Researchers identified a high-severity social-engineering and online-fraud campaign in which shipping-rebate offers, retailer promotions, checkout prompts, and browser pop-ups allegedly enroll consumers into recurring paid memberships. The campaign uses shipping-themed brands and domains including free-shipments.com, freeshipments.com, freeshpmts.com, myshipmentsfree.com, shipmentfree.com, shipmentsfree.com, shipmentsfreeclub.com, and shipmentsfreezone.com, with similar account pages, policy language, and support details suggesting operational overlap.
Consumers reported discovering recurring charges of roughly $25 per month after accepting offers they believed were limited to shipping rebates. ShipmentsFree's Better Business Bureau profile reportedly recorded 529 complaints over three years, including 179 categorized as billing issues. Affected users should retain offer, enrollment, cancellation, and charge evidence; cancel through verified official channels; request consent and billing records; and dispute charges with their card issuer if authorization was absent, terms were misleading, or billing continued after cancellation.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers documented ShipmentsFree as a shipping and return rebate service offered through an auto-renewing paid subscription. Their analysis linked multiple shipping-themed domains with shared branding, account pages, policy language, and support details, while consumer complaints described unrecognized recurring charges of about $25 and unclear enrollment terms.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.