
Fake iPhone Crypto Wallet Stole $1.8M
Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…
A network of more than 120 convincing Walmart lookalike websites is luring mobile shoppers with “40% to 70% off” discounts on name-brand liquor. Victims are funneled to checkout pages that collect full credit card details (number, expiry date, CVV), even though the sites have no connection to Walmart.
A network of more than 120 near-identical websites was built to impersonate Walmart. Each site reused the same WordPress/WooCommerce template, with only the fabricated US business addresses and phone numbers swapped between them. Visitors, most of them browsing on mobile devices, landed on a Walmart-branded homepage and category pages stacked with name-brand liquor discounted 40% to 70%. From there, shoppers were funneled directly to a checkout form requesting a full credit card number, expiry date, and CVV, despite the sites having no connection to Walmart.
The scam relied on a mix of visual credibility and urgency. Reusing a polished ecommerce template gave each site a legitimate look and feel, while the steep discounts on recognizable liquor brands created pressure to buy quickly rather than scrutinize the site. Steep discounts on high-demand goods are effective precisely because they encourage people to act on impulse instead of checking the source.
Organizations and individuals can reduce exposure to this type of scam by building habits around verification rather than visual trust. Employees, procurement staff, and cardholders should be reminded to check the address bar before entering any payment information, since brand look-and-feel alone is not proof of legitimacy. Anyone who has already entered card details on a suspicious site should treat the card as compromised, contact the issuer immediately, explain what happened, and ask whether the card should be cancelled and reissued. Because these scams target consumer purchasing behavior rather than corporate systems, awareness training that includes personal shopping scenarios, not just work-related phishing, helps close this gap. Retail and ecommerce teams should also be aware that lookalike domains impersonating their brand can appear at scale using low-cost templated infrastructure, which is relevant context for fraud and customer support teams fielding related complaints.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Researchers identified more than 120 near-identical domains built to look like a legitimate retailer, all designed to steal card details.
The sites advertised name-brand liquor at 40% to 70% off, a discount level optimized to attract mobile shoppers and push impulse buying.
The checkout forms asked for a full credit card number, expiry date, and CVV.
They should assume the card has been compromised and contact the card issuer immediately to explain what happened and ask about cancellation or replacement.
You’re on your phone, see a “Walmart” site pushing name‑brand liquor at 40% to 70% off, and it looks totally legit. Behind that one page is a network of more than 120 near‑identical Walmart lookalike sites. Same WordPress and WooCommerce template, fake US addresses, all driving you to one thing: the checkout form. Here’s the trap: the fake Walmart checkout asks for your full card number, expiry date, and CVV. The branding looks right, but the address bar shows an odd .shop domain that is not walmart.com. If you’ve already typed card details into a site like this, treat your card as compromised and call your card issuer immediately to lock it down.

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google…

Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked…

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password,…

Apple warns that scammers are placing unsolicited FaceTime calls and sending urgent-looking messages that appear to come from “Apple Support” or a bank. The…

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct…