This holiday season checking off that gift list will look a little different than in past years. Many shoppers are planning to rely on e-commerce for a significant amount of their holiday shopping. Digital gift card sales are also likely to increase.
However, given the spike in digital activity predicted over the holidays, cybercriminals, too, will be making their lists and checking them twice. It’s a particularly risky time of the year as shoppers of all ages (including some with less experience recognising digital threats) flock to search engines and online channels to place orders before holiday delivery date cutoffs. And opportunistic hackers know just how to create enticing, seasonally-appropriate lures—and even some of the simplest scams can fool adept online shoppers.
Here are some of the most common cyber threats to prepare for during the holidays—along with a few unique outliers we’re expecting to see this season because of the pandemic.
Online holiday gift card scams
Gift cards are a common vector for cybercriminals and scammers, since stealing the money loaded onto them is like stealing cash: once it’s taken, there’s virtually no way for a victim to get it back (unlike credit card transactions, which allow chargebacks).
Around the holiday season, when gift card purchases spike, thieves are on the lookout for easy ways to take advantage. Some will go as far as to manipulate gift cards sold in stores, scratching off the layer of protective coating to write down pin numbers, and then “replacing” the coating with a sticker so it looks brand new. Scammers will plug those PINs into software that sends an alert once someone has purchased and activated their gift card—and then proceed to drain all its funds.
Another common gift card-related ploy is the account takeover attack (ATO). These attacks tend to spike around the holidays. A cybercriminal first uses credential stuffing or password spraying tactics to obtain account credentials for a particular e-commerce platform. They then use this information to make purchases on using that account information, often buying high-value electronic gift cards in bulk before promptly spending those gift cards to avoid being tracked down.
The best way to avoid becoming the target of gift card scams is to remain vigilant and follow the best practices listed below:
- Set a strong password for every online account, making sure not to repeat the same password across any two platforms. Use a password management app to keep track of different accounts. Don’t forget to use random, non-duplicate User IDs as well if the site allows. Unique usernames with unique passwords are better than just unique passwords.
- Regularly update your login credentials and monitor your payment accounts for signs of unusual activity.
- If you purchase gift cards in stores, visually inspect them for signs of tampering before loading funds and stick with retailers who keep their gift cards secured behind a checkout counter.
- Never agree to pay for online purchases in gift cards when prompted via email—in these instances, the item you’re trying to “purchase” probably doesn’t exist. Stick with retailers you know and trust, and make sure the site’s checkout system is secure. Credit cards are the best way to pay since most offer some level of fraud protection. Remember peer-to-peer transaction apps such as Paypal (for friends without payment protection), Venmo, CashApp should only be used when transactions occur between people you know and trust.
While COVID-19 has transformed the holiday season this year in more ways than one, it’s still possible to enjoy your favourite traditions safely. Thanks to digital platforms, we can connect with family and friends from the comfort and safety of our homes – and check off those gift lists without setting foot in crowded malls and shopping centres. It just requires a new level of vigilance that, itself, can become the new normal.
Stay safe online this season by remaining vigilant: Never blindly trust an email, text message, or phone call, especially those that come from unfamiliar numbers or sources. Use common sense to look out for signs of phishing. Update login credentials regularly. And, of course, pass along this information to anyone you believe could benefit from it. Education, after all, is the best weapon in fighting back against cybercrime.
By Aamir Lakhani, Global Security strategist and researcher at Fortinet.