Date: November 07, 2024
Satori researchers have issued an urgent warning to Chrome, Safari, Edge, And Firefox Users after over 10 million were stolen from online shoppers.
Human’s Satori Threat Intelligence and Research team has revealed an ongoing sophisticated scam dubbed Phish ‘n’ Ships, which estimates that tens of millions have been stolen from online shoppers in the last five years. The threat actors have infected over 1000 legitimate online shopping websites with genuine products listed with too-good-to-be-real offers and discounts.
Victims were redirected from the legitimate website to a fake one that was extremely difficult to identify. Considering the core source of redirection was a genuine website with global authority, the victims did not experience hesitation in completing their transactions on fake payment portals. The orders were placed successfully, and no product was ever arriving.
The UK government’s security agency estimates millions of victims have been without much support over the years as they manually enter their credentials and transaction passwords. The dangerous campaign has managed to inflate search signals to relatively new, malicious websites, which has helped the rankings of the fake websites grow rapidly. Over 121 fake web stories have been identified, tricking users with genuine products at unreal prices to redirect them to fake portals. Some of the 1000 fake websites are still active despite their identification as being shared with popular search engines.
Google has removed all the websites working on the threat campaign. But that’s not enough. Microsoft’s Bing has only a 4% market share of online searches and acts as a great alternative to Google in conducting fraudulent campaigns. In some cases, the fake websites were indexed on top search engines much before the original ones did. What worries the agency most is that these attacks are expected to expand to AI search results as it is much more prone to show falsely worded information.
“This operation underscores the relationship between the digital advertising ecosystem and fraud. Without the threat actors’ staged fake organic and sponsored product listings, there would have been no traffic to the fake web stores and, therefore, no fraud. A key takeaway from Phish ‘n’ Ships is that digital advertising can be dangerous, and consumers should exercise caution when clicking through to the next step in a digital journey.”
- Satori
NCSC has issued a warning to legitimate companies that digital ad campaigns can expose their customers to fraud if they don’t introduce countermeasures against malvertising. The warning also underlines the responsibility of facilitating the platform’s technology to support fraudulent digital advertisers without adequate verification methods.
Even the best internet browsers are unable to provide support, as the scam primarily revolves around consumer trust and manual redirection to fraudulent websites. As a measure, Satori has sent notifications to all federal agencies to populate the warning to billions of online shoppers and raise awareness as an immediate measure.
By Arpit Dubey
Arpit is a dreamer, wanderer, and tech nerd who loves to jot down tech musings and updates. Armed with a Bachelor's in Business Administration and a knack for crafting compelling narratives and a sharp specialization in everything from Predictive Analytics to FinTech—and let’s not forget SaaS, healthcare, and more. Arpit crafts content that’s as strategic as it is compelling. With a Logician mind, he is always chasing sunrises and tech advancements while secretly preparing for the robot uprising.
Reddit Unveils AI-Powered Search Tool for Smarter Results
Reddit launched Reddit Answers, an AI-powered search tool that curates and summarizes discussions to enhance user experience and reduce reliance on Google.
OpenAI Scraps o3 Model, Pushes for Unified GPT-5 in a Major AI Overhaul
OpenAI is canceling its o3 AI model and merging it into GPT-5 for a simpler, more powerful system. A big move to stay ahead in the AI race.
Virtual Reality in Healthcare: Revolutionizing Patient Care
Experience the power of virtual reality in healthcare as it transforms medical training, patient care, and treatment methods with immersive technology for better accuracy, efficiency, and improved outcomes.
Google I/O 2025: Dates Announced for the Tech Giant’s Biggest Event of the Year
Google I/O 2025 is set for May 20-21! Expect big AI reveals, Android 16 updates, and more. Registrations are open for keynotes, demos, and game-changing tech innovations!