Skip to content

Roblox phishing scams surge: NordVPN detects 196 active addresses in a week

NordVPN’s Threat Intelligence team has uncovered a sharp rise in phishing scams targeting Roblox users, with 196 active phishing addresses detected in a single week in July 2026. Scammers are using industrialized tools to steal credentials, often targeting children via platforms like Discord, YouTube, and TikTok.

Editor, Lazyfounder

Published 5 min read
Roblox phishing scams surge: NordVPN detects 196 active addresses in a week
Image: (Image credit: Roblox) via source

NordVPN’s Threat Intelligence team has uncovered a sharp rise in phishing scams targeting Roblox users, with 196 active phishing addresses detected in a single week in July 2026. Scammers are using industrialized tools to steal credentials, often targeting children via platforms like Discord, YouTube, and TikTok.

30 SEC SUMMARY

  • NordVPN’s Threat Intelligence team detected 196 active Roblox phishing addresses in a single week in July 2026.
  • Scammers are using ready-made phishing pages and tools to steal credentials, often targeting children via Discord, YouTube, and TikTok.
  • A scam service claims to have processed over six million stolen login records and has 239,000 registered users.
  • Phishing sites mimic Roblox domains using country-code top-level domains to appear legitimate.
  • Roblox’s 'Enhanced Protection' setting requires hardware security keys or mobile passkeys but adds complexity for users.

TABLE OF CONTENTS

  • Surge in Roblox phishing scams detected
  • Sophisticated tools and widespread impact
  • How scammers reach victims
  • Roblox’s response and user protections
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • NordVPN identified 196 active Roblox phishing addresses in a week in July 2026.
  • Scammers sell ready-made phishing pages, credential-checking tools, and disguised links via crypto payments.
  • A scam service claims over six million stolen login records and 239,000 registered users.
  • Phishing sites use domains like roblox[.]com[.]ug and roblox[.]com[.]kz to deceive users.
  • 22 out of 24 sampled phishing sites were live and visually convincing, targeting popular Roblox games.

Surge in Roblox phishing scams detected

According to TechRadar, NordVPN’s Threat Intelligence team identified 196 active phishing addresses targeting Roblox users in a single week in July 2026. The scams are part of a broader trend of cybercriminals industrializing attacks on gaming platforms.

Scammers are using ready-made phishing pages, tools to check stolen credentials, and disguised links, all available for purchase via cryptocurrency payments. This method allows attackers to scale operations quickly and evade detection.

Sophisticated tools and widespread impact

A single scam service claims to have processed over six million stolen login records, referred to as 'logs,' and reports more than 239,000 registered users. NordVPN observed around 300 new signups daily on the service’s website, indicating rapid growth.

Phishing sites often use domains that mimic Roblox, such as roblox[.]com[.]ug (Uganda) and roblox[.]com[.]kz (Kazakhstan), to appear legitimate. NordVPN tested nearly 4,000 combinations of Roblox misspellings and country codes, uncovering 123 scam addresses with over 105,000 recorded visits.

A random sample of 24 phishing addresses revealed that 22 were live and visually convincing. These sites targeted popular Roblox games like Steal a Brainrot, Grow a Garden, Blox Fruits, and PLS DONATE, as well as the legitimate Discord verification bot RoVer.

How scammers reach victims

Scammers typically initiate contact on platforms frequented by children, such as Discord, YouTube, and TikTok. They lure victims with promises of free Robux, the platform’s in-game currency, or exclusive game access.

Once a user enters their credentials on a phishing site, attackers use automated tools to verify the stolen logins. Compromised accounts are often stripped of valuable items or currency, which are then sold or traded.

Roblox’s response and user protections

Roblox introduced mandatory facial age checks for chat worldwide in January 2026, aiming to improve safety for younger users. However, this measure does not directly address account hijacking.

The platform’s 'Enhanced Protection' setting requires users to enable hardware security keys or mobile passkeys for authentication. While effective, this added layer of security may be difficult for children to manage.

Roblox’s official guidance for hacked accounts includes removing suspicious downloads, resetting passwords, and enabling two-step verification. However, the company may not assist users in recovering compromised accounts unless legally required. Users have only 30 days to contact Roblox after an account breach to recover lost items or currency.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This surge in Roblox phishing scams highlights a growing risk for young users and their families. Scammers are industrializing their operations, using ready-made tools and crypto payments to scale attacks. The ease with which these phishing pages mimic legitimate Roblox domains—even using country-code top-level domains—makes it harder for children and parents to spot fraud.

Roblox’s move to require facial age checks for chat globally is a step toward safety, but it doesn’t address account hijacking. The platform’s 'Enhanced Protection' feature, which requires hardware security keys or mobile passkeys, is robust but may be too complex for younger users. For founders and operators, this is a reminder that even well-regarded platforms with large young audiences are prime targets for cybercriminals. If your product serves minors, assume scammers will exploit it—and build defenses accordingly, like simplifying multi-factor authentication or adding proactive fraud detection.

Key takeaways

  • Roblox phishing scams are surging, with 196 active addresses detected in a single week in July 2026.
  • Scammers are using scalable, ready-made tools and crypto payments to operate efficiently.
  • Phishing sites mimic Roblox domains using country-code top-level domains to appear legitimate.
  • Most sampled phishing sites were live and convincing, targeting popular Roblox games and even impersonating legitimate tools like RoVer.
  • Roblox’s 'Enhanced Protection' setting is secure but may be too complex for younger users.

FAQ

What makes Roblox a target for phishing scams?

Roblox has a massive user base, many of whom are children with limited experience spotting scams. The platform’s in-game economy, where users trade virtual items and currency, creates financial incentives for attackers. Additionally, scammers can easily reach victims through platforms like Discord, YouTube, and TikTok, where Roblox content is widely shared.

How can parents protect their children from Roblox phishing scams?

Parents should educate children about the risks of clicking links from unknown sources, especially those promising free Robux. Enabling two-step verification and discussing the importance of strong, unique passwords can help. For added security, parents can enable Roblox’s 'Enhanced Protection' setting, though it requires hardware security keys or mobile passkeys, which may be complex for younger users.

Why are scammers using country-code top-level domains for phishing sites?

Country-code top-level domains (like .ug for Uganda or .kz for Kazakhstan) allow scammers to create domains that closely resemble the legitimate Roblox website. These domains can appear more trustworthy to users, increasing the likelihood of successful phishing attacks. They are also often easier or cheaper to obtain than traditional domains.

Related on Lazyfounder

Sources

  1. TechRadar · 2026-10-06
    Parents beware — Roblox scammers are stealing logs and passwords like never before, here's what to look out for

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us