How Fake Social Media Deals on Big Brands Steal Your Payment Data

Fake online discounts on brands like Lego and Calvin Klein on social media hide sophisticated phishing scams using malware that captures your credentials before submission.

How Fake Social Media Deals on Big Brands Steal Your Payment Data
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

Why are social media discount posts risky?

Online shoppers chasing deep discounts on popular brands via social media need to be cautious. Scammers exploit trusted platforms like Facebook and TikTok to advertise fake deals, tricking shoppers into entering sensitive information on counterfeit ecommerce websites. These scams use convincing tactics that go beyond traditional phishing emails, making them harder to detect.

How do these scams work technically?

Fake brand discounts on social media prey on shoppers' fear of missing out  - Help Net Security
Fake brand discounts on social media prey on shoppers' fear of missing out - Help Net Security

The scammers create spoofed ecommerce sites mimicking legitimate retailers or brands. Users land on these fake sites through social media posts shared in bargain-hunting groups. A key danger is the malware called BytePress embedded on these sites, which captures all keystrokes in real time—even before the user submits any form. This means usernames, passwords, credit card numbers, and one-time multi-factor authentication codes can be intercepted as they are typed.

When a victim submits information, the scam infrastructure relays it to the real retailer site, prompting legitimate authentication processes that the malware captures. This real-time interception defeats the security benefits of multi-factor authentication, allowing attackers full access to user accounts.

Who is targeted and what brands are spoofed?

The campaign casts a wide geographical net spanning at least 66 countries, with concentrated victim counts in Malaysia, Singapore, and Thailand. The attackers impersonate a broad range of 21 popular brands across cosmetics, fashion, toys, food, and baby products, extending to regional supermarkets and 36 financial institutions and banks. This diversity increases the probability of reaching unsuspecting victims worldwide regardless of their shopping preferences.

Why do victims keep falling for it?

Mathew J. Schwartz - BankInfoSecurity
Mathew J. Schwartz - BankInfoSecurity

After stealing credentials, scammers generate fake order confirmations and display them to victims. This false success signal delays victims from realizing they have been compromised, preventing quick action such as freezing their credit cards or changing passwords. The attackers gain precious time to exploit the stolen credentials for financial theft or further fraud.

What should users do to protect themselves?

  • Be skeptical of unusually deep discounts or limited-time offers on social media, especially if shared in bargain groups.
  • Verify offers by visiting official brand websites directly rather than clicking on shared links.
  • Use trusted payment methods offering fraud protection, such as credit cards with zero-liability policies.
  • Keep security software updated to detect malware activity.
  • Monitor bank and credit card statements regularly for unauthorized transactions.
  • Enable multi-factor authentication but stay vigilant as some sophisticated scams can bypass it; use hardware security keys where possible.
  • If you suspect exposure, immediately contact your bank and change your passwords.

What are the practical takeaways for staying safe?

Blog elhacker.NET: Kit Milk Dragon AiTM usa relay OTP y keylogging para  evadir MFA
Blog elhacker.NET: Kit Milk Dragon AiTM usa relay OTP y keylogging para evadir MFA

Social media can be a powerful retail tool but also an advanced phishing vector. The shifting tactic from email to social media lures requires shoppers to be extra vigilant. Always question deals that appear too good to be true, validate sources, and avoid entering credentials on sites reached via shared social media posts without independent verification. Multi-layered security practices and prompt response to suspicious activity are crucial as threat actors continuously adapt to bypass traditional safeguards.

React to this story

Related Posts