120 Fake Walmart Sites Steal Card Details

Malwarebytes · Medium sophistication
Last updated July 30, 2026

A network of more than 120 convincing Walmart lookalike websites is luring mobile shoppers with “40% to 70% off” discounts on name-brand liquor. Victims are funneled to checkout pages that collect full credit card details (number, expiry date, CVV), even though the sites have no connection to Walmart.

How the Attack Worked

A network of more than 120 near-identical websites was built to impersonate Walmart. Each site reused the same WordPress/WooCommerce template, with only the fabricated US business addresses and phone numbers swapped between them. Visitors, most of them browsing on mobile devices, landed on a Walmart-branded homepage and category pages stacked with name-brand liquor discounted 40% to 70%. From there, shoppers were funneled directly to a checkout form requesting a full credit card number, expiry date, and CVV, despite the sites having no connection to Walmart.

Why It Succeeded

The scam relied on a mix of visual credibility and urgency. Reusing a polished ecommerce template gave each site a legitimate look and feel, while the steep discounts on recognizable liquor brands created pressure to buy quickly rather than scrutinize the site. Steep discounts on high-demand goods are effective precisely because they encourage people to act on impulse instead of checking the source.

What to Watch For

  • Discounts of 60% to 70% on premium or name-brand products, which are far outside normal retail promotions
  • Unfamiliar domains, including uncommon top-level domains like ".shop", instead of a retailer's known web address
  • A checkout process that asks for full card details (number, expiry, CVV) on a site that has not been independently verified
  • Repetitive site structure across multiple "different" stores, a sign of a templated scam network rather than distinct retailers

How to Build Resistance

Organizations and individuals can reduce exposure to this type of scam by building habits around verification rather than visual trust. Employees, procurement staff, and cardholders should be reminded to check the address bar before entering any payment information, since brand look-and-feel alone is not proof of legitimacy. Anyone who has already entered card details on a suspicious site should treat the card as compromised, contact the issuer immediately, explain what happened, and ask whether the card should be cancelled and reissued. Because these scams target consumer purchasing behavior rather than corporate systems, awareness training that includes personal shopping scenarios, not just work-related phishing, helps close this gap. Retail and ecommerce teams should also be aware that lookalike domains impersonating their brand can appear at scale using low-cost templated infrastructure, which is relevant context for fraud and customer support teams fielding related complaints.

Key findings

  • Attackers set up “more than 120 near-identical domains” designed to impersonate Walmart long enough to capture payment card data.
  • The lure is steep discounts on “name-brand liquor at 40% to 70% off,” optimized for mobile shoppers.
  • Victims are sent to a checkout form that requests “a full credit card number, expiry date, and CVV.”
  • The sites reuse “the same WordPress/WooCommerce template” with swapped “fabricated US business addresses and phone numbers.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance (corporate cardholders), Procurement/Purchasing, Customer support / fraud teams.
  • Affected industries: Retail (e-commerce), Consumer/household shoppers.
  • Attack channels: website.
  • Impersonated: Walmart.

Red flags to watch for

  • Unusually large discounts (60%–70%) pushing impulse buying
  • Lookalike/non-Walmart domain (example given: unfamiliar “.shop” domain)
  • Checkout page requests full card details on an untrusted site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How many fake Walmart sites were found?

Researchers identified more than 120 near-identical domains built to look like a legitimate retailer, all designed to steal card details.

What lure did the fake Walmart sites use?

The sites advertised name-brand liquor at 40% to 70% off, a discount level optimized to attract mobile shoppers and push impulse buying.

What information did the fake checkout pages request?

The checkout forms asked for a full credit card number, expiry date, and CVV.

What should someone do if they entered card details on one of these sites?

They should assume the card has been compromised and contact the card issuer immediately to explain what happened and ask about cancellation or replacement.

Read the video transcript

You’re on your phone, see a “Walmart” site pushing name‑brand liquor at 40% to 70% off, and it looks totally legit. Behind that one page is a network of more than 120 near‑identical Walmart lookalike sites. Same WordPress and WooCommerce template, fake US addresses, all driving you to one thing: the checkout form. Here’s the trap: the fake Walmart checkout asks for your full card number, expiry date, and CVV. The branding looks right, but the address bar shows an odd .shop domain that is not walmart.com. If you’ve already typed card details into a site like this, treat your card as compromised and call your card issuer immediately to lock it down.

Similar attacks

Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

July 29, 2026
Fake CoD Points Giveaway Steals Accounts

Fake CoD Points Giveaway Steals Accounts

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password,…

July 24, 2026
TikTok Resin Art “DM to Order” Scam

TikTok Resin Art “DM to Order” Scam

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct…

July 24, 2026