As Black Friday approaches, shoppers are at increased risk of falling victim to phishing attacks disguised as fake discount sites. Hackers are exploiting the surge in online shopping by creating counterfeit pages that mimic popular brands like IKEA, L.L. Bean, and The North Face. These malicious sites offer tempting discounts to steal personal and financial information.
How the Scam Works
Hackers use deceptive tactics like typosquatting—creating fake domain names similar to legitimate e-commerce sites—to lure in unsuspecting shoppers. These sites often use top-level domains such as .shop, .top, and .store to make them appear authentic. Once victims visit these fake sites, they’re asked to enter their credit card details, personal information, and even phone numbers, which may later be used for follow-up smishing or vishing attacks.
The scam is made even more convincing through the use of Google Translate, dynamically adjusting the site’s language based on the shopper’s location. Attackers also deploy trackers like TikTok Pixel and Meta Pixel to measure the effectiveness of their fraud tactics.
What Happens to Your Data?
Once entered, your financial data is captured and sent to the attackers’ servers, often using legitimate payment processors like Stripe, making the transaction appear legitimate. The stolen information is then used for fraudulent purchases or sold on the dark web.
Stay Safe This Black Friday
To protect yourself from these scams:
- Be cautious of unfamiliar websites and look for secure site indicators (like HTTPS).
- Avoid clicking on links in unsolicited emails or social media ads.
- Use trusted payment methods and multi-factor authentication (MFA) wherever possible.
As shopping seasons like Black Friday attract millions of online buyers, it’s important to stay vigilant and avoid falling for these increasingly sophisticated phishing schemes.