China scammers steal $50 million through fake webshops in ring

May 18, 2024
1 min read

TLDR:

China-based fraudsters operating tens of thousands of fake webshops called ‘BogusBazaar’ stole credit card details of hundreds of thousands of Western shoppers, earning tens of millions of dollars in fake orders. The scam ring runs a decentralized Fraud-as-a-Service operation, targeting individuals in the United States and Western Europe by selling shoes and apparel from well-known brands at low prices. SRLabs has shared findings and a tool to help buyers identify dubious online stores, urging caution in online shopping to avoid falling victim to scams.

Article Summary:

Fraudsters operating tens of thousands of fake webshops stole credit card details of hundreds of thousands while also earning tens of millions of dollars in fake orders. The fake online shops called ‘BogusBazaar’ tricked over 850,000 people, allowing the criminals to steal credit card information and attempt to process an estimated $50 million in fake orders.

SRLabs discovered that the massive webshop fraud ring steals credit cards from individuals in the United States and Western Europe and rarely from China, their primary operating base. The fraudsters harvest credit card details from spoofed payment interfaces before redirecting victims to legitimate payment gateways and initiating transactions.

The fraudsters operate a “Fraud-as-a-Service” operation consisting of a core team that manages infrastructure and affiliates who operate the webshops. The core team develops software and backend systems, and customizes WordPress and eCommerce plugins while also running a few fake webshops, likely for testing purposes.

The criminal ring also decentralizes infrastructure by running fake webshops, payment gateways, and management applications on separate servers. This strategy allows them to rotate checkout pages rapidly without changing storefronts when payment pages are taken down for fraud.

SRLabs has shared its findings with authorities and relevant entities and has also shared a Fakeshop Finder tool for German buyers to identify dubious online stores involved in the massive fraud campaign. Buyers are urged to be cautious and check for authenticity before making purchases from online stores.

Latest from Blog

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is

Get ready for a cyber attack with NewsRadio 740 KTRH

TLDR: A cyber attack recently caused a global outage of numerous Microsoft business products, highlighting the vulnerability of our technology infrastructure. Cyber security expert Matt Malone believes that the incident could serve