As reported by The Manila Times and separately carried by Newsbytes.ph and Sri Lanka’s Daily FT, Kaspersky says it blocked “nearly 30,000” mobile attacks against APAC consumers in the first quarter of 2026. The same set of claims says India logged 18,187 mobile attacks and Indonesia 15,163. Those two country figures alone total 33,350 incidents — already more than the stated regional total, before any other APAC market is included.
That does not prove the underlying telemetry is wrong. It does mean the figures cannot all represent the same population, time frame and unit of measurement as presented. Kaspersky needs to clarify whether the regional number refers to blocked attacks while the country totals refer to detections; whether one number counts unique users and another counts events; or whether the data sets cover different product populations. Until then, the headline total should not be used as a regional threat baseline.
APAC usage rates are higher, but the survey cannot establish a regional ranking
Kaspersky Market Intelligence’s B2C Pulse Survey found that 80 percent of APAC respondents shopped online, versus 71 percent globally. Digital-finance use was 72 percent in APAC against 70 percent globally; digital entertainment measured 70 percent versus 62 percent; and digital communication was 68 percent against 61 percent.
Those are credible indicators that the surveyed APAC population relies heavily on connected services. The largest gaps were in shopping, entertainment and communications, which are also categories routinely used in phishing, impersonation and fraudulent-app campaigns. For banks, marketplaces, telecoms and government-service teams, the useful conclusion is not that a particular country is uniquely exposed; it is that authentication, fraud detection and recovery workflows need to assume customers transact primarily through smartphones.
The survey’s wording nevertheless overreaches when it characterizes APAC consumers as leading in digital activity. A comparison between one regional segment and a global figure does not establish that APAC ranks first against every other region. A global average may also include APAC respondents, depending on the study design.
Kaspersky has not published, in the accounts reviewed by WindowsForum, the survey’s field dates, total sample size, country-level sample sizes, respondent recruitment method, weighting methodology, confidence intervals or precise definition of “digital finance.” Without those basics, readers cannot judge whether a two-point difference — such as 72 percent in APAC versus 70 percent globally — is statistically meaningful or simply normal survey variation.
That missing methodology is more important than the marketing-friendly regional averages. An 80 percent online-shopping result says considerably more if it represents a broad, weighted sample across APAC markets than if it comes from a limited online panel already predisposed toward digital services.
The mobile-attack increase rates need their denominators
Kaspersky’s telemetry claims steep year-over-year growth in several markets during the first quarter: Taiwan rose 373 percent, Sri Lanka 132 percent, Thailand 127 percent, Bangladesh 108 percent, China 69 percent and the Philippines 28 percent. Newsbytes.ph independently highlighted the inconsistency between the regional total and the India-Indonesia figures, while The Nation Thailand reported the Thai increase alongside the survey’s cybercrime-awareness result.
Percentage growth can be useful for spotting a trend, but it is a poor standalone measure of exposure. A 373 percent increase can reflect a major campaign, yet it can also start from a very small number of detections. The report gives no corresponding country-level counts for Taiwan, Sri Lanka, Thailand, Bangladesh, China or the Philippines, and does not say how many devices or customers were covered by Kaspersky products in each market in either year.
This distinction matters for IT administrators and security teams supporting customers in the region. The reported percentages are signals to review mobile fraud telemetry and app-security controls; they are not sufficient evidence to redirect budgets toward one market rather than another. Raw events, protected-device counts, detection definitions and the relevant malware or phishing families would be required for that.
The report also does not identify a new vulnerability, provide indicators of compromise, name a malware family or describe a campaign that defenders can block today. It should therefore not be read as a threat advisory in the same category as a CVE bulletin, a Microsoft security update or an incident-response notice. It is a vendor’s aggregate observation, useful mainly for identifying where more detailed telemetry should be sought.
Consumer awareness has not translated into measurable protection
Kaspersky says 35 percent of APAC respondents were concerned about criminal use of digital technology, compared with 32 percent globally. Thailand had the highest reported concern at 39 percent, followed by Malaysia at 38 percent, Indonesia at 35 percent, China at 34 percent, India at 32 percent and Vietnam at 31 percent.
The juxtaposition with the mobile-threat data is the report’s most useful finding, even though it remains incomplete. Thailand, where concern was highest among the countries listed, also recorded a claimed 127 percent increase in mobile attacks. Awareness of cybercrime is plainly not the same thing as resistance to phishing, malicious sideloaded apps, account takeover or payment fraud.
For organizations, the implication is practical. User education remains necessary, but it should not be the primary barrier between a fraudulent message and a financial transaction. Mobile applications handling payments, identity data or sensitive account changes should use phishing-resistant sign-in methods where possible, bind sessions to device risk signals, flag anomalous beneficiary or payout changes, and make account recovery more difficult for an attacker to abuse.
Windows administrators should take the same lesson into cross-device identity management. A compromise often begins on a personal phone and later becomes a corporate account problem when passwords are reused, an MFA prompt is approved under pressure, or a browser session is hijacked. Conditional access, strong MFA, password-manager adoption and tested self-service recovery controls address that risk more directly than broad awareness campaigns alone.
Kaspersky’s recommended answer is also its product pitch
The company’s announcement promotes its Mobile Security SDK, Who Calls SDK and Safe Web DNS-filtering service. Embedded anti-phishing, malware detection, device-reputation checks and risky-link filtering are reasonable categories of protection for consumer-facing apps. But the survey and telemetry presented here do not independently demonstrate the effectiveness of Kaspersky’s particular products, nor do they compare them with mobile operating-system protections, app-store screening, enterprise mobile-device management or other security SDKs.
That commercial context does not invalidate the survey. It does require readers to separate the evidence from the proposed purchase. The evidence supports an argument for defense in depth around mobile identity, transactions and links. It does not establish that one vendor’s SDK is the necessary response.
Kaspersky’s APAC report is therefore best treated as an early warning about concentration of digital activity on phones, rather than a precise measure of the region’s mobile-threat volume. The company’s next publication needs to resolve the 33,350-versus-30,000 discrepancy and disclose enough survey and telemetry methodology for customers to determine whether the reported increases reflect a changing threat environment, a changing customer base, or both.