{"id":25453,"date":"2024-11-13T06:10:07","date_gmt":"2024-11-13T14:10:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/11\/13\/news-19183\/"},"modified":"2024-11-13T06:10:07","modified_gmt":"2024-11-13T14:10:07","slug":"news-19183","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/11\/13\/news-19183\/","title":{"rendered":"Warning: Online shopping threats to avoid this Black Friday and Cyber Monday\u00a0"},"content":{"rendered":"\n<p>It\u2019s that time of year again. Thanksgiving will pass just as quickly as it arrived, and the festive season will soon hit full swing as countless people go online for some gift shopping. But where there\u2019s a gift to be bought, there\u2019s also a scammer out to make money.<\/p>\n<p>And make money they do. In the last five years, the <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2023_IC3Report.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Internet Crime Complaint Center (IC3)<\/a> said it has received 3.79 million complaints for a wide range of internet scams, resulting in $37.4 billion in losses.\u00a0<\/p>\n<p>Today, we\u2019re warning of several online threats that could target you over the next few weeks and months: brand impersonation and fakes, credit card skimming, and malvertising.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-1-brand-impersonation-scams-nbsp\">1. <strong>Brand impersonation scams<\/strong>&nbsp;<\/h2>\n<p>This Black Friday and beyond, you\u2019re likely to see scammers ripping off big name brands. Here are a few fakes you should look out for.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-temu-ads-offer-discounted-ps5s-nbsp\"><strong>Temu ads offer discounted PS5s<\/strong>&nbsp;<\/h3>\n<p>Scrolling through Facebook, we were presented with a couple of posts advertising discounted PS5s.&nbsp;<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1200\" height=\"904\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/Temu-ads.png?w=1024\" alt=\"Ads on Temu showing PS5\" class=\"wp-image-120767\" style=\"object-fit:cover\" \/><\/figure>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cQuit overspending on PS5! This one I got off TEMU is AWESOME and is much cheaper. I\u2019d highly recommend picking this up!\u201d&nbsp;<\/p>\n<\/blockquote>\n<p>Of course, it\u2019s tempting to get a discount on high-value items like a PlayStation 5, but Temu doesn\u2019t actually sell PS5s.<\/p>\n<p>If you click the play button on the \u201cvideo,\u201d you are instead redirected to a Temu page selling various PlayStation accessories that are not official or in any way approved by Sony.\u00a0\u00a0<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-fake-amazon-offers-you-great-deals-this-black-friday-nbsp\"><strong>Fake Amazon offers you great deals this Black Friday<\/strong>&nbsp;<\/h3>\n<p>Amazon is relatively low cost, it\u2019s convenient, and you can look at someone\u2019s wish list on there. Except in this scam we caught online, the website isn\u2019t really Amazon\u2014check out the URL.&nbsp;<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"932\" height=\"824\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/Amazon-watermark.png?w=932\" alt=\"Screenshot of a fake Amazon site showing goods to buy\" class=\"wp-image-120754\" style=\"object-fit:cover\" \/><\/figure>\n<p>Fake online stores like this use Amazon\u2019s branding to sell counterfeit products. Even if you take the risk and buy a knock off product (which we think is a bad idea), you have no guarantee of receiving the merchandise, and definitely no buyer protection.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-walmart-makes-it-easy-for-you-to-buy-gift-cards-nbsp\"><strong>Walmart makes it easy for you to buy gift cards<\/strong>&nbsp;<\/h3>\n<p>Nothing says \u201cI saw this and thought of you\u201d like a Walmart gift card on Christmas day. But make sure you are buying from the right website.&nbsp;&nbsp;<\/p>\n<p>Again, in this example, check out the URL\u2014this website might look Walmart, but it\u2019s a fake that will happily take your money in exchange for nothing.\u00a0<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"928\" height=\"823\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/Walmart-watermark.png?w=928\" alt=\"Screenshot of a fake Walmart site advertising gift cards\" class=\"wp-image-120771\" style=\"object-fit:cover\" \/><\/figure>\n<h3 class=\"wp-block-heading\" id=\"h-usps-now-delivers-you-fraud-nbsp\"><strong>\u201cUSPS\u201d now delivers you fraud<\/strong>&nbsp;<\/h3>\n<p>If you\u2019re taking advantage of Black Friday sales and buying many things at once, it can be tricky to keep track of what you\u2019ve ordered. Even if you do know what&#8217;s coming, you often don\u2019t know which package service will deliver it to your door. Scammers take advantage of this and will send fake delivery notice emails that encourage you to click on them.\u00a0<\/p>\n<p>With this fake USPS site, you are asked to pay a small fee to have your delivery processed. However, once you hand over your card details the scammers can take whatever amount they like and sell your details to other criminals.&nbsp;<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1600\" height=\"1200\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/USPS-watermark.png?w=1024\" alt=\"Screenshot of fake USPS site\" class=\"wp-image-120760\" style=\"object-fit:cover\" \/><\/figure>\n<p>These scams are very common. In fact, when we looked, we saw 50 fake USPS sites set up in only a day:&nbsp;<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" width=\"1485\" height=\"1202\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/USPS-sites-watermark.png?w=1024\" alt=\"Diagram showing many fake USPS domains\" class=\"wp-image-120759\" style=\"width:1000px\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-2-credit-card-skimmers-nbsp\">2. <strong>Credit card skimmers<\/strong>&nbsp;<\/h2>\n<p>We\u2019re seeing a lot of online stores <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/08\/hundreds-of-online-stores-hacked-in-new-campaign\" target=\"_blank\" rel=\"noreferrer noopener\">hosting credit card skimmers,<\/a> especially smaller retailers.&nbsp;&nbsp;<\/p>\n<p>A credit card skimmer is a piece of malware that is injected into a website, often through vulnerabilities in the content management system (CMS) or the plugins that the site owner uses.&nbsp;<\/p>\n<p>When visiting a site that has a card skimmer on it, you\u2019ll likely have no idea it\u2019s even there. However, a single script injection is enough to steal your credit card data.&nbsp;<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" width=\"1223\" height=\"651\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/code-watermark.png?w=1024\" alt=\"Screenshot of code being inserted into a website\" class=\"wp-image-120755\" style=\"width:1000px\" \/><\/figure>\n<p>Last year, we saw a <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/11\/credit-card-skimming-on-the-rise-for-the-holiday-shopping-season\" target=\"_blank\" rel=\"noreferrer noopener\">large uptick in card skimmers<\/a> just before the holiday season. One particular campaign that we tracked peaked in April 2023, but then really slowed down during the summer months. Across months, cybercriminals had infected multiple websites and built custom templates to trick victims into handing over their credit card details. By October, the same campaign had increased to its highest volume yet, and it is highly likely that this year will be the same.\u00a0<\/p>\n<p>When looking at compromised websites, it can be hard to tell what\u2014if anything\u2014is wrong. However, if a site looks like it hasn\u2019t been maintained in a while (for example, it displays outdated information, such as \u2018Copyright 2022\u2032) you should avoid entering in your card details. Most compromises happen because a website\u2019s CMS and its plugins are outdated and vulnerable.\u00a0<\/p>\n<p>Our free browser extension <a href=\"https:\/\/www.malwarebytes.com\/browserguard\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes Browser Guard<\/a> blocks credit card skimmers by default. If you visit a compromised store you\u2019ll be shown a warning like this:\u00a0<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"607\" height=\"347\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/image_e05f85.png\" alt=\"\" class=\"wp-image-120741\" \/><\/figure>\n<p>Access to the store isn\u2019t blocked, we just block the skimmer code so it can\u2019t load. And while you could in theory still shop safely, we\u2019d still advise you to avoid buying anything from there.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-3-malvertising-increases-in-line-with-gift-shopping-nbsp\">3. <strong>Malvertising increases in line with gift shopping<\/strong>&nbsp;<\/h2>\n<p>Malvertising\u2014or malicious advertising\u2014is a favorite of scammers, who use online ads and sponsored search results to deliver malware to their unsuspecting victims.&nbsp;&nbsp;<\/p>\n<p>Malvertising doesn\u2019t require that criminals know a victim\u2019s email address, login credentials, or personal information to deliver them malware. All the scammers need to do is <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/02\/malvertising-this-cyberthreat-isnt-on-the-dark-web-its-on-google\" target=\"_blank\" rel=\"noreferrer noopener\">fool someone into clicking on an ad<\/a> that looks legitimate.&nbsp;&nbsp;<\/p>\n<p>Last fall, Malwarebytes tracked a 42% increase month-over-month in malvertising incidents in the US. This year we\u2019re seeing a similar uptick, with a 41% increase from July to September as we head into the holiday shopping season.&nbsp;<\/p>\n<p>In terms of the actual advertiser accounts that are used in malvertising campaigns, most are based in the US and are set up using a combination of fake identities or hijacked accounts. However, according to our research findings, ads originating in Pakistan and Vietnam account for 90% of the fraud.&nbsp;<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"604\" height=\"372\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/Advertiser-origin-watermark.png?w=604\" alt=\"Pie chart showing the countries of origin of attacks\" class=\"wp-image-120753\" \/><\/figure>\n<p>Most (77%) of the accounts are used once only\u2014created quickly and then burned. Once that account is dead, cybercriminals spin up the next one and on it goes.&nbsp;&nbsp;<\/p>\n<p>No brand is safe from malvertisers. We\u2019ve tracked campaigns that spoof <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2024\/08\/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a>, <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2023\/05\/malvertising-its-a-jungle-out-there\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon<\/a>, <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2024\/11\/large-ebay-malvertising-campaign-leads-to-scams\" target=\"_blank\" rel=\"noreferrer noopener\">eBay,<\/a> <a href=\"https:\/\/www.malwarebytes.com\/blog\/scams\/2024\/09\/walmart-customers-scammed-via-fake-shopping-lists-threatened-with-arrest\" target=\"_blank\" rel=\"noreferrer noopener\">Walmart<\/a>, <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/09\/lowes-employees-phished-via-google-ads\" target=\"_blank\" rel=\"noreferrer noopener\">Lowe\u2019s<\/a>\u2014and even <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2020\/04\/copycat-criminals-abuse-malwarebytes-brand-in-malvertising-campaign\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes<\/a>.&nbsp;&nbsp;<\/p>\n<p>Our advice: It\u2019s not always easy to tell a real ad from a scam, so it\u2019s best to avoid clicking on sponsored ads at all. Use genuine search results or navigate directly to the site yourself.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-to-shop-safely-this-holiday-season-nbsp-nbsp\"><strong>How to shop safely this holiday season&nbsp;<\/strong>&nbsp;<\/h2>\n<ul>\n<li><strong>Remember: If it\u2019s too good to be true then it probably is.<\/strong> Discounted items are tempting\u2014especially at a time of year when lots of spending takes place\u2014but these offers often amount to nothing. Instead, research the best deal at reputable retailers.\u00a0<\/li>\n<\/ul>\n<ul>\n<li><strong>Don\u2019t get rushed into making decisions.<\/strong> Scammers will use a sense of urgency to pressure you into performing quick actions before you can properly think things through. Take your time before doing anything like clicking links or entering card details.&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><strong>Get an ad and malicious content blocker like <\/strong><a href=\"https:\/\/www.malwarebytes.com\/browserguard\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Malwarebytes Browser Guard.<\/strong><\/a><strong> <\/strong>If you\u2019re blocking ads then you can\u2019t be tricked into clicking on them. Browser Guard (which is free!) also protects against credit card skimming and other online threats.&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><strong>Keep an eye on your financial statements: <\/strong>An uptick in online shopping deserves an uptick in vigilance with checking online bank accounts, credit card statements, investment portfolios\u2014in fact, any financial account data. Flag anything that seems suspicious with your provider.&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><strong>Protect your online accounts. <\/strong>Use a different password for every account (a password manager is super helpful in generating and storing all your passwords), and set up multi-factor authentication (MFA) wherever you can.&nbsp;&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><strong>Protect your devices:<\/strong> Most security products offer some kind of web protection that detects malicious domains and IP addresses, including <a href=\"https:\/\/www.malwarebytes.com\/premium\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes Premium<\/a> which offers web and phishing protection.&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><strong>Clean up your personal data online: <\/strong>Cybercriminals use publicly available information in their scams, so check what information is available about you online using our free <a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Footprint scan.<\/a> You can also take the first step in removing your personal information from the network of data brokers online with our <a href=\"https:\/\/www.malwarebytes.com\/personal-data-remover\" target=\"_blank\" rel=\"noreferrer noopener\">Personal Data Remover<\/a>.\u00a0<\/li>\n<\/ul>\n<p><em>Thanks to Jerome Segura for his research on this piece.<\/em><\/p>\n<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/11\/warning-online-shopping-threats-to-avoid-this-black-friday-and-cyber-monday\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Where there\u2019s a gift to be bought, there\u2019s also a scammer out to make money. Here&#8217;s how to stay safe this shopping season. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11014,11015,32,3923,26699,10574],"class_list":["post-25453","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-black-friday","tag-cyber-monday","tag-news","tag-online-shopping","tag-personal","tag-scams"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25453"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25453\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}