adult ran into a digital scam or a cyberattack attempt in the past year, and far fewer trust that their sensitive data is still private. That is the core of the 2026 Consumer Cyber Readiness Report, released October 1 by Consumer Reports, Aspen Digital, and the Global Cyber Alliance at the start of Cybersecurity Awareness Month. It is the fifth annual edition. The numbers come from three Consumer Reports surveys fielded earlier in 2026.
The surveys
The fraud findings are from a nationally representative survey of 4,682 U.S. adults in March and April 2026. Ninety-one percent said they had encountered at least one cyberattack attempt or digital scam. Seventeen percent said they lost money. Ten percent lost it for good. Seven percent got it back.
The privacy finding is a year-over-year break. In a May 2026 survey of 2,082 adults, 32 percent were at least somewhat confident that sensitive data such as a Social Security number, health history, or financial information stayed private. The same question in May 2025, asked of 2,333 adults, drew 48 percent. People who said they were “not confident at all” nearly doubled, from 16 percent to 29 percent.
Consumer Reports CEO Phil Radford tied the shift to automation. “AI is making fraud faster, cheaper, and more personal, and no one can out-smart that alone,” he said. Companies should be held accountable, he said, and governments need guardrails.
Personalization, and who gets the money back
One in five people who had seen a scam said the latest attempt used their own details. Phone was the worst channel. Among people whose most recent attempt started with a call, 32 percent said it was personalized.
Recovery depends on the rail. Of those who paid with a credit card, 61 percent said they got the money back. Debit cards: 45 percent. Peer-to-peer apps such as Zelle or Venmo: 15 percent. Cryptocurrency: 5 percent. The report’s point is structural. A credit-card chargeback is a consumer protection. A crypto transfer is not.
Asked who should stop this, 29 percent named the platform owners, meaning social, messaging, and marketplace sites. Eighteen percent named the federal government. Sixteen percent named consumers themselves. Fourteen percent named financial companies.
What people are already doing
Self-defense is common and incomplete. Sixty-nine percent said they inspect links before clicking. Sixty percent use multi-factor authentication. Forty-eight percent turn on automatic updates. Forty-four percent said they use strong passwords. Global Cyber Alliance CEO Brian Cute called the authentication and password numbers moderately encouraging, then argued that passwords cannot fix insecure routing or maliciously registered domains. Those are upstream problems for industry and government.
Aspen Digital’s acting executive director, Konstanze Frischen, said consumers are fighting back and should not have to do it alone. The report points to Take9, a Craig Newmark Philanthropies effort that tells people to pause nine seconds before they click, download, or share. It also names two bills as examples of platform accountability: the federal SCAM Act and New York’s False Social Media Advertising Prevention Act. Existing tools are already on the table. The Federal Trade Commission and state attorneys general can use unfair-and-deceptive-practice authority against platforms that let scam ads run.
Why the privacy drop matters
A 16-point fall in one year is not a mood. It lands in the same window as record breach counts, AI-written lures, and a federal privacy debate that still has no statute. The report does not claim AI caused the confidence crash. It does show the two facts side by side: scam attempts are nearly universal, and trust that a Social Security number stays private has collapsed.
For companies the operational read is narrower than the policy ask. Personalized phone scams mean data already in circulation is being reused, not just guessed. Platforms are where the public puts primary blame. Payment rails decide who eats the loss. A privacy program that stops at a policy page does not answer a customer who just wired a scammer a number taken from a breach the company did not cause and could not see.