Chinese crooks behind one of the world's 'largest online scams'

  • Group labelled ‘BogusBazaar’ is believed to have swindled millions of pounds 

Chinese scammers using fake websites purporting to flog designer products at huge discounts are believed to have made off with the credit card details and personal data of some 800,000 people in Europe and the US, an investigation has revealed.

The ruse, dubbed by a British trading standards body as one of the largest scams of its kind ever, involves more than 75,000 websites bearing the logos of various high-end marques – from Nike to UNIQLO and Paul Smith to Cartier – that claim to sell cut-price merchandise.

English versions of the sites are accompanied by duplicates in several European languages including French, German, Spanish and Italian, designed to dupe unsuspecting shoppers from the continent to North America.

And though roughly two-thirds of them have now been deactivated, investigators believe more than 22,500 are still live and continue to trick bargain-hunting online shoppers.

SR Labs, a German cybersecurity consultancy that uncovered the scam, said that a group of programmers appeared to have created a system to rapidly generate and deploy new sites, dramatically increasing their reach.

microsoft, chinese crooks behind one of the world's 'largest online scams'

The Chinese group, labelled ‘BogusBazaar’ by SR Labs, is believed to have swindled millions of pounds, euros and dollars from their victims (stock image)

microsoft, chinese crooks behind one of the world's 'largest online scams'

Chinese scammers have used fake websites purporting to flog designer products at huge discounts to take people’s data

The Chinese group, labelled ‘BogusBazaar’ by SR Labs, is believed to have swindled millions of pounds, euros and dollars from their victims since it launched the first sites in 2015.

Around 476,000 people are believed to have shared their debit and credit card details, including their three-digit security number.

But in many cases, the scammers were not after money. Often customers were told upon checkout that their bank, or the website itself, had rejected the payment request.

Though the money may have remained in their accounts, their personal details – including full name, address, credit card number and three digit security code – were all in the hands of the scammers.

‘Data is the new currency,’ Jake Moore, a global cybersecurity adviser at the software company ESET, told The Guardian.

‘The bigger picture is that one must assume the Chinese government may have potential access to the data,’ he said.

SR Labs consultant Matthias Marx explained how a small team of programmers appeared to have created a system which can partially automate the generation and publishing of new versions of scam sites, helping the team to scale their operation at a rapid pace.

A wider team is then brought in to oversee and manages these sites in a kind of a ‘franchise’ model.

microsoft, chinese crooks behind one of the world's 'largest online scams'

English versions of the sites are accompanied by duplicates in several European languages including French, German, Spanish and Italian, designed to dupe unsuspecting shoppers

He explained that a core team develops the software and supports the operation of the network, while franchisees ‘manage the day-to-day operations of fraudulent shops.’

SR Labs chose to share the results of their investigation with German newspaper Die Zeit, who then worked with The Guardian and French outlet Le Monde to dig deeper.

READ MORE: Cyber attack targeting bank details of 250,000 British MoD workers fits Chinese ‘pattern of behaviour’ and could lead to blackmail, ex-GCHQ spy chief warns – as Beijing dismisses hacking claims as a ‘smear’ 

Their investigation found a huge variety in the brands and companies the Chinese developers were using to build their scam.

Though many of the brands were haute-couture big hitters like Christian Dior, investigators also found sites mimicking British high street favourites like shoemaker Clarks, as well as fraudulent pages catering to those with a penchant for the work of individual designers.

The products they purported to sell were not just limited to fashion, either.

Websites were found pretending to flog everything from children’s toys to homeware and garden furniture to car parts.

The sites had no connection to the brands they claim to sell and consumers who used them told the investigation that they never received the items they thought they bought.

However, the sites still managed to trick shoppers into sharing their information.

Personal data like that taken during the scams could prove valuable for foreign intelligence agencies and surveillance purposes.

This week, it emerged that up to 272,000 UK service personnel may have been hit by a data breach.

Defence secretary Grant Shapps blamed the attack on a ‘malign actor’, but failed to confirm reports that China was behind the break-in.

The cyber attacks that hit the UK

– March 2024

The UK and the United States accused China of a global campaign of ‘malicious’ cyber attacks in an unprecedented joint operation to reveal Beijing’s espionage.

Britain publicly blamed China for targeting the Electoral Commission watchdog and for being behind a campaign of online ‘reconnaissance’ aimed at the email accounts of MPs and peers.

The Electoral Commission attack was identified in October 2022, but the hackers had first been able to access the commission’s systems for more than a year, since August 2021.

– December 2023

A Foreign Office minister told the Commons that private conversations of high-profile politicians and civil servants were compromised by Russia’s principal security service during ‘sustained’ attempts to interfere in UK politics.

A cyber influence campaign by a group known as Star Blizzard, ‘almost certainly’ a subordinate of an FSB cyber unit, had ‘selectively leaked and amplified information’ since 2015.

– July 2022

The British Army confirmed a ‘breach’ of its Twitter and YouTube accounts. The channel featured videos on cyptocurrency and images of billionaire businessman Elon Musk.

The official Twitter account had retweeted a number of posts appearing to relate to NFTs (non-fungible tokens).

– July 2021

The UK accused the Chinese government of being behind ‘systematic cyber sabotage’ following a hacking attack which affected a quarter of a million servers around the world. The attacks, which took place in early 2021, targeted Microsoft Exchange servers.

– April 2021

Britain accused Russia’s foreign intelligence service of being behind a major cyber attack on the West.

The Foreign, Commonwealth and Development Office (FCDO) said the National Cyber Security Centre (NCSC) had assessed that it was ‘highly likely’ the SVR was responsible for the so-called SolarWinds hack.

– July 2020

Britain, the United States and Canada accused Russian spies of targeting scientists seeking to develop a coronavirus vaccine.

The three allies said hackers linked to Russian intelligence were seeking to steal the secrets of research bodies around the world, including in the UK.

Read more

OTHER NEWS

15 minutes ago

Who's qualified for Champions and Europa League as Man Utd and Chelsea's fate in balance

19 minutes ago

Rankings QBs on Steelers' Schedule

19 minutes ago

Minister orders probe into fatal Ballito construction collapse

19 minutes ago

BC Wildfire Service talks wildfire safety, how wildfire fighters are preparing for the season

19 minutes ago

Caitlin Clark adjusting to the WNBA, finishes first week on a high note

19 minutes ago

MAGA Republican Elise Stefanik loses it with Fox News host: ‘This is a disgrace!’

19 minutes ago

Erik ten Hag: Everyone knows why Manchester United recorded worst ever Premier League finish

19 minutes ago

Huddersfield Giants coach confirms injury blow following Challenge Cup semi-final defeat

19 minutes ago

Van Dijk fights off tears as Jurgen Klopp makes emotional statement, welcomes Arne Slot to Liverpool

19 minutes ago

How To Turn An Old Laundry Basket Into A Beautiful Decorative Planter

19 minutes ago

Jesus is their savior, Trump is their candidate. Ex-president’s backers say he shares same faith and values

19 minutes ago

REPORT: Matvei Michkov Could Join Flyers This Summer

19 minutes ago

2 highly rated ASX growth shares to buy before it's too late

19 minutes ago

Breiden Fehoko Thinks Calvin Austin III Will Breakout in Year 3

19 minutes ago

Seahawks OTAs underway this week: What you need to know

20 minutes ago

Scottie Scheffler ‘running on fumes’ after strong finish at US PGA Championship

21 minutes ago

US troops to leave Niger by mid-September: Officials

21 minutes ago

Woman denied pretrial release after allegedly orchestrating Bridgeview man's murder

21 minutes ago

Professional Faqs: Are There Any Contraindications With Taking Ashwagandha While On Antidepressants?

21 minutes ago

Eagles Need More From Jordan Davis But Don't Downplay His Importance

21 minutes ago

Bruins' Jake DeBrusk Linked to 3 Teams

21 minutes ago

The Hidden Downside of Always Flying Basic Economy

21 minutes ago

Jake Gyllenhaal Sings Rendition of Boyz II Men's ‘End of the Road' in ‘SNL' Season Finale: Watch

21 minutes ago

Preakness winner Seize the Grey is likely running in the 1st Belmont at Saratoga

21 minutes ago

Aleksander Barkov, the Panthers' reluctant star, leads without having to say much

21 minutes ago

Jurgen Klopp sends message to Man City after parting shot at champions' 115 charges

21 minutes ago

Bruce Nordstrom, who helped grow family-led department store chain, dies at 90

22 minutes ago

Kansas City Chiefs On Cusp Of NFL History Nearly 100 Years In The Making

22 minutes ago

Earth-size planet found orbiting nearby star that will outlive the sun by 100 billion years

22 minutes ago

Fresh fears 'Satanists' have returned to torment picture postcard New Forest village after severed deer head is left dangling from a high street lamppost -in the latest 'sacrificial killing' linked to suspected Devil worshippers

22 minutes ago

Father of boy, 13, who drowned in the River Tyne tells of his anguish after the death of another lad, 14, on the same stretch of water and says tragedy has 'brought back memories' of his ordeal

22 minutes ago

Auburn running back Brian Battie 'left in critical condition' after shooting in Florida that killed his brother Tommie

22 minutes ago

Guardians receive positive injury update on Steven Kwan

29 minutes ago

Father of boy, 13, who drowned in the River Tyne tells of his anguish after the death of another lad, 14, on the same stretch of water and says tragedy has 'brought back memories' of his ordeal

29 minutes ago

Antiques Roadshow guest freezes in shock after hearing five-figure price of painting left by her great-grandfather

30 minutes ago

Blood scandal was preventable and compensation is too late, say victims’ families

30 minutes ago

Angela Rayner probe won’t be drawn into ‘political spats’, says police chief

30 minutes ago

PGA Championship 2024 live updates: Xander Schauffele leads cluttered leaderboard

30 minutes ago

Dali ship that crashed into Baltimore’s Key bridge to be removed from collapse site ‘within days’

30 minutes ago

Alek Manoah shines over seven innings as Blue Jays fend off Rays 5-2 to avoid sweep

Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch