Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Scammers Spoof Target’s Gift Card Balance Checking Page

Scammers Spoof Target’s Gift Card Balance Checking Page

It’s the giving season, and cybercriminals are more actively looking to steal gift cards. One of the most popular brands in their sight is giant retailer Target.

A trick that crooks are currently pulling is to lure victims to fake sites that check the balance on the gift card.

Retail and gaming brands are at the top of scammers’ list of preferences these days as gift card sales register a sharp growth.

According to online fraud prevention company Bolster, November saw new websites related to gift card fraud at a rate of more than 220 per day. 

gift card fake sites

Also Read: Advisory Guidelines on Key Concepts in the PDPA: 23 Chapters

Fake Target gift cards balance check

Bolster’s research team note that online scams involving gift cards are predominantly impersonating Target’s balance checking pages. Some attempts are more credible than others.

In one example, the fraudsters are imitating Target’s service to such an extent that most users would not see any difference between the fake website and the legitimate one in terms of layout, text, and colors.

Even more, the crooks also registered a domain targetgiftscard[.]com, which makes it difficult to spot the scam. The only red flags are the links, which either don’t work or point to the same fraudulent page.

Target gift card balance check

After typing in the gift card and access numbers and hitting the “check balance” button, the information gets to the fraudster.

To keep up appearances, the site displays the “checking balance” status indefinitely. Alternatively, an error pops up to mislead the victim that something went wrong, and the verification failed.

“In reality, the valid gift card numbers are harvested by the criminals and monetized by either reselling them on other sites or using them to make purchases”

– Bolster

The researchers note that a regular user would easily miss the signs revealing the sham. Noticing the red flags requires background information on Target and with some technical abilities.

For instance, the domain is similar to others belonging to Target (giftcard.com and giftcards.com) and would raise suspicions when checking if it was indeed registered by the retailer.

What the researchers found was that an entity in New Delhi, India registered the fraudulent site and that its IP address (used in the past in phishing campaigns) is shared with other businesses in India.

Bolster also discovered less advanced gift card scams that may not fool most users because the imagery is different than what the retailer uses.

Fake Target gift card balance check site

Survey scam with gift card bait

In another scam, fraudsters lure victims with the promise of getting a gift card if they fill in a survey. They choose popular brands like Amazon, Google, Pizza Hut, or Walmart.

Gift card lure

Bolster found more than 1,000 sites baiting users in this way, with domains that follow the same pattern ([fakedomain]/​free-[brandname]​.html). This suggests that the same group may be behind all of them.

  • liveoffer.online/​free-aliexpress-gift-cards[.]html
  • liveoffer.online/​free-bathandbody-gift-cards[.]html
  • gamer007.club/​free-forever21-gift-cards[.]html
  • wepromocode.com/​free-amazon-gift-cards[.]html
  • promohub.xyz/​free-google-play-gift-cards​[.]html
  • real-giveaway.com/giftcard/​free-hbo-gift-cards​[.]html

Although filling in a survey may not appear too dangerous, there are risks. Apart from giving away personal information (name, address, phone number, email, date of birth, demographic data, spending habits, insurance, car, healthcare preferences), victims are also likely to incur financial damage.

Also Read: Letter of Consent MOM: Getting the Details Right

In some cases, victims need to agree to receive calls and marketing messages to get to the survey and the promised gift card.

Gift card survey scam terms

In the end, what the victim gets is a never ending stream of surveys. And the scammers take a commission for each survey the victim completes.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us