Site navigation

Black Friday Shoppers Warned Over Fraudulent Brand Apps

Ross Kelly

,

Black Friday fraud

As consumers gear up for Black Friday sales this year, cybersecurity experts have warned that criminals may be targeting shoppers.  

Fraudulent mobile apps that mimic the websites of some of the UK’s top retailers are creating a “feast for threat actors”, according to RiskIQ.

The apps aim to fool consumers into sharing login credentials or personal payment information while they browse the best deals available online.

Black Friday Bonanza

While the report from RiskIQ did not name the retailers popularly used by scam apps, it suggested that bad actors are using the popularity of online retailers, such as Amazon, to prey on shoppers.

“With more people than ever poised to partake in this year’s November shopping frenzy, attackers will capitalise by using the brand names of leading e-tailers to exploit users looking for Black Friday deals,” the report said.

Online shoppers spent more than $19 billion (£14.8 billion) in 2017, which presents a prime opportunity for cyber criminals to take advantage of consumers and reap huge rewards.

By setting up fake mobile apps and landing pages with fraudulent branding, hackers can fool consumers into downloading these unsafe apps and visiting pages that redirect them to other malicious websites.

Nearly 40% of the Black Friday and Cyber Monday spending influx took place on mobile devices in 2017, which RiskIQ says puts shoppers “increasingly at risk of encountering threats in the mobile space.”

This year, in particular, hackers have increasingly turned to Magecart, a repository of credit card skimming groups. Magecart has previously targeted UK-based websites such as British Airways and Ticketmaster – both of which were subjected to highly damaging data breaches.

Growing Threats

In September, RiskIQ researcher Yonathan Klijnsma said: “Magecart attacks are surging – RiskIQ’s automatic detections of instances of Magecart breaches pings us almost hourly.”

RiskIQ recorded an average of 89,837 monthly Magecart attacks between August and October 2018.

While analysing dedicated Black Friday apps, the cybersecurity company found that more than 5% of some 4,000 were found to be malicious.

Black Friday Bots

Similar Black Friday warnings have been released by UK-based identity verification and fraud preventions specialists, HooYu.

HooYu is warning businesses that during this peak period they should prepare themselves for a surge in fraud attacks.

According to the firm, one of the main reasons behind this surge is the number of high-profile data breaches during 2018. With people’s personal information in the hands of hackers, consumers should remain vigilant and watch for tell-tale signs of fraud.

Additionally, fraudsters are using technology to automate their fraud attacks, the company said. In particular, fraudsters are using bots to test stolen data to see if cards are still active. This means that hackers can monetise stolen identity data and perform attacks at both a faster pace and greater scale.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data