Consumer Reports, with Aspen Digital and the Global Cyber Alliance, published its fifth annual Consumer Cyber Readiness Report on 1 October 2026, at the start of Cybersecurity Awareness Month [1]. The report finds that about nine in ten Americans have been targeted by a scam or cyberattack, and Consumer Reports' chief executive said that "AI is making fraud faster, cheaper, and more personal" [1] [2]. The finding bears on Mac users because personalised scams usually begin with personal data that earlier breaches have exposed.
Background
Phishing and scam messages have long relied on volume. Personalisation takes more effort per target, and a cybersecurity expert quoted by CBS News said that before AI, "the level of effort required to personalize something was too great" [2].
Findings
The release states that the main survey covered 4,682 US adults in March and April 2026 and was nationally representative, with two further surveys on privacy confidence of 2,082 adults in May 2026 and 2,333 adults in May 2025 [1]. Consumer Reports reports that nearly all respondents had met at least one cyberattack or digital scam attempt, and that 17 percent of respondents lost money to scams, some of them recovering it later [1]. CBS News gives the same headline findings [2].
On AI, the release says AI is making fraud faster, cheaper and more personal, and that breached data combined with AI tools enables more targeted scams [1]. It reports that about one in five scam victims described an attack that used their personal details [1]. CBS News quotes Consumer Reports cybersecurity fellow Stacey Higginbotham: "AI allows scammers to make better use of personal data… and lowers the cost of reaching more people" [2].
The release also reports that confidence in the privacy of personal data fell between the 2025 and 2026 surveys, and that recovery of lost money varied by payment type, with credit card victims recovering more often than victims of peer-to-peer or cryptocurrency fraud [1]. Among protective habits, it says a majority check links before clicking and use multi-factor authentication, while fewer enable automatic updates or use strong passwords [1].
Implications for individuals and families
The report suggests that generic warnings about badly written messages no longer describe the typical attempt, since a message can quote a real address, employer or recent purchase [1] [2]. The report's survey is of US adults and says nothing specific about Mac users, so the figures describe a general exposure rather than one tied to a platform.
Recommendations
- Turn on multi-factor authentication for email, banking and the Apple Account; the report lists it among its recommendations [1].
- Use the Take9 habit that the report promotes: pause for nine seconds before clicking, downloading or sharing [1] [2].
- Treat a message that knows personal details as a possible sign of a past breach, and not as proof that the sender is genuine.
- Contact a bank or company through the number or site printed on a card or statement, not through a link in a message.
- Report a scam to the platform and to the relevant authority; the report finds that recovery of lost money varies with how it was sent [1].
Relevance to FireAI
FireAI is a firewall for one Mac. It asks before an app contacts a destination it has no rule for, applies per-app rules, and, if the user turns on threat lists, checks traffic against public lists of dangerous websites and addresses, including phishing lists, without sending that traffic to the list providers.
FireAI does not read email or messages, and it cannot tell whether a message is a scam. It does not stop a person from typing a password into a fake page in a browser, and it does not recover money or monitor bank accounts. A threat list only covers addresses that the list already contains.
Limitations
The two sources round the headline figure differently, and this item states it as about nine in ten rather than a precise value [1] [2]. The findings come from self-reported surveys and a press release, and this item did not obtain the full report or the questionnaire. The sources do not measure how much of the personalisation was done by AI, as opposed to breached data used by hand.
Try FireAI, by HisnLabs free for 17 days.