The Festive season is approaching, along with a busy online shopping period.
It will also come with a new round of evolved and dangerous online scams, specifically targeting Black Friday, Christmas, and New Year’s Sale shoppers.

Last year online shoppers lost an average of £1000 each over the festive shopping period, as cited in figures released by the National Cyber Security Centre (NCSC).

This average is calculated from cases reported to Action Fraud and does not take into account unreported scams, and so is likely to significantly under-represent the true average.

Even with under-represented figures, it has been reported that last year online shoppers lost a total of £15.3 million between November 2021 and January 2022.

 

Unlike most cyber-crime, younger shoppers are much more likely to fall victim to online shopping scams. Just under half (47%) of buyers scammed were 19 to 25-year-olds.

Of the 20,000 incidents reported to Action Fraud, around 50% involved the use of a social media site, with 20% involving the purchase of electronics.

8% of reports involved an attempt to purchase a vehicle, with one victim losing more than £7,000 trying to acquire a camper van.

But losing money is not the only risk faced by consumers this year. Cybercriminals take advantage of increased online shopping to target users with malicious websites that promise great offers on consumer items, but in reality, steal personal details and payment information to use in future fraud.

 

In order to help reduce the number of online scams experienced by consumers this year, we’ve released some helpful tips for shopping safely online, provided by the NCSC:
 
Choose carefully when shopping online

Before you make a purchase, it’s worth doing some research on online retailers to check they’re legitimate. Search for the company running the website on companies house, and try and find real reviews for them on consumer websites.

Reputable organisations will have information on their website about how they handle your personal data. This is usually a statement confirming that your information should only be used to fulfil your order, and not shared with third parties. If the website doesn’t have this statement, you should not purchase anything through it.

Often you’ll receive emails and text that contain amazing offers on desirable consumer goods. These invariably contain links to a malicious website, which once clicked may install malware onto your device, or trick you into providing personal information.

Even if the email or text claims to be from a famous and familiar retailer, such as John Lewis, never click on the link to get to their website. If you’re unsure, search for the company through a search engine and visit their website directly.

 

 
Only provide enough details to complete your purchase

When purchasing online, only fill in the mandatory details on a website when making a purchase.

These will usually be marked with an asterisk, and include your delivery address and payment details.

You should never have to provide security details, such as your mother’s maiden name, or the name of your first pet, to complete your purchase.

If possible, never create an account with the online store when making your payment. You can usually complete your purchase without having to create an account by:

  • Using an online payment platform (such as PayPal).
  • Signing in using an existing account with a service provider (such as Apple or Google).

The online store may ask you if they can save your payment details for a quicker check-out next time. Unless you’re going to use the site regularly don’t allow this, and don’t pay by direct bank transfer.

These rules are important as, even if an online store is legitimate, all companies are vulnerable to cyber-attacks and data breaches. This means that the fewer companies that hold your data, the less likely that your data will be lost to cyber criminals.

 

 
Keep your accounts secure

If you’re using the same password for all of your online accounts, you are putting yourself at increased risk in the event of a data breach.

If one of your accounts is affected by a data breach, and you maintain the same username and password as other online accounts, then cyber criminals can easily use your breached details to access these other accounts.

For this reason, you should ensure that your most important accounts, such as your email, social media, banking, and shopping accounts, are protected by strong, unique passwords.

You can further protect your most important accounts from being hacked by enabling Multi-Factor-Authentication. Enabling this prevents criminals from being able to access your accounts with just your username and password.

 

 
Be aware when receiving suspicious emails, text messages, and websites

Many online stores increase their marketing communications in the festive season and send them directly to consumers who have ‘opted in’ to receive them via email or SMS message.

Hidden amongst these genuine messages are fake ones, that effectively mimic them and contain links designed to take your money and personal details.

With emails, always check the sending address, and look for obvious spelling errors and other mistakes made by criminals. Check your emotions and ask yourself, do you feel alarmed or pressured into taking action? Does the email contain urgent language?

With SMS messages, always research the sender’s number before interacting with the message. It’s likely that if the number is malicious, it will have been reported and exists on a public awareness database online.

 

 

If you’ve suffered a Cyber Attack:

If you think your debit or credit card details have been stolen and/or used by someone else, let your bank or credit lender know so they can block anyone using it.

If you’ve lost a significant amount of money, report the incident to your bank and report it as a crime to Action Fraud. By doing this, you’ll be helping to prevent others from becoming victims of cybercrime.

If you’ve lost personal details to a scam, or have experienced a ransomware attack after visiting a malicious website, contact TecSec using the contact form below: