Asia-Pacific Consumers Lead Globally in Digital Adoption and Cybercrime Awareness, Kaspersky Reports
Key Takeaways
- •APAC consumers exceed global averages across major digital activities, including online shopping at 80% versus 71% globally and digital finance at 72% versus 70%.
- •Kaspersky blocked nearly 30,000 mobile attacks targeting APAC consumers in the first quarter of 2026, with India and Indonesia recording the highest incident volumes at 18,187 and 15,163 respectively.
- •Several APAC markets saw sharp year-on-year increases in mobile attacks during Q1 2026, led by Taiwan at 373%, Sri Lanka at 132%, and Thailand at 127%.
- •The APAC region is projected to reach 2.11 billion mobile subscribers by 2030, underscoring the growing importance of mobile cybersecurity infrastructure.
- •Kaspersky advocates a secure-by-design approach in which organizations embed protection directly into mobile applications rather than relying solely on end users to install separate security solutions.

Consumers in the Asia-Pacific (APAC) region outpace their global counterparts in both the adoption of digital platforms and awareness of cybercrime threats, according to global cybersecurity and digital privacy company Kaspersky.
A B2C Pulse Survey conducted by Kaspersky Market Intelligence found that APAC consumers exceed global averages across key digital activities: online shopping (80% versus 71%), digital finance (72% versus 70%), digital entertainment (70% versus 62%), and digital communication (68% versus 61%). These adoption rates reflect a structural shift in a region that is home to the world's largest internet user population, where mobile devices serve as the primary — and in many cases sole — computing platform for hundreds of millions of consumers.
Alongside this high level of digital engagement, regional consumers also demonstrate heightened awareness of online dangers, with 35% reporting awareness of cybercrimes compared with the 32% global average.
"The awareness is highest in Thailand (39%), followed closely by Malaysia (38%), Indonesia (35%), China (34%), India (32%), and Vietnam (31%)," Kaspersky said.
Choon Hong Chee, head of Consumer Channel for APAC at Kaspersky, emphasized the stakes: "When 77% of APAC is online and digital wallets account for roughly 70% of online payments, cybersecurity is no longer optional. The region expects 2.11 billion mobile subscribers by 2030, which makes protecting personal data and financial transactions critical to sustaining trust in the region's thriving digital economy."
As consumers across the region become increasingly mobile-first, embedded security on smartphones is taking on greater importance, the company noted. Mobile operating systems such as Android and iOS restrict third-party security applications from accessing system-level processes, limiting the effectiveness of traditional antivirus-style solutions that have long been standard on desktop platforms.
Kaspersky reported blocking nearly 30,000 mobile attacks targeting APAC consumers during the first three months of 2026. India and Indonesia recorded the highest number of incidents, with 18,187 and 15,163 attacks respectively.
"However, this type of threat is ballooning in other APAC countries," the company said.
In the Philippines, mobile attacks rose 28% year-on-year in the first quarter. Other countries experienced even steeper increases over the same period, including Taiwan (373%), Sri Lanka (132%), Thailand (127%), Bangladesh (108%), and China (69%).
"The rapid rise in mobile attacks across multiple APAC markets is a reflection of how quickly the region's digital habits are changing. While the nearly 30,000 mobile threats detected in just the first quarter may appear small against the scale of APAC's digital population, they could represent only the tip of the iceberg," Mr. Choon said.
"India and Indonesia recorded the highest volumes, but the sharp year-on-year increases seen in Taiwan, Sri Lanka, Thailand and Bangladesh show that mobile threats are rapidly expanding beyond the region's largest digital economies."
He added: "Unlike PCs, mobile phones are often not protected with the same level of security, despite increasingly becoming the gateway to our financial, social and professional lives. As cybercriminals follow this shift, the challenge is ensuring that mobile security evolves at the same pace as adoption."
Kaspersky argued that building protection directly into mobile applications is becoming increasingly critical, as developers should not rely solely on users to install and maintain separate security solutions on their devices. This recommendation aligns with a broader industry and regulatory push toward "secure by design" principles, which place greater responsibility on technology providers to build protections into their products rather than relying on end-user vigilance.
"This embedded approach to mobile security is particularly relevant as smartphones increasingly become the primary gateway to banking, payments, shopping and other sensitive digital services. By integrating security into the applications themselves, organizations can help provide protection without placing the entire responsibility on consumers to identify and respond to increasingly sophisticated mobile threats," the company said.
Kaspersky highlighted its Kaspersky Mobile Security SDK, which enables organizations such as banks, retailers, government services, and app developers to integrate multilayered security directly into their mobile applications. Additional solutions include Kaspersky Who Calls SDK, which provides integrated caller identification and reputation information to help users identify potentially suspicious or unwanted calls and numbers, and Kaspersky Safe Web, which scans users' web traffic to identify potentially dangerous links before users access them.
— Bettina V. Roc