Taiwan and China have the Double 11 shopping festival, while Europe and the United States have the Black Friday shopping wave. Both of these provide consumers with items they have been reluctant to buy on official websites for a long time at lower prices than usual. Internet malicious actors are also gearing up for this, setting up phishing, scams, fake websites and other traps waiting for consumers to open their wallets. Security research unit Kaspersky found that in addition to targeting counterfeit tickets for the 2022 FIFA World Cup, there are also new scams targeting this year’s Black Friday and Christmas shopping seasons.

As the Black Friday shopping rush approaches, security agencies discover new online scams
Internet fraud is always the same. Although there are more or less differences, the ultimate goal is either to defraud consumers of their money or their personal information. The biggest advantage of online shopping is that it can easily purchase overseas products across regional restrictions, so Taiwanese consumers are also likely to fall into Black Friday scams.KasperskyIn light of the recent online scams, I hope everyone will be more vigilant and be cautious.
Phishing targeting data and online payment accounts
From January to October 2021, Kaspersky’s security products alone detected more than 40 million phishing attacks, including Amazon, eBay, Alibaba, and Mercado Libre. They are the most popular bait targets, so you should be especially careful if you receive promotional and discount emails from large e-commerce platforms.

▲Phishing letters urge users to fill out fake quick opinion surveys to obtain promotional offers
Trend-wise, phishing attacks to steal account credentials from electronic payment systems saw a 208% increase in October 2021 alone compared to the previous month. While bank credentials are still a target, phishing trolls are now more likely to target online payments as the popularity of online payment systems has increased by 40% in the past two years.

Banking Trojans are gradually disappearing
Kaspersky found that cybercriminals used 11 different types of malware against online shoppers in 2021, more than half of which were variants of the Zeus banking Trojan. The more popular viruses in malicious attacks in 2021 also include Qbot (13.9%), Anubis (13.4%), Trickbot (11.6%) and Neurevt (4.8%). Another trend is that the number of people infected has dropped from 20 million in the past two years to 10 million this year. This decline is consistent with bad actors shifting their focus to online payments. Most of these Trojans are narrowly targeted and limited to specific financial institutions or platforms, so more efforts must be expended to target more potential victims.
Currently popular malware is more focused on targeting e-commerce platforms, with the aim of stealing information such as online store account credentials, credit card numbers, CVV, credit card expiration dates and phone numbers.

Ancestor trick: malicious website
There are two types of fake websites that can impact victims, the first are phishing websites that steal credentials, and the second are scam websites that are directly aimed at stealing money. In this case, bait often comes in the form of emails claiming to be sent by well-known online channels or popular e-commerce platforms and directing recipients to fake login pages.

▲Fake German version of eBay website
The second scenario involves creating a fake website that resembles a real store by copying its CSS and all content, or shopping scams that accept payment without shipping the item to the buyer. In some cases, these platforms will indeed send an empty box to the victim, only to provide a valid logistics tracking number and delay the time for users to report to the platform. This also reduces the possibility of preventing money from being transferred to the scammer’s account when users encounter shopping disputes using PayPal payment, giving scammers a greater chance of receiving these illegal incomes.

▲Scammers will also imitate the official shopping websites of some popular brands to deceive users.
How to stay safe when shopping online
During various major shopping seasons, you will see more product discounts and promotions, but the possibility that some of them are scams is higher than usual. In order to protect yourself and the money in your bank account, you should adopt a more reliable online security solution, and always be vigilant before entering payment information to carefully check whether you are spending money on a legal and safe website. If you stumble across a deal that’s too low to be true, there’s a good chance it’s a scam, even during the Black Friday shopping season.
Finally, if you use electronic payment instead of a credit card, the impact of data leakage will be less, so it can be used as the main payment method for online shopping. And because the electronic payment system uses a virtual card number mechanism, your card number will not be directly exposed, so it is safer than paying directly with a credit card or bank account. If you are shopping on a little-known small platform, you can consider using this method. If you still have to pay by bank account or credit card, be sure to verify that the amount entered is correct and closely monitor future transaction records to avoid unknowingly having your hard-earned money swallowed up.
Source: KOCPC Chinese