2 Sources
2 Sources
[1]
Cybercriminals are preparing for Black Friday with new AI-powered scams and attacks -- how to shop safely this year
At this point, AI is unavoidable in day-to-day life and according to new data from the cybersecurity firm Kaspersky, 72% of consumers have used AI and a third of them rely on it for everyday tasks like creating shopping lists and budgeting. You may not even think that you've relied on an AI for shopping but if you've used a virtual "try-on" feature, or a shopping agent on a website, you've used AI. As we approach Black Friday, plenty of shoppers are using AI as a deal hunter or for price comparisons. While AI is more than capable of handling those tasks, plenty of people use it for more complex ones too. If delegated a command, agentic AI can perform a shopping chore for you from start to finish. For instance, you could tell it to watch the prices for a new iPad and tell it to purchase one for you automatically when the price falls into a particularly good range. Companies aren't missing out on what AI tools have to offer, either. Brands and storefronts use AI tools in order to shape and tailor the shopping experience that they provide to their customers. From personalized product recommendations to AI-powered chat assistants, there are plenty of opportunities for brands to use this tech to give shoppers options - even going so far as allowing them to buy and browse products through chatbots like with ChatGPT Agent. Shoppers aren't the only ones who are taking advantage of AI this year as we approach the holiday shopping season. Cybercriminals also employ AI tools to create online scams and phishing attacks so they can trick shoppers into giving out their personal information like credit card details, usernames and passwords and more. Threat actors can also use prompt injection techniques to confuse AI models into redirecting users to malicious websites. From there, users may unknowingly enter their details which can lead to financial fraud or even identity theft. Even without prompt injection and LLMs being involved, scammers have long been able to impersonate retailers and send phishing emails to your inbox. These messages will often offer "exclusive discounts" or "limited prizes," to entice recipients into clicking through. Last year, Kaspersky reported a 25% surge in retail focused cyberthreats in the days leading up to Black Friday. Kaspersky's security researchers have highlighted several examples on how to stay safe while using AI tools to shop, browse and complete purchases ahead of - and during - Black Friday. One of the top tips is to make prompts to your AI assistant as detailed and well thought out as possible. Avoid general "find me good deals on computers" style prompts, and instead clearly and specifically state what you need. Here's an example prompt provided by the firm's security experts: "Act as my trusted personal shopping assistant. Find three laptops from major, reputable retailers like Apple, Amazon or Dell with an average customer review of four stars or higher. Exclude any sellers with less than 1,000 reviews. For each, list the product name, key specs, current price and a direct link to the product page on the official retailers site. Ensure that all deals are valid for Black Friday 2025." At the same time, you also want to be cautious sharing with an AI: don't grant your AI access to payment details or browser extensions unless it's from a highly reputable and established company. Make sure that your accounts are protected with two-factor, or multi-factor, authentication, and always use a credit card (or trusted payment platform) for the increased security features and fraud protection. From there, you want to check URLs to make sure they'll lead you to the correct company and to be extra safe, enter them in manually instead of clicking on sponsored results from a search engine. Obviously, you should never, ever enter any information onto a site that you were taken to from a unsolicited link that was sent to you via email, text or social media ads, no matter how compelling the offer seems. Instead, head directly to the retailers official website and try to find the deal there. If you can't, you just avoided what was likely a scam. In order to stay protected, you should be using the best antivirus software and make sure that it has anti-phishing protection and that you've enabled it. Many antivirus suites also have payment protection or online shopping features that can be turned on, too. Keep in mind that many antivirus programs will also use AI-powered tools, so you can use the same technology hackers are using to fend them off and avoid their attacks.
[2]
Beware These Black Friday Shopping Scams
Watch out for sales that sound urgent or seem too good to be true. Holiday shopping season is ripe for scammers, as consumers rush to find and take advantage of some of the best discounts of the year, and potentially overlook red flags that signal fraud. Security researchers are warning of an uptick in scams capitalizing on the Black Friday and Cyber Monday hype. Fraudsters know that they can prey on shoppers' sense of urgency and excitement for limited-time, exclusive deals -- and AI is making these campaigns even more difficult to spot than usual. New data from McAfee suggest that nearly half of Americans have come across an AI-powered scam while shopping, from deepfakes impersonating celebrities pushing promotions to near-flawless spoofed websites that steal your credit card information. Here are the scams to watch for this Black Friday. Spoofed websites are a common type of a scam, and fraudsters use holiday shopping season to trap users with fake retail sites and sales pages that look legitimate but are actually just collecting data like your login credentials and payment information. Scammers will use stolen assets like logos and product photos from known and trusted brands, and AI makes it easy to set up a convincing (but fake) small business website with elements like a customer service page and consumer reviews in no time. Another shopping scam facilitated by AI is the impersonation scam. You think you're watching a popular influencer or celebrity promoting an exclusive deal or product giveaway on TikTok or another social media platform, but it's actually a deepfake. If you click through to enter or buy, you'll land on a counterfeit page (as outlined above) designed to steal from you. According to Google's November fraud and scam advisory, scammers can get eyes on their content by hijacking search terms for Black Friday sales, running deceptive ads, or pushing deals on social media. Fake storefronts may appear as sponsored links, which are easy to overlook if you're in a rush to make a purchase. Of course, you may encounter other common holiday scams, such as fake shipping notifications that request payment in order to resolve a delivery issue as well as account verification scams that prompt you to confirm personal details. These phishing and smishing campaigns use standard scam tactics like impersonating a legitimate company or service and sending a fraudulent link that collects your bank information or username and password combination. When shopping holiday deals, slow down enough to look for common signs of scams. Fraudsters will use urgency -- such as a limited time to secure a deal or a limited number of items left in stock -- in hopes you won't think before you buy. You should also be wary of any deal that is too good to be true, or a promotion with especially low prices that are out of line with other sales on similar items. This includes influencers pushing "exclusive" opportunities. If you are purchasing from a small business you don't know, google the brand and read third-party reviews to see whether it is legitimate. Instead of clicking links from emails, texts, and social media posts promoting sales, go directly to the retailer's website and search for the deal. If you do click through, check the URL carefully to ensure it is legitimate (scammers may use homoglyphs that avoid detection at first glance) and look for website elements that real companies have, such as a privacy policy and address. If you see a promotion on social media, check the creator's account to see when they joined the platform, what they've posted in the past, and whether they are verified. Beware of any site that requires you to pay with a gift card, cryptocurrency, or bank transfer versus a credit card, which has some protection in the case of fraud. Legitimate retailers will use legitimate payment methods. Finally, never enter your login credentials unless you've confirmed that the site you're using is trustworthy. This includes delivery services and your Amazon and PayPal accounts, all of which scammers may pressure you to "verify" in order to resolve a billing or delivery issue.
Share
Share
Copy Link
Cybercriminals are leveraging AI technology to create sophisticated Black Friday scams, including deepfake celebrity endorsements and spoofed retail websites. Security experts warn of a 25% surge in retail-focused cyber threats during the holiday shopping season.
As Black Friday approaches, cybercriminals are increasingly leveraging artificial intelligence to create more sophisticated and convincing scams targeting holiday shoppers. According to new data from cybersecurity firm Kaspersky, 72% of consumers have used AI technology, with a third relying on it for everyday tasks including shopping activities like creating lists and budgeting
1
.
Source: Lifehacker
While consumers embrace AI for deal hunting and price comparisons, threat actors are simultaneously exploiting these same technologies to create more convincing phishing attacks and online scams. McAfee research indicates that nearly half of Americans have encountered AI-powered scams while shopping, ranging from deepfake celebrity endorsements to nearly flawless spoofed websites designed to steal credit card information .
Security researchers have documented a significant increase in retail-focused cyberthreats during the holiday shopping period. Kaspersky reported a 25% surge in such threats in the days leading up to Black Friday last year, highlighting the seasonal nature of these criminal activities
1
.Cybercriminals employ various AI-enhanced techniques to deceive shoppers. Prompt injection techniques can confuse AI models into redirecting users to malicious websites, where unsuspecting victims may enter personal details that lead to financial fraud or identity theft. Traditional phishing emails offering "exclusive discounts" or "limited prizes" remain prevalent, but AI enhancement makes these campaigns more convincing and harder to detect
1
.
Source: Tom's Guide
Spoofed websites represent one of the most common AI-facilitated scams during the holiday season. Fraudsters create fake retail sites and sales pages that appear legitimate but actually collect login credentials and payment information. AI technology enables scammers to quickly establish convincing fake business websites complete with customer service pages and fabricated consumer reviews using stolen assets like logos and product photos from trusted brands .
Impersonation scams have become particularly sophisticated with AI deepfake technology. Consumers may encounter what appears to be popular influencers or celebrities promoting exclusive deals or product giveaways on social media platforms, but these are actually AI-generated deepfakes designed to lure victims to counterfeit shopping pages .
Related Stories
Security experts emphasize the importance of crafting detailed and specific prompts when using AI shopping assistants. Rather than general requests like "find me good deals on computers," users should provide comprehensive instructions. Kaspersky recommends prompts such as: "Act as my trusted personal shopping assistant. Find three laptops from major, reputable retailers like Apple, Amazon or Dell with an average customer review of four stars or higher. Exclude any sellers with less than 1,000 reviews"
1
.Experts strongly advise against granting AI assistants access to payment details or browser extensions unless from highly reputable companies. Essential security measures include enabling multi-factor authentication on all accounts and using credit cards or trusted payment platforms for their enhanced security features and fraud protection
1
.Consumers should manually enter website URLs rather than clicking sponsored search results and never provide information on sites accessed through unsolicited links from emails, texts, or social media advertisements. When encountering promotional offers, shoppers should navigate directly to official retailer websites to verify deals rather than clicking through potentially malicious links
1
.Summarized by
Navi
[1]
[2]
1
Technology

2
Technology

3
Business and Economy
