1) Stop chasing any and all deals
“We live in an age where we have all these push notifications and emails,” said Steve Koenig, senior director of market research at the Consumer Technology Association, a trade group in Arlington, Va.
The volume of such activity during the holidays, he said, only makes consumers even more vulnerable to clicking on a $100 coupon before thinking twice.
“We’re all moving super fast, we get distracted,” said Tim Helming, director of product management at DomainTools.
When we’re rushing, we might not notice that the website in an email has an odd name.
Brands that continue to be spoofed include Amazon,Walmartand Target. Other brands that are commonly targeted include PayPal, Yahoo and Apple.
Helming told me that consumers need to be wary of fake sites that play up the “Black Friday” frenzy. Dozens of malicious domain registrations that touted a Black Friday connection cropped up last year beginning around Nov. 20, and he’d expect the same this year, too.
2) Learn how to spot a fake
Watch out for a domain decorated with a few extra, possibly even reassuring words or odd spellings. DomainTools listed some brand-abusing domains that have a dot-com at the end but they’re still frauds, such as Amazonsecure-shop, Target-officialsite or Walmartkt.
Other fakes include: Amazonshop.gq or Targethome.today or Walmart-outlet.ga.
Helming said domains that include a hyphen and words such as shop or secure can be good clues to a phony site, as many brand names use their names alone for their sites.
Other words in a fake URL site that appears to be connected to a well-known name might be something like outlet, discounts or deals.
Many times, the fraudsters use words like “official site” to make their fake sites look legitimate. Or there might be extra letters, such as “Yahooo” or “Walmaart.”
Take care on social media. Phishers can use of “URL shortening” services to obfuscate phishing URLs. As a result a very short URL, can be used in Tweets, which automatically redirect the visitor to a longer “hidden” URL, according to the Anti-Phishing Working Group’s research.
3) Recognize the risks of rushing
Consumers who click on the links or visit malicious sites are typically unknowingly handing over their name, address, and credit card information.
Never click on links in emails or social media to go to a retailer’s website. A better bet: Take a few extra seconds to go directly to the site yourself. Be sure to take a second look at all URLs.
4) Ask yourself why would Amazon be sending you a free gift card? Really?
Yes, one of those free $50 Amazon gift cards popped up in my email the other day. Of course, it’s a spoofed email. So I just hit delete.
Amazon is warning consumers that phishing emails will direct you to a “false website that looks similar to the Amazon website, where you might be asked to provide account information such as your e-mail address and password combination.”
The fake sites can steal sensitive information that can be used without your knowledge to commit fraud, according to Amazon.
Phishers can steal usernames and passwords from one site to engage in fraud on other sites. Too many consumers carelessly use the exact same usernames and passwords across different sites.
Amazon doesn’t send emails that ask for your Social Security number, bank account information, PIN, or your Amazon.com password.
Amazon offers shoppers a way to report suspicious emails and web pages. You can forward the email or send suspicious e-mail as an attachment to firstname.lastname@example.org.
More: Are 2017’s Black Friday deals really as amazing as retailers claim?
More: How to find hard-to-get, out-of-stock gifts without getting ripped off
5) As you order gifts online, don’t get tripped up by fake email alerts
As holiday shipping goes up in November and December, the frequency of phishing emails relating to orders or shipments goes up, too.
Walmart warns that if you received an order confirmation email from Walmart but never placed such an order, it may be a “phishing scam attempting to gather information, or in some cases, spread malware.”
FedEx warns consumers about a “delivery failure” scam email.
Fraudulent emails claiming to be from FedEx or the U.S. Postal Service “regarding a package that could not be delivered.”
The consumer is then asked to open an attachment in order to obtain the invoice needed to pick up their package. The attachment in the email may contain a virus.
Don’t just rush and assume there’s trouble with something that you ordered.
“Be suspicious of incoming email from unknown or unsolicited sources, especially those that have attachments as well as hyperlinks,” said Jeremy Stempien, detective for the City of Novi, Mich., and a special federal deputy marshal for the Southeast Michigan Financial Crimes Task Force.
“The same should apply to incoming phone calls,” he said.
6) Every deal you find online is not a bargain
Con artists tempt consumers with great deals on hard-to-find items or hot gifts. Maybe you’ll spot some extraordinary deal on an Apple iPhone X or find a crazy bargain price on an L.O.L. Surprise! Big Surprise toy.
Or you think you’ve found a great deal on jewelry. The Better Business Bureau and others warned in 2017, for example, about fake sites that offer up to 70% off on Pandora charms.
Charisse Ford, chief marketing officer for Pandora Americas, said shoppers should be aware that counterfeit sites have some clear indicators, including the “About Us” page that can be very generic without descriptions about the business, company mission or current Pandora images or promotions.
Another clue: Try calling and talking with someone in customer service first before placing an order to ask about return policies or the like. Shoppers are less likely to connect with a real person if going through a fraudulent site.
Companies such as Pandora note that they work hard to help identify and shut down counterfeit sites, including those on social media channels.
Con artists use phony websites to sell counterfeit goods — or engage in cybercrime.
It’s no bargain if, when you click on the link, you download malware.
“You think you are getting the discount of a lifetime or an exclusive offer, but this is a phishing attack,” warned Adam Levin, author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers and Identity Thieves.
Remember, bargains abound throughout the holiday season — so there’s no reason to think you absolutely must get all that shopping done right now.