Fake Social Ads Push Shoppers to Card-Stealing Sites

Help Net Security · High sophistication
Last updated October 6, 2026

A phishing operation dubbed “Milk Dragon” uses fake discount posts on Facebook and TikTok to lure shoppers to lookalike online stores. Victims are tricked into entering payment card details and then a one-time password on a spoofed 3D Secure verification page, enabling fraudulent purchases or account takeover.

How the attack worked

The operation, tracked as Milk Dragon (also called NaiLong), relies on fake discount posts placed in social media marketplace listings on Facebook and TikTok. These posts advertise steep, exclusive discounts on popular brands and consumer goods to catch attention. Clicking the link redirects the shopper to a WordPress site disguised as a legitimate online retailer selling the discounted products. The checkout flow captures card details in real time, then shows a fake loading screen before presenting a spoofed 3D Secure verification page that mirrors a real bank's 2FA challenge. When the victim enters the one-time password, the operator relays it to approve a fraudulent transaction or take over the account. The kit has reportedly been linked to over 250 phishing pages affecting victims across dozens of countries, with an operator panel that stores victim profiles and supports templates tailored to multiple financial institutions.

Why it succeeded

The scheme leans on fear of missing out rather than fear or urgency tied to a security threat. Steep, time-limited discounts on recognizable brands push shoppers to act quickly without scrutinizing the source of the link. Because the traffic originates from ordinary-looking marketplace posts rather than obvious spam, it blends into normal social media browsing. The fake checkout and spoofed verification page are designed to mimic the real purchase and 3D Secure flow closely enough that most shoppers see nothing unusual until after the fraud occurs.

What to watch for

  • Marketplace listings or social posts advertising unusually steep or short-lived discounts on well-known brands
  • Links that lead away from a brand's official site to an unfamiliar storefront domain
  • A one-time password request appearing during or after checkout on a site reached through a social media link
  • Checkout behavior that feels unusual, such as odd loading screens or verification steps that don't match a bank's normal process

Building resistance

Shoppers should treat exclusive, time-pressured discounts found through third-party marketplace links as a warning sign rather than a bargain, and buy directly from a brand's verified site when possible. Before entering a one-time password at checkout, confirm the page genuinely belongs to the bank or card issuer rather than a lookalike verification screen. Anyone who has entered card details on a suspicious site should contact their bank or card issuer immediately to limit potential fraud. Organizations responsible for brand protection should monitor for lookalike domains, request takedowns early, and watch for unusual checkout patterns or suspicious card activity tied to their brand.

Key findings

  • Attackers used fake discounts on Facebook/TikTok to drive victims to phishing storefronts.
  • The phishing kit (“Milk Dragon”, also called “NaiLong”) has been active since October 2025 and linked to 258 phishing pages with victims in 66 countries.
  • Fake shops impersonated well-known brands and supermarkets to reduce suspicion and trigger fear of missing out (FOMO).
  • A fake checkout captured card details in real time and then presented a spoofed 3D Secure (3DS) OTP verification page to complete fraudulent transactions.
  • The operator panel stored victim profiles and enabled scaling via affiliates and templates for multiple financial institutions.

Who’s being targeted

  • Commonly targeted roles: All employees, Procurement, Finance (fraud awareness), Communications/Brand protection, E-commerce / Digital teams (if applicable).
  • Affected industries: Retail / E-commerce, Consumer goods (fashion, cosmetics, toys), Banking / Card issuers (fraud/charge activity).
  • Attack channels: website.
  • Impersonated: Popular retail brand / online shop (impersonating well-known brands), Payment verification step for the victim’s bank / 3D Secure (3DS).

Red flags to watch for

  • Steep or time-limited discount used to trigger urgency/FOMO
  • Link originates from a marketplace listing/third-party post rather than the brand’s official site
  • Checkout presents unusual payment options or an unfamiliar storefront domain
  • Unexpected OTP request after shopping from a social-media-linked discount site
  • Verification page appears after a suspicious loading screen and may not match the bank’s usual flow
  • Checkout behavior seems controlled (redirects/accept-reject messages) in unusual ways
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the Milk Dragon phishing scheme work?

Fake discount ads on Facebook and TikTok link to lookalike online stores. Once a victim enters payment card details, the site presents a spoofed 3D Secure verification page to steal their one-time password as well.

What should I do if I entered my card details on a suspicious site?

Contact your bank or card issuer right away to flag the activity and limit fraud, since the attackers can use stolen card details and OTPs to approve fraudulent transactions or take over accounts.

What red flags indicate a fake discount scam?

Steep or time-limited discounts posted on social media marketplace listings, links that bypass a brand's official site, and unexpected requests for a one-time password during checkout are all warning signs.

Can brands protect themselves from this kind of impersonation?

Yes, companies are advised to watch for lookalike domains, request takedowns early, and monitor for suspicious card activity and unusual checkout patterns.

Read the video transcript

You’re scrolling Facebook, see a crazy 70% off deal from your favorite brand, and it says: “Exclusive marketplace offer, ends today.” That’s the Milk Dragon scam. The ad link sends you to a WordPress site that looks like a real shop, then a fake checkout quietly grabs your card details in real time. Here’s the nasty twist: after you pay, a fake 3D Secure page pops up saying, “Your payment requires verification, enter the OTP.” You type the code, and Milk Dragon uses it to approve a fraudulent purchase or even take over your account. If you ever enter card details on a sketchy discount site and then see an OTP screen, stop and call your bank or card issuer immediately, that call is what kills Milk Dragon’s profit.

Similar attacks

AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Claude Linked to Real Phishing and Credential Theft

Claude Linked to Real Phishing and Credential Theft

Anthropic reports multiple real-world threat groups used Claude to support cyber operations, including credential harvesting and data theft across many victims. The report includes specific, simulation-ready lures such as a fake ESET NOD32 login portal that sends stolen passwords to Telegram and a…

September 11, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake FIFA Ticket Sites Steal Cards and OTPs

Fake FIFA Ticket Sites Steal Cards and OTPs

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are…

July 16, 2026
Fake TikTok Shop Sites Mimic Badges to Steal Pay

Fake TikTok Shop Sites Mimic Badges to Steal Pay

Scammers are setting up lookalike websites that copy TikTok Shop’s design, trust badges, and wording to trick people into thinking they’re shopping inside TikTok. The main risk is entering payment (and sometimes loan-application) details into a site that has no real connection to TikTok, leading to…

August 11, 2026
ClickLock Tricks Mac Users Into Pasting Malware

ClickLock Tricks Mac Users Into Pasting Malware

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their…

July 16, 2026