Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams

Platon Kotzias

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Phishing & Fraud 2 · Phishing & Fraud 2

Overview

In "Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams," Platon Kotzias, representing a collaborative effort between the Norton Research Group and the India Software Institute, presents a groundbreaking quantitative analysis of user exposure to various online scam types. The talk addresses a critical gap in cybersecurity research: a comprehensive, comparative understanding of how different scams impact users and their prevalence across the internet. This study is vital because online scams have escalated into a top-tier threat, inflicting not only profound emotional distress, including feelings of betrayal, embarrassment, and vulnerability, but also causing staggering financial damages.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction, problem statement, and study motivation
  2. 1:35 Key research questions addressed by the study
  3. 2:05 Overview of data sources: telemetry and scam domains
  4. 3:40 Method for classifying and grouping scam types
  5. 4:10 Detailed explanation of the seven identified scam types
  6. 6:00 Initial findings: Overall user exposure to online scams
  7. 6:40 User exposure analysis per specific scam type
  8. 7:15 Analysis of scam lifetime characteristics and active time

Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams

Speakers: Platon Kotzias

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=jy6hYmzj8yI

Overview

In "Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams," Platon Kotzias, representing a collaborative effort between the Norton Research Group and the India Software Institute, presents a groundbreaking quantitative analysis of user exposure to various online scam types. The talk addresses a critical gap in cybersecurity research: a comprehensive, comparative understanding of how different scams impact users and their prevalence across the internet. This study is vital because online scams have escalated into a top-tier threat, inflicting not only profound emotional distress, including feelings of betrayal, embarrassment, and vulnerability, but also causing staggering financial damages.

The urgency of this research is underscored by recent figures, with the FTC reporting losses of $10 billion in the US alone in 2023, and similar statistics emerging from Australia's ACCC. While prior research has focused on specific scam categories like tech support or cryptocurrency fraud, a holistic view comparing the popularity and user exposure across diverse scam types has been absent. Existing reports from consumer protection agencies, though valuable, are often geographically limited and inherently biased by their reliance on victim self-reporting, which is known to be significantly underreported. This presentation aims to provide the first large-scale, quantitative measurement of user exposure, enabling improved defenses and more strategic prioritization of security investments.

Background

▶ Watch: Introduction, problem statement, and study motivation (0:00)

Online scams have evolved into a pervasive and financially devastating threat in the digital landscape. The sheer scale of the problem is alarming, with global financial losses reaching unprecedented levels. Despite the clear and present danger, a comprehensive understanding of the ecosystem of online scams, particularly in terms of user exposure across different types, has been lacking. Previous academic and industry efforts have largely concentrated on isolated scam categories, such as technical support scams, cryptocurrency investment frauds, or phishing campaigns. While these focused studies have yielded valuable insights into specific attack vectors and defensive strategies, they have not provided a comparative framework to assess the relative impact and prevalence of the myriad scam types users encounter daily.

The limitations of existing data sources further exacerbate this challenge. Reports from consumer protection agencies like the FTC and ACCC, while crucial for public awareness, suffer from two significant constraints. Firstly, their scope is often confined to specific countries or regions, making it difficult to extrapolate global trends or understand cross-border scam operations. Secondly, and perhaps more critically, these reports are heavily dependent on victim self-reporting. It is a well-documented phenomenon that victims of scams, due to feelings of embarrassment, shame, or a lack of awareness regarding reporting mechanisms, frequently do not come forward. This underreporting leads to a skewed and underestimated view of the actual scale of user exposure and financial loss. The absence of robust, data-driven quantification of user exposure has thus hindered the ability of security researchers, product developers, and policymakers to effectively prioritize resources, develop targeted defenses, and allocate security investments where they are most needed. This study directly addresses these shortcomings by providing an unprecedented, large-scale empirical analysis of the online scam landscape.

Key Findings

▶ Watch: Overview of data sources: telemetry and scam domains (2:05)

The research presented by Platon Kotzias unveils several critical findings that quantify the pervasive nature of online scams and highlight specific areas of concern for defenders.

Firstly, the study provides a stark quantification of overall user exposure. Out of the half-million scam domains in their dataset, an astonishing 83% were observed actively receiving user visits in the telemetry data. Over a 10-month period, this translated to 25 million unique desktop and mobile devices visiting these scam sites. On a daily basis, more than 149,000 devices are exposed to online scams. A notable disparity was observed between platforms, with desktop users exhibiting twice the exposure to scams compared to mobile users.

Secondly, the analysis clearly identifies the most prevalent scam types. Users are overwhelmingly most exposed to shopping scams, which consistently rank at the top. This is followed by cryptocurrency scams and financial scams. The exposure to the remaining scam types—dating, gambling, employment, and funds recovery—is significantly lower in comparison. This prevalence holds true even after accounting for potential bias from the internally identified shopping scam domains, confirming shopping scams as the most widespread threat.

Thirdly, the study offers crucial insights into the lifetime characteristics of scams. The average active time for scam domains, defined as the duration between the first and last observation of a scam SLD (Second-Level Domain) in the telemetry, is approximately 11 days. This figure is remarkably long, especially when contrasted with prior work on phishing domains, which typically remain active for only 17 to 21 hours. This means scam domains persist 12 to 15 times longer than phishing sites, indicating a significant gap in current defensive capabilities and allowing them extended periods to ensnare victims.

Fourthly, the research quantifies the listing delay, which is the time difference between a scam SLD's first observation in telemetry and its first appearance in a scam domain feed. On average, scam domains are detected approximately **one day after the first user visits them. This seemingly short delay is critical, as the analysis reveals that the majority of user traffic to these scam domains occurs within these initial 24 hours. On a more positive note, 88%** of scams are detected in a feed before the first user visit, suggesting some proactive capabilities in existing scam feeds, though this proactive window is often insufficient to prevent initial exposure for the remaining 12%.

Finally, the study sheds light on the significant role of online advertisements in driving scam exposure. It was found that 13% of all scam observations occurred because a user clicked on an advertisement. The scam types most heavily advertised—shopping, cryptocurrency, and financial scams—mirror the types with the highest user exposure, indicating a strong correlation between advertising efforts and successful victim engagement. Interestingly, cryptocurrency scam advertisements were found to be four times more "efficient" or successful in attracting user visits compared to financial scam ads, despite similar numbers of advertised SLDs. The UTM source parameters in these ad URLs revealed that scam advertisements are largely placed on social media platforms, with Facebook being the most preferred channel, followed by Twitter.

Technical Deep Dive

▶ Watch: Detailed explanation of the seven identified scam types (4:10)

The comprehensive quantitative analysis presented in "Ctrl+Alt+Deceive" relies on a sophisticated methodology leveraging two primary data sources and an innovative approach to scam type classification. The research aimed to answer several key questions, including quantifying overall exposure, identifying prevalent scam types, analyzing scam lifetimes, and measuring ad-driven exposure.

The foundation of the study is built upon anonymized telemetry data obtained from Norton antivirus clients. This vast dataset comprises information from 11 million Windows desktop devices and 14 million Android and iOS mobile devices, spanning over 230 countries and covering a 10-month period. A crucial distinction between these two telemetry streams is the granularity of observable events: for Windows desktops, events are captured at the URL level, offering detailed insights, while for mobile devices, observations are at the domain level.

This telemetry data is combined with an extensive scam domain dataset, which is significantly larger than those used in prior studies. It includes 67,000 FQDNs (Fully Qualified Domain Names), grouped into approximately half a million SLDs (Second-Level Domains), representing one to two orders of magnitude more data than previous research. This dataset is compiled from two main sources:

  1. Scam Advisor Feed: A commercial scam detection solution providing a feed of identified scam domains. This feed underwent extensive filtering by the researchers to ensure quality and relevance for the study.
  2. Internal Machine Learning (ML) Detection Solution: This solution, developed by the Norton Research Group and evaluated in their AXAC 2023 paper, specializes in identifying shopping scam domains. It contributed an additional 289,000 shopping scam domains to the dataset.

A critical challenge for the study was assigning specific scam types to the collected domains. While the domains from the internal ML classifier were, by definition, known to be shopping scams, the vast majority of domains from the Scam Advisor feed lacked explicit type labels. To address this, the researchers leveraged content signatures, referred to as "industry tags," available within the Scam Advisor feed. They meticulously evaluated the precision of each tag, discarding those with low precision and retaining those deemed sufficiently reliable. These high-precision tags were then grouped to establish seven distinct scam types for the study:

  1. Shopping Scams: These involve fraudulent online shops where users either receive nothing after placing an order or receive an item drastically different from what was advertised.
  2. Cryptocurrency Scams: Websites offering investment services specifically targeting assets related to cryptocurrencies.
  3. Financial Scams: A broader category encompassing generic investment services, including Forex trading, High Yield Investment Programs (HYIPs), and fraudulent real estate schemes.
  4. Dating Scams: Platforms masquerading as legitimate dating sites but which primarily offer fraudulent adult subscription services.
  5. Gambling Scams: Fake sports betting sites or online casinos where users are frequently unable to withdraw any funds they may have "won" or deposited.
  6. Employment Scams: Websites targeting job seekers, often through fake subscription services or by offering fraudulent assistance during the job application process.
  7. Funds Recovery Scams: Considered particularly malicious, these scams target individuals who have already fallen victim to a previous scam. They promise to help victims recover their losses but instead defraud them once again.

The study employed various measurement techniques to quantify different aspects of scam exposure. Overall user exposure was determined by counting unique devices visiting scam domains. Scam lifetime was characterized by two metrics: active time (the duration between the first and last observation of a scam SLD in telemetry) and listing delay (the time difference between a scam SLD's first appearance in telemetry and its inclusion in a public scam feed).

A particularly innovative aspect of the technical deep dive was the method for identifying scam observations originating from online advertisements. This was achieved by analyzing UTM parameters (Urchin Tracking Module parameters) embedded in URLs. These parameters, such as utm_source, utm_medium, and utm_campaign, are commonly added to URLs for tracking the efficacy of advertising campaigns. Both legitimate advertisers and scammers utilize these parameters. By extracting and analyzing these UTM parameters, the researchers gained valuable insights into the platforms where scam ads were placed (e.g., utm_source=facebook) and the overall success of these advertising efforts in driving user traffic to scam domains. This allowed for the quantification of ad-driven scam exposure and the identification of preferred advertising channels for scammers.

Demo / Proof of Concept

▶ Watch: Initial findings: Overall user exposure to online scams (6:00)

This talk presented a comprehensive measurement study and quantitative analysis of user exposure to online scams, rather than a live demonstration of a specific security tool or a proof-of-concept exploit. The research focused on data collection, classification, and statistical analysis of a large dataset of scam domains and user telemetry to quantify the problem, rather than showcasing an interactive system or a new vulnerability.

Defensive Implications

▶ Watch: Analysis of scam lifetime characteristics and active time (7:15)

The findings from "Ctrl+Alt+Deceive" offer several crucial implications for cybersecurity defenders, guiding the prioritization of resources and the development of more effective mitigation strategies.

Firstly, the extended active time of scam domains (averaging 11 days, 12-15 times longer than phishing sites) is a clear call to action. Current defensive mechanisms, which often focus on rapid takedowns, appear to be insufficient for these types of threats. Defenders need to invest in more persistent and proactive detection and remediation strategies that can identify and neutralize scam sites earlier and keep them offline for good.

Secondly, the identification of shopping, cryptocurrency, and financial scams as the most prevalent and impactful types provides a clear roadmap for prioritization. Security vendors and researchers should dedicate significant effort to developing specialized and highly effective detection and prevention solutions for these categories. As suggested by the speaker during the Q&A, it may be more effective to create dedicated classifiers for these high-prevalence scam types, leveraging unique features and patterns specific to each, rather than relying solely on generic, broad-spectrum scam detectors. For the less prevalent scam types, a more generic classifier might suffice.

Thirdly, the observed listing delay—where the majority of scam traffic occurs within the first 24 hours, often before public feeds list the domain—underscores the critical need for real-time or near real-time detection capabilities. Proactive identification, even if only 88% effective, is valuable, but the remaining 12% that slip through before being listed account for a disproportionate amount of initial user exposure. Enhancing the speed and comprehensiveness of scam domain feeds and integrating them more rapidly into protective systems (like browser warnings or network filters) is paramount to minimize initial victim engagement.

Fourthly, the significant role of online advertisements, particularly on social media platforms like Facebook and Twitter, demands a stronger stance from these platforms. Social media companies must enhance their ad screening processes, implement more robust automated detection of fraudulent advertisements, and improve their enforcement mechanisms against scam advertisers. Defenders should also educate users about the prevalence of scam ads on these platforms and the need for extreme caution when clicking on sponsored content, even from seemingly reputable sources.

Finally, the existence and prevalence of funds recovery scams highlight a particularly insidious form of re-victimization. Defenders should prioritize public awareness campaigns specifically targeting individuals who have previously fallen victim to scams, warning them against offers of "recovery services" that are almost always another form of fraud. Support groups and legitimate consumer protection agencies should be equipped with clear messaging to counteract these predatory schemes.

Key Takeaways

  • Pervasive Threat: Online scams are a major and growing threat, with over 149,000 devices exposed daily, inflicting significant financial losses (e.g., $10 billion in the US in 2023).
  • Top Scam Types: Shopping scams are the most prevalent, followed by cryptocurrency and financial scams, indicating where defensive efforts should be primarily focused.
  • Longer Lifespans: Scam domains remain active for an average of 11 days, significantly longer (12-15 times) than phishing sites, highlighting a critical gap in current rapid takedown strategies.
  • Ad-Driven Exposure: A substantial portion (13%) of user exposure to scams originates from online advertisements, primarily placed on social media platforms like Facebook and Twitter.
  • Detection Urgency: The majority of user traffic to scam sites occurs within the first 24 hours, often before they are listed in public feeds, emphasizing the need for faster, more proactive detection.
  • Targeted Defenses: Developing dedicated detection solutions for high-prevalence scam types (shopping, crypto, financial) is recommended over a single, generic classifier.

About the Speaker(s)

Platon Kotzias is a researcher whose work focuses on understanding and quantifying user exposure to online threats. This particular study, "Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams," was a joint effort with fellow researchers from the Norton Research Group and the India Software Institute. His research contributes to a deeper, data-driven understanding of the online scam landscape, aiming to inform and improve defensive strategies against these pervasive digital threats.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Solid measurement paper with real telemetry scale — 25 million devices, 10 months, half a million scam SLDs — that fills a genuine gap in comparative scam exposure data. The UTM parameter technique for isolating ad-driven exposure is clever, and the 11-day active time vs. 17-hour phishing lifetime delta is the kind of concrete number defenders can actually use. Nothing here redefines the threat model or demands a slot over stronger submissions, but it's honest empirical work that earns its place.

Heather Calloway (CISO) — SOLID

Rigorous measurement study that gives defenders real numbers on a problem most organizations have been estimating from FTC press releases. Solid research, but the talk stays in the analyst's lane — it stops short of telling institutions, platforms, or security leaders what to actually change.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025