A phishing operation dubbed “Milk Dragon” uses fake discount posts on Facebook and TikTok to lure shoppers to lookalike online stores. Victims are tricked into entering payment card details and then a one-time password on a spoofed 3D Secure verification page, enabling fraudulent purchases or account takeover.
How the attack worked
The operation, tracked as Milk Dragon (also called NaiLong), relies on fake discount posts placed in social media marketplace listings on Facebook and TikTok. These posts advertise steep, exclusive discounts on popular brands and consumer goods to catch attention. Clicking the link redirects the shopper to a WordPress site disguised as a legitimate online retailer selling the discounted products. The checkout flow captures card details in real time, then shows a fake loading screen before presenting a spoofed 3D Secure verification page that mirrors a real bank's 2FA challenge. When the victim enters the one-time password, the operator relays it to approve a fraudulent transaction or take over the account. The kit has reportedly been linked to over 250 phishing pages affecting victims across dozens of countries, with an operator panel that stores victim profiles and supports templates tailored to multiple financial institutions.
Why it succeeded
The scheme leans on fear of missing out rather than fear or urgency tied to a security threat. Steep, time-limited discounts on recognizable brands push shoppers to act quickly without scrutinizing the source of the link. Because the traffic originates from ordinary-looking marketplace posts rather than obvious spam, it blends into normal social media browsing. The fake checkout and spoofed verification page are designed to mimic the real purchase and 3D Secure flow closely enough that most shoppers see nothing unusual until after the fraud occurs.
What to watch for
- Marketplace listings or social posts advertising unusually steep or short-lived discounts on well-known brands
- Links that lead away from a brand's official site to an unfamiliar storefront domain
- A one-time password request appearing during or after checkout on a site reached through a social media link
- Checkout behavior that feels unusual, such as odd loading screens or verification steps that don't match a bank's normal process
Building resistance
Shoppers should treat exclusive, time-pressured discounts found through third-party marketplace links as a warning sign rather than a bargain, and buy directly from a brand's verified site when possible. Before entering a one-time password at checkout, confirm the page genuinely belongs to the bank or card issuer rather than a lookalike verification screen. Anyone who has entered card details on a suspicious site should contact their bank or card issuer immediately to limit potential fraud. Organizations responsible for brand protection should monitor for lookalike domains, request takedowns early, and watch for unusual checkout patterns or suspicious card activity tied to their brand.
Key findings
- Attackers used fake discounts on Facebook/TikTok to drive victims to phishing storefronts.
- The phishing kit (“Milk Dragon”, also called “NaiLong”) has been active since October 2025 and linked to 258 phishing pages with victims in 66 countries.
- Fake shops impersonated well-known brands and supermarkets to reduce suspicion and trigger fear of missing out (FOMO).
- A fake checkout captured card details in real time and then presented a spoofed 3D Secure (3DS) OTP verification page to complete fraudulent transactions.
- The operator panel stored victim profiles and enabled scaling via affiliates and templates for multiple financial institutions.
Who’s being targeted
- Commonly targeted roles: All employees, Procurement, Finance (fraud awareness), Communications/Brand protection, E-commerce / Digital teams (if applicable).
- Affected industries: Retail / E-commerce, Consumer goods (fashion, cosmetics, toys), Banking / Card issuers (fraud/charge activity).
- Attack channels: website.
- Impersonated: Popular retail brand / online shop (impersonating well-known brands), Payment verification step for the victim’s bank / 3D Secure (3DS).
Red flags to watch for
- Steep or time-limited discount used to trigger urgency/FOMO
- Link originates from a marketplace listing/third-party post rather than the brand’s official site
- Checkout presents unusual payment options or an unfamiliar storefront domain
- Unexpected OTP request after shopping from a social-media-linked discount site
- Verification page appears after a suspicious loading screen and may not match the bank’s usual flow
- Checkout behavior seems controlled (redirects/accept-reject messages) in unusual ways
Frequently asked questions
How does the Milk Dragon phishing scheme work?
Fake discount ads on Facebook and TikTok link to lookalike online stores. Once a victim enters payment card details, the site presents a spoofed 3D Secure verification page to steal their one-time password as well.
What should I do if I entered my card details on a suspicious site?
Contact your bank or card issuer right away to flag the activity and limit fraud, since the attackers can use stolen card details and OTPs to approve fraudulent transactions or take over accounts.
What red flags indicate a fake discount scam?
Steep or time-limited discounts posted on social media marketplace listings, links that bypass a brand's official site, and unexpected requests for a one-time password during checkout are all warning signs.
Can brands protect themselves from this kind of impersonation?
Yes, companies are advised to watch for lookalike domains, request takedowns early, and monitor for suspicious card activity and unusual checkout patterns.
Read the video transcript
You’re scrolling Facebook, see a crazy 70% off deal from your favorite brand, and it says: “Exclusive marketplace offer, ends today.” That’s the Milk Dragon scam. The ad link sends you to a WordPress site that looks like a real shop, then a fake checkout quietly grabs your card details in real time. Here’s the nasty twist: after you pay, a fake 3D Secure page pops up saying, “Your payment requires verification, enter the OTP.” You type the code, and Milk Dragon uses it to approve a fraudulent purchase or even take over your account. If you ever enter card details on a sketchy discount site and then see an OTP screen, stop and call your bank or card issuer immediately, that call is what kills Milk Dragon’s profit.