Consumer Reports, Aspen Digital and the Global Cyber Alliance released their 2026 Consumer Cyber Readiness Report on October 1, finding that 91% of U.S. adults had encountered at least one type of digital scam or cyberattack attempt. That is a measure of exposure, not a finding that nine in ten people were successfully hacked. The report puts the share who lost money at 17%, including people who later recovered it.
CNET covered the findings on October 2. The underlying evidence comes from surveys conducted earlier in the year. The new development is the report's publication, not a count of attacks that occurred this week.
Read the question before comparing the percentages
The full report says its main survey interviewed 4,682 U.S. adults between March 13 and April 10. Respondents were asked which listed attempts they had ever personally encountered. Examples included suspicious messages and fake invoices. The figure is not an annual attack rate.
91% encountered an attempt: ever encountering at least one listed scam or cyberattack attempt, among all respondents.
17% lost money: losses including money subsequently recovered; this is not the share of attempts that succeeded.
20% saw personalization: personal details used in the most recent attempt, among people who had encountered an attempt.
32% expressed privacy confidence: a separate May survey about whether sensitive personal data remained private.
The last figure fell from 48% in May 2025. It measures confidence, not a technical audit proving that a corresponding share of records was leaked. Keeping those distinctions intact is more useful than treating every percentage as the same kind of security incident.
Familiar details are not proof of a genuine sender
The report discusses how available personal data and AI tools can assist customized scams. Its survey does not establish what fraction of the reported attempts was generated by AI, or how much AI caused scam exposure to increase.
For a reader, the personalization finding supports a narrower conclusion: recognition is not authentication. A message can mention information that feels familiar while making an unverified request. The FBI explains that criminals can disguise sender names, phone numbers and website addresses to create that impression.
The FTC's phishing guidance recommends contacting the organization through a phone number or website already known to be genuine, rather than using the contact information supplied in the message. That approach remains useful whether the text was written by a person or produced with AI.
Account protection and payment pressure need different responses
Multifactor authentication and automatic software updates are layers of protection recommended by the FTC. They do not answer whether a convincing caller is entitled to receive a payment. A family can strengthen account access while still agreeing to an impostor's request.
The practical response is to separate the request from its claimed identity: verify an unexpected invoice or account warning through the organization's established channel before acting. The report's broad exposure figure makes that a routine precaution, rather than a reason to assume every encounter caused a breach.