2023 Black Friday: Here’s How to Avoid This Year’s Elaborate Scams – CNET

Black Friday arrives the day after Thanksgiving. This year that means it falls on Nov. 24. It’ll be a day filled with deals on items like headphones and air fryers, but with all the potential money flowing from customers to stores, cybercriminals will be looking to get their hands on some of it.

Money Tips logo Money Tips logo

mobile-payments-visa-paywave-chip-security-credit-cards-4885.jpg mobile-payments-visa-paywave-chip-security-credit-cards-4885.jpg

Credit card skimming at one point required physical hardware, but nowadays hackers are inserting malicious code directly on retailers’ websites to steal customers’ credit card information.

James Martin/CNET

Credit card skimming goes all-digital

You’ve seen it in movies. A hacker places an object over a card reader, disguised to look like part of the ATM, and then waits for people to swipe their cards. A day or week later, the thief takes the object — known as a skimmer — back and collects the mountain of stolen card information stored inside, which they can then use to make purchases, withdraw money and more.

Instead of using physical hardware to steal payment card numbers, hackers can insert malicious code directly on a website to do the same thing as traditional skimming, but with online payment information instead.

Regarding e-skimming incidents — sometimes called Magecart attacks after the name of the software used — Tim Mackey, principal security strategist for Synopsis, a digital security company, warns, “There isn’t an obvious way for the average person to be able to identify if or when a website has been compromised. The only potential tell-tale sign might be that the website itself doesn’t quite look ‘right.'” 

Mackey suggests a few strategies you can can use to protect yourself: 

  • Don’t save your credit card information on retail sites.
  • If possible use a third-party payment method like Apple Pay, Google Wallet or PayPal.
  • Enable purchase alerts on all your credit cards.
  • Disable international purchases on all credit cards.
  • Only make purchases over your home network or cellular network, never on a public Wi-Fi where your payment could be intercepted.

Avoid the ‘Secret Sister’ gift exchange — it’s a pyramid scheme

Originating on Facebook, this sketchy gift exchange among internet strangers plays off the popular workplace practice of “Secret Santa,” a game where each person in a group buys a present for one other randomly selected group member, without the gift-giver revealing their identity. 

Instead, in Secret Sister, it’s a pyramid scheme dressed up in holiday clothes, according to the Better Business Bureau. The “Secret Sister” exchange invitation promises you’ll receive about $360 worth of gifts after purchasing and mailing a $10 gift for someone else. A variation includes swapping bottles of wine. And there’s even “Secret Santa Dog,” in which you gift money to a “secret dog.”

Unfortunately, bad math hasn’t stopped this scam from resurfacing year after year. If you fall for it, you’ll probably be out 10 bucks when you don’t receive any gifts in return. You might lose personal details too, because the scam involves sending your name, email address and phone number to people you’ve never met in person.

The Better Business Bureau recommends you deal with any request to become a Secret Sister by ignoring it — do not give your personal details to online strangers. You can also report the invitation to Facebook or whichever social network you were approached on.

Leave a Reply