The strategy identifies mobile channels, including messaging platforms, social applications, mobile banking apps, and voice communications, as a central component of modern fraud operations. It also highlights the growing role of AI-enabled phishing, SIM-swapping, fraudulent mobile applications, deepfake impersonation, and social engineering attacks designed to target users directly through mobile devices.
Mobile first attack strategy
According to the UK Government, fraud now accounts for 45% of all crime in England and Wales, while nearly half of all fraud is categorised as online-enabled. The report also states that 53% of authorised push payment (APP) fraud originates through social media, messaging platforms, and phone calls — environments increasingly centered around mobile devices.
“The UK Fraud Strategy validates what security and fraud teams are already experiencing globally: attackers are targeting users directly through mobile channels where traditional security tools often lack visibility,” said Andy Fleet, Regional Vice President of EMEA at Zimperium. “As cyber criminals adopt a mobile-first attack strategy, organizations can no longer treat mobile security as a secondary concern or an extension of desktop security.”
Zimperium noted that the strategy introduces growing operational and financial pressure on enterprises through expanding fraud liability, intelligence-sharing initiatives, and increasing regulatory scrutiny around fraud prevention and customer protection.
AI is accelerating speed, scale and sophistication of attacks
The company also warned that AI is accelerating the speed, scale, and sophistication of mobile-targeted attacks. The strategy specifically references AI-generated phishing, voice cloning, and deepfake-enabled fraud campaigns designed to bypass traditional authentication and impersonate trusted individuals or organisations.
“Fraud prevention strategies that focus only on networks, endpoints, or web channels are missing a rapidly expanding attack surface,” added Andy Fleet. “Organisations need real-time visibility into threats targeting mobile devices and applications, along with the ability to identify real attacks, understand what is happening, and respond in minutes.”
Purpose-built for mobile environments, Zimperium delivers AI-empowered protection for mobile applications and devices, helping enterprises defend against mobile-targeted phishing (mishing), malware, app compromise, fraudulent applications, account takeover attempts, and zero-day mobile threats.
















