Cybercriminals are exploiting the holiday shopping season by launching a wave of fake online shops designed to steal financial and personal information from unsuspecting consumers. These fraudulent e-shops often mimic well-known brands or create convincing new storefronts using advanced tools such as artificial intelligence to generate realistic product descriptions and reviews. Security researchers have observed a dramatic increase in blocked fake e-shop attacks, with millions of attempts thwarted globally and a 185% spike in the United States during October compared to earlier in the year. Scammers leverage legitimate e-commerce platforms and seasonal marketing tactics, such as festive banners and countdown timers, to lure victims, while also investing in targeted ads on social media platforms like Facebook and TikTok to drive traffic to their fraudulent sites.
The sophistication and scale of these scams have grown, making it increasingly difficult for consumers to distinguish between real and fake online stores. Attackers are not only after immediate financial gain but also seek to harvest personal data for future scams. Security experts recommend heightened vigilance during peak shopping periods, as the combination of urgency, attractive deals, and professional-looking sites increases the risk of falling victim to these schemes. Staying informed about the latest scam tactics and scrutinizing online shops before making purchases are critical steps to avoid financial loss and identity theft during the holiday season.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The 2025 research found that many fraudulent storefronts were hosted on legitimate e-commerce platforms such as Shopify, MyShopline, and Shoplazza, with traffic driven heavily through Facebook Ads and TikTok Ads. It also described copy-paste single-product scam shops and trust-building tactics such as SSL certificates, seeded reviews, and reused older domains.
Researchers said they blocked nearly 260,000 fake e-shop domains worldwide across October and November 2025, roughly four times the level seen during the same shopping season a year earlier. The activity was concentrated in North America, much of Europe, and Australia.
Gen Digital reported that fake online shop attacks in the United States surged in October 2025, with blocked attacks up 185% and targeted users up 126% compared with the January-September average. The report linked the increase to holiday shopping campaigns and discount-driven lures.
Avast reported a significant rise in fake online shop scams during the 2024 holiday season, with researchers blocking more than 21 million attacks globally in the last quarter. The company said criminals were increasingly using AI, brand impersonation, and social media ads to scale the fraud.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.