Recent Retail Cyber Attacks

Attacks on retailers and e-commerce platforms, from gift card scams to credential phishing against store and corporate staff. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Pig Butchering Scams Drive $12.7B Crypto Losses

Pig Butchering Scams Drive $12.7B Crypto Losses

FinCEN reports that overseas scam centers stole about $12.7B from U.S. victims since 2023, largely through “pig butchering” style cryptocurrency investment scams. Scammers build trust using fake personas (often romance or “financial adviser” roles), then pressure victims to buy crypto and send it…

September 10, 2026
DoppelCart Fake Shops Steal Payment Details

DoppelCart Fake Shops Steal Payment Details

Researchers uncovered a massive network of over 119,000 fake online stores that copy real brands to trick shoppers into entering payment details. The cloned sites look legitimate and use big discounts to create urgency, but the checkout pages capture card and personal data that criminals can reuse…

September 10, 2026
AI-Assisted CEO Invoice Scam Pushes $50K ACH

AI-Assisted CEO Invoice Scam Pushes $50K ACH

Microsoft reports a real, large-scale email campaign that impersonated company executives and ServiceNow to pressure accounts payable teams into sending nearly $50,000 via ACH/bank transfer. The emails bundled a CEO “approval,” a fake ServiceNow-branded invoice, and a fabricated forwarded thread to…

September 10, 2026
Fake M&A Wire Fraud and Trezor Phishing Alert

Fake M&A Wire Fraud and Trezor Phishing Alert

This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users…

September 10, 2026
119,000 Fake Shops Clone Brands to Steal Cards

119,000 Fake Shops Clone Brands to Steal Cards

Researchers found a massive network of nearly 119,000 look‑alike online stores that copy real retailers’ branding and product pages. These fake shops lure buyers with big discounts and then capture payment card details (and sometimes bank one‑time codes) during checkout, sending the data to…

September 9, 2026
Trezor Users Targeted by Phishing Calls & QR Letters

Trezor Users Targeted by Phishing Calls & QR Letters

After a breach at shipping partner ShipMonk, attackers obtained Trezor customers’ contact and shipping details, increasing the risk of scams. Reports on Reddit indicate customers have already received phishing phone calls and physical letters containing QR-code phishing lures. Trezor warned…

September 8, 2026
ClickFix Lures Users to Paste Code via Browser

ClickFix Lures Users to Paste Code via Browser

Cisco Talos described real ClickFix campaigns where attackers trick people into pasting code either into the Chrome address bar (or a browser extension) or into the Windows Run dialog. The first campaign targeted crypto swap sites and used a fake “leaked vulnerability report” to get victims to run…

September 8, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Fake Bank Calls Drain £180k From Revolut Users

Fake Bank Calls Drain £180k From Revolut Users

Jersey Police report a surge of scam phone calls where criminals impersonate bank fraud/security teams or Revolut support. Victims are pressured with warnings about “suspicious transactions” and then tricked into handing over security details or moving money, leading to about £180,000 in losses in…

September 2, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026
Fake GTA 6 “Leaked Copy” Site Drains Wallets

Fake GTA 6 “Leaked Copy” Site Drains Wallets

A scam website posing as a GTA 6 fan countdown page tricks visitors into buying a “leaked copy” and then prompts them to connect a crypto wallet. Once connected, it generates transactions/approvals designed to transfer the victim’s cryptocurrency (and potentially NFTs) to the attacker. The site…

September 1, 2026
Amazon GPU Scam Uses “Free Gift” + Fake Support

Amazon GPU Scam Uses “Free Gift” + Fake Support

A third-party Amazon seller reportedly sent a cheap “complimentary gift” instead of a high-end graphics card, along with printed instructions designed to keep the buyer waiting until refund/return deadlines pass. The pamphlet directs the victim to email a fake “Amazon” support address to get…

September 1, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Deepfake Stock Tips Pushed via WhatsApp

Deepfake Stock Tips Pushed via WhatsApp

Group-IB warns that organized investment fraud is using deepfake video “endorsements,” WhatsApp groups, and professional-looking fake crypto platforms to trick victims into sending money. The models described (“GoldBull” and “CoinLure”) include pump-and-dump stock manipulation and a large network…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fake Recruiters Steal Corporate Logins on Mobile

Fake Recruiters Steal Corporate Logins on Mobile

Scammers posing as HR staff at major brands are luring targets into an interview “scheduling” flow that ultimately steals corporate passwords on mobile devices. The campaign uses a browser-in-the-browser style approach (or a full-screen fake login on phones) and even blocks personal email logins to…

August 26, 2026
Interpol Sting Hits Black Axe Scam Networks

Interpol Sting Hits Black Axe Scam Networks

Interpol said Operation Jackal IV arrested dozens and disrupted West Africa–linked criminal networks tied to scams and money laundering, including Black Axe. The cases described include a call-center “investment” scam, romance/investment scams targeting retirees, and sextortion of teenagers on…

August 25, 2026
Fake Recruiters Steal Enterprise Logins on Mobile

Fake Recruiters Steal Enterprise Logins on Mobile

A real “fake recruiter” phishing campaign (tracked as RecruitTrap) is targeting employees’ corporate credentials, especially on mobile devices. The scam uses lookalike recruitment domains and full-screen fake login pages that hide browser cues, and it rejects personal email addresses to focus on…

August 25, 2026
Notion Alerts Used to Steal Microsoft Tokens

Notion Alerts Used to Steal Microsoft Tokens

A financially motivated actor (“Doubloon Dredger”) abused legitimate Notion sharing notifications to trick employees into opening a PDF and completing a Microsoft device-code login flow. This allowed the attacker to harvest authentication tokens and access victim accounts without needing the…

August 24, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo