News

Beware of Holiday Shopping Frauds and Malware Scams – How to Avoid it

US-CERT alerted users to stay aware of online shopping frauds and malware campaigns that mimic popular brands, fake advertisements and offers.

Attackers can deliver sophisticated malware through email campaigns that result in financial loss, security breaches & loss of PII.

“As this holiday season approaches, the Cybersecurity and Infrastructure Security Agency (CISA) encourages users to be aware of potential holiday scams and malicious cyber campaigns, particularly when browsing or shopping online,” says CISA.

CISA also warns that threats actors may send a spoofed email requesting you to support for fraudulent charities or causes. Users should be vigilant in accessing those emails.

Holiday Online Shopping Frauds

Europol warns users to be aware of ads in instant messaging or social media that claim to be offering tickets, email advertisements and gift cards received. “Think twice before clicking on any emails as they could direct you to a fraudulent site or infect your device with malware.”

It is always recommended to buy the tickets from the official website, venue’s box office, reputable ticketing website or through official agent or partner.

Beware of the advertisements that offering you a service at a very low price and ads that urge you to pay quickly for additional discounts.

  • Before making bookings, check it is a reputable website.
  • Ensure the payment processed over HTTPS.
  • Check for user reviews
  • Pay attention to the website name and domain
  • Check for website contact details and validate them

Holiday Malware Campaigns

Users should be aware of unsolicited emails that contain malicious links or attachments as malware, links for the malicious site or fraudulent domains.

Beware of the Fake apps that promises you to get additional discounts, these bogus apps may enter into official play store also, be careful while installing those apps. It’s easier anyone can fall prey into cyber scams, always go with the reputable vendor.

  • Avoid clicking of links or opening attachments.
  • Use reputable Internet Security products.
  • Don’t use public Wi-Fi.
  • Beware of social media pleas, calls, texts and websites.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago