Over 850,000 people hit with online shopping scam that steals credit cards — how to stay safe

Even though shopping online has now become the norm, you still need to be careful when buying products from lesser-known stores, as doing so could lead to hackers stealing your credit card information.

Case in point, the German cybersecurity firm SRLabs recently uncovered a massive network of 75,000 fake online shops called ‘BogusBazaar’, which over the course of three years, tricked more than 850,000 people into buying $50 million worth of fake goods.

As reported by BleepingComputer, online shoppers duped by these fake stores also had their credit card details stolen and then resold on the dark web. Not only can this lead to additional fraud but the information used at checkout on these fake online stores could be used to commit identity theft.

Whether you’re an avid digital shopper or just occasionally buy things from the web, here’s everything you need to know about this huge network of fake stores and how you can stay safe when shopping online.

Using expired domains to launch fake online stores

how to, amazon, over 850,000 people hit with online shopping scam that steals credit cards — how to stay safe

((Image credit: SRLabs))

According to SRLabs’s report on the matter, most of BogusBazaar’s victims live in either the U.S. or Western Europe. Surprisingly, there are virtually no victims from China where the operation is likely located.

Since 2021, the cybercriminals behind BogusBazaar have launched more than 75,000 fake online stores. They do this by setting up these shops on previously expired domains with a good reputation, ensuring their fake stores show up in search results.

As seen in the picture above, most of these fake stores pretend to sell shoes and other apparel at very low prices. Likewise, they use custom names and logos to appear more legitimate.

Even though the stores themselves are fake, the cybercriminals running this operation used PayPal, Stripe and legitimate credit card processing services. In order to steal money and data from their customers, the operators of BogusBazaar have also developed custom WooCommerce WordPress plugins. For those unfamiliar, WooCommerce is a free plugin for WordPress that turns any site into an online store and is often used by the best website builders.

The group behind BogusBazaar is using an infrastructure-as-a-service model where a core team manages the operation’s infrastructure while the fake stores themselves are operated by a large, decentralized network of franchisees.

While the operation itself is believed to be headquartered in China, the servers used for these fake stores are mostly located in the U.S. As such, it likely won’t be long until we hear about how government agencies took them down in order to disrupt the entire operation.

How to stay safe when shopping online

how to, amazon, over 850,000 people hit with online shopping scam that steals credit cards — how to stay safe

((Image credit: Shutterstock))

Even though you may want to support small businesses online, a story like this one could make you reconsider buying products from unfamiliar stores.

While you could stick to large online retailers like Amazon, Best Buy and Walmart in order to stay safe online, sometimes it can be difficult to find more niche products at these larger online stores. For this reason, there are a couple of things to keep in mind when shopping at an unfamiliar online store.

To confirm that a store is actually real, you want to check out its contact information, examine the return policy, look for trust seals, browse through the entire site and also check its social media. This will help you avoid fake stores overall.

As BleepingComputer points out, many of the fake stores in this BogusBazaar operation use the same template: items are listed with their original prices crossed out and a new sale price—often more than 50% off—next to them. You can use the example image above from SRLabs to weed out fake stores from this campaign, too.

When shopping online, you also want to read reviews and use an online shopping checker like this one from F-Secure or even Bitdefender’s Scamio before you head to checkout.  There are some other signs to look out for, too, which include examining a store’s URL for spelling mistakes and other errors, poor quality pixelated images, poor website design and an overly complex or non-existent return policy. The biggest red flag, though, is highly discounted prices. If a deal seems too good to be true, it likely is. This is why you want to price-check any products you’re shopping for online before pulling the trigger.

Just like malicious apps and phishing attacks, fake online stores have been used by cybercriminals, scammers and other hackers for years to dupe unsuspecting shoppers. It’s up to you to look at them carefully and determine whether what looks to be a great deal is worth having your credit card information or identity stolen.

More from Tom’s Guide

    OTHER NEWS

    22 minutes ago

    Jerry Seinfeld heckled by pro-Gaza protester at stand-up comedy gig

    22 minutes ago

    Inflation flattens Americans' wealth gains under Biden: report

    23 minutes ago

    Opinion | Gavin Newsom’s Battleground Gift to Donald Trump

    23 minutes ago

    ESPN Faces Serious Accusations of 'Knicks Bias' During Sunday's Game 7 Broadcast

    29 minutes ago

    Harry Styles 'SPLITS from Taylor Russell' as pair call time on 14-month romance following make-or-break trip to Japan - weeks after friends claimed 'he wanted children' with the actress

    29 minutes ago

    Rishi Sunak to apologise for worst treatment disaster in NHS history.. as devastating report will lay bare failing over infected blood scandal that's claimed 3,000 lives

    29 minutes ago

    Video: Introducing Rezon! Kyle Walker brings his baby boy onto the pitch as wife Annie Kilner arrives with their four sons to support footballer at Manchester City match

    29 minutes ago

    Video: Roberto De Zerbi will LEAVE Brighton at the end of the season, but 'is NOT taking over at Bayern Munich' after German side distanced themselves from move

    29 minutes ago

    Video: Sheffield United 0-3 Tottenham: Spurs SECURE Europa League football for next season as Dejan Kulusevski's brace and Pedro Porro's thumping strike finish off their season in style

    29 minutes ago

    Video: Jurgen Klopp addresses his Liverpool players for the final time in emotional dressing room scenes... as his nine-year reign at Anfield comes to an end: 'I'm so proud of you'

    30 minutes ago

    Aubrey O'Day blasts former mentor Diddy for not saying sorry to Cassie in his apology video: 'Leave God and mercy out of this!'

    30 minutes ago

    Amy Jackson turns heads in an elegant black evening gown with huge bouffant sleeves as she attends the 77th Cannes Film Festival premiere of Horizon: An American Saga

    31 minutes ago

    Maryland governor signs Biden-inspired bill establishing 'Center for Firearm Violence Prevention'

    31 minutes ago

    Fanatics files lawsuit against Marvin Harrison Jr for breach of contract

    32 minutes ago

    Mike Tyson vs Jake Paul: 57-year-old boxing legend has request for fight granted

    33 minutes ago

    Why Eurovision results are about more than just the best song

    33 minutes ago

    Bayer Leverkusen writes more history in first ever unbeaten Bundesliga season

    33 minutes ago

    Recall on promotional tumblers handed out as free gift with Nütrl drinks at LCBO

    34 minutes ago

    ‘The Substance’ Review: Demi Moore And Margaret Qualley Pair Up For The Year’s Smartest, Goriest Horror Breakout – Cannes Film Festival

    36 minutes ago

    Westfield Fountain Gate stabbing: Woman allegedly knifed while waiting for a bus in Narre Warren, Melbourne

    36 minutes ago

    Emma Raducanu WITHDRAWS from the French Open to focus on training to give herself 'a chance to keep fit for the rest of the year' - having only just returned from an eight-month absence in January

    36 minutes ago

    Courtney Lawes is still laying down the law, and a young wing wizard casts a spell... WORLD OF RUGBY - SEASON REVIEW

    36 minutes ago

    George Takei remembers horrors of Japanese internment camp: ‘We had nothing’

    36 minutes ago

    Long Island teacher accused of tying autistic, nonverbal teen to a chair — and school waited to tell parents

    37 minutes ago

    Erik ten Hag reveals his half-time tactical tweak that helped Manchester United beat Brighton

    37 minutes ago

    Brooks Koepka leaves PGA Championship wondering what could've been after ugly Saturday

    37 minutes ago

    Oleksandr Usyk beats Tyson Fury to become undisputed world heavyweight boxing champion

    37 minutes ago

    Rio Ferdinand questions how long Arsenal board will accept silver medals under Mikel Arteta

    37 minutes ago

    UCLA locks doors on conservative students, preventing them from hosting pro-Israel event: YAF

    38 minutes ago

    PGA Championship 2024: This year's low club pro plans to drive 10 hours through the night to make another tee time

    38 minutes ago

    Indiana Fever Coach Addresses Caitlin Clark's Frustration With Teammates

    38 minutes ago

    Why Orlando Pirates lost to TSG – Vincent Pule

    38 minutes ago

    Gupta associate fails to stop final sequestration

    38 minutes ago

    American Eagle Embraer E175 Diverts To Philadelphia International Airport After Mechanical Issue

    38 minutes ago

    Blinken orders crackdown on Israel-Hamas leaks

    38 minutes ago

    Saudi offers Iran 'any assistance' needed in Raisi helicopter search

    40 minutes ago

    Ducklings trapped in storm drain rescued by Vernon firefighters

    42 minutes ago

    Video: Chrishell Stause looks sensational in busty lavender dress as she takes Netflix event by storm with the stars of Selling Sunset and Love Is Blind

    44 minutes ago

    Soccer-Feyenoord send off coach Slot with banners and victory

    44 minutes ago

    Parties share R200m two weeks before elections

    Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch