This is according to research vendor Egress, who warned that threat actors will be deploying phishing campaigns to deceive online shoppers as the Black Friday online sales begin.
“In our haste to pick up this year’s bargains, many of us are guilty of being less cautious or discerning than we would be throughout the rest of the year,” said Jamie Akhtar, co-founder and CEO at CyberSmart.
“Sadly, cybercriminals know this and it’s what drives the vast numbers of phishing scams every November,” he said.
Cyber Monday, taking place on the 27th of November, is open season for threat actors as well. The security firm Cycognito warned that personally identifiable information (PII) will be at risk for many consumers.
On Cyber Monday last year, over 77 million people spent billions on deals. Along the way, customers provide PII such as credit cards, addresses, and sometimes even passports to carry out transactions.
As Cycognito points out, over half of ecommerce web apps are hosted in the cloud, which they say are not without security gaps.
“The harsh reality is that for many organisations, application security posture takes a back seat to the need to develop and deploy in time for the holiday shopping season,” said Nick Rago, field CTO at Salt Security.
Recommended reading
- Cyber Monday Sales: Scots Urged to be Wary of Online Scams
- Black Friday Scams: How to Stay Safe Online This Festive Season
- Watch Out for Black Friday Online Scams, NCSC Warns
Safety Principles
In precaution for the upcoming shopping season, Akhtar shared some general safety principles to avoid any “unpleasant surprises.”
Use MFA on all accounts, this will make it difficult for a hacker to do much damage even if they do gain access to your account.
Where possible, use a credit instead of a debit card. They offer an extra layer of fraud protection and getting back any money for bogus goods will be far easier.
Always use a secure network, don’t do your shopping at the local coffee shop.
Follow the maxim that if an offer seems too good to be true, it probably is.
Review your bank and credit card statements for unusual activity.
Seek out reviews of sellers as (although not totally foolproof) this can help you establish whether the vendor is legitimate.
Double-check emails claiming to be from vendors. Does the email address look like a real company address? Are there grammar, spelling or syntax errors? Does the branding look right? Although they get more sophisticated each year, most phishing emails will have some sort of tell.
Finally, if you’re at all in doubt, don’t click a link or buy anything from the seller. Most of the time your instincts will serve you well.





