Analysis of hundreds of millions of web pages found phishing and fraudulent sites using the Amazon brand and logos poised for big Prime Day sales, according to Bolster Research.
Image: iStock/OrnRin
It’s bigger than Black Friday and Cyber Monday combined: Amazon Prime Day, the mega-site’s biggest annual retail event. For two days, Oct. 13-14, special sales are offered across departments. With shopping malls still closed and other retail stores operating with reduced hours and limited capacity due to COVID-19, Amazon may see its biggest Prime Day yet. But a new report reveals that cyber criminals are poised and ready to take advantage of enthusiastic shoppers who might not be paying close attention to the link they’re clicking on, anxious to get a good deal.
SEE: Identity theft protection policy (TechRepublic Premium)
Analysis of hundreds of millions of web pages led to tracking new phishing and fraudulent websites using the Amazon brand and logos–the fake sites are trying to replicate the actual Amazon site in the hopes of hacking into the unsuspecting “customer’s” personal information.
Bolster Research used deep learning, natural language processing and computer vision to determine what is informational and what is used to reveal logins, passwords or credit card information.
Bolster is confident that protests at Amazon CEO Jeff Bezos’ house won’t deter shoppers from taking advantage of Prime Day: “This year’s Prime Day will likely be the biggest ever, and the protests against Amazon will have zero effect,” said Abhishek Dubey, co-founder and CEO of Bolster. “People are shopping online, and nobody can resist a good deal.”
SEE: Amazon Prime Day 2020 is Oct. 13-14: How to get the best deals (TechRepublic)
Bolster provided a chart of the new, monthly phishing and fraudulent websites, created using the Amazon brand, showing a spike in March at the start of the pandemic, dipped in April, but has pretty much risen to the year’s so-far high in August.
Image: Bolster
Criminals–at least successful ones–are well prepared. “Criminals were likely gearing up for the originally anticipated Prime Day being in July like last year,” Dubey said. “However, when it was delayed, they probably just put those plans on hold. Creating a fake site to steal information or harvest credit cards doesn’t take too much effort. The planning probably occurred a couple months in advance, but the execution of the fraud campaign likely occurs within a week or two before the actual Prime Day to avoid detection.”
The phishing campaigns not only attempt to very closely resemble an actual Amazon page, but choose oft-used actions and verbiage. For example, one campaign targets Amazon “returns” or “order cancellations” related to Prime Day.
For example, www.amazoncustomersupport.net, is clearly designed to mimic an authentic Amazon site, and the webpage could easily fool an unsuspecting shopper.
“The biggest sign it is a scam is the URL,” Dubey said. “One technique that criminals are using is to create fake URLs that are long so you can’t really tell what the domain is. For example, you may be directed to a link that looks something like “amazon.com/prime_day_deals/xyz.info.” Shoppers may see the “amazon.com” and think this is a legitimate site, but a closer look shows that this page is hosted on the “xyz.info” domain. “
Image: Bolster
While there are companies that offer Amazon “reviewers” free products for a review (the disclaimer should be included in the posting), Amazon is not a “sweepstakes” kind of website, and you won’t find discounts on Groupon or coupons on RetailMeNot. So, when a seemingly Amazon page claims to be from a loyalty program and offers a free iPhone in return for answering a few questions, close the page.
The questions are no-brainers, and then users are directed to a game that seems challenging, but surprise! They win. They’re then required to enter credit-card information so they are charged $1 to receive the phone, which will arrive, courtesy of a courier, in five to seven days
The “free iPhone” is supposedly validated by reviews of other Amazon customers who received the phone. Sadly, the reviews were fake and the phone will never arrive, but the customer will begin to see strange charges on the credit card they used.
Image: Bolster
SEE: Social engineering: A cheat sheet for business professionals (free PDF) (TechRepublic)
Cyber criminals must keep apprised of new trends, which will help them in their efforts to phish and defraud. Prime Day 2019 yielded more than $7 billion in sales during the 36-hour sales event. And because of COVID-19 and the brick-and-mortar retail situation, 2020 is looking fresh to hackers. It’s time to be hyper-aware.
There are few who are fully flush with coin, who can purchase whatever they want for whatever price. But being smart and vigilant will get shoppers authentic good deals, and protect privacy and personal information from malicious bad actors.
It’s in Amazon’s interest to shutdown and/or catch these cyber criminals. “Amazon is likely anticipating these attacks, and they likely have a team to monitor and assess this problem,” Dubey said. “I don’t think they will issue warnings to customers since that would give the impression that they do not have a handle on this problem.”
Dubey also noted that the only recourse for customers who are scammed is “is through their credit card or financial institution. Some payment cards have online shopping guarantees and protection for consumers for unauthorized charges.”
Amazon can take control: “Amazon can shut them down by working with the hosting companies,” Dubey explained. “The challenge is finding the sites and then submitting the documentation to have them taken down. The process is often manual, and companies are not able to keep up with the sheer volume of phishing and fraud sites. Using artificial intelligence (AI) to find and assess the fraudulent nature of these sites and automating the takedown process allows companies to keep up with the criminals.” He added that Bolster “can scale to take down thousands of sites per hour.”
Finally, Dubey warned, “Prime Day can be a frenzy because inventory does run out. In their goal not to miss out, people do often overlook signs such as low resolution/blurry images or graphics or a completely new site layout they have never seen before. Another sign people may not notice is the changes in location of buttons or links. For example, no matter where you are on the Amazon site, the shopping cart is always on the upper right. It will likely not be there on a fake site, but people miss these small details and just assume that it’s a special page for the Prime Day event.”