News: 1715210528

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

What do Europeans, Americans and Australians have in common? Scammed $50M by fake e-stores

(2024/05/09)


A crime ring dubbed BogusBazaar has scammed 850,000 people out of tens of millions of dollars via a network of dodgy shopping websites.

Victims in Western Europe, Australia, and America were tricked by these sham sites into placing orders for goods that either didn't exist or were cheap knock-offs, and had their credit card details harvested for fraud to boot.

The crooks behind the caper bagged roughly $50 million in the past three years from fake online stores spanning 22,500 domains, according to a [1]report by analysts at SRLabs this week.

The fraudsters managed to evade the attention of the law enforcement despite earning millions

"The operation of fraudulent webshops is a seemingly small but well-organized crime," Matthias Marx, a security consultant at SRLabs, told The Register .

"As each fraud case has a relatively low volume, the fraudsters seem to have managed to evade the attention of the law enforcement authorities despite earning millions."

[2]

The primary purpose of the fake e-commerce network is to steal credit card data, and BogusBazaar also spoofed payment services like PayPal and Stripe to collect that information. When the crew isn't harvesting credit cards, it sells fake goods that cost real money.

[3]

[4]

According to the report, most folks who make a purchase on one of the fake stores – usually for discounted luxury items – don't receive anything at all, and the lucky few who do get a delivery are greeted with counterfeit merchandise.

The crooks have also been running both scams against the same person. First, a customer will attempt to complete their purchase via a spoofed payment service, which will collect their credit card details and then throw an error. After that, the victim is brought to the actual payment processor, which makes a real transaction that at best results in fake goods.

E-commerce fraud, powered by US servers and WordPress

The operation is decentralized and optimized to deploy fresh fake sites fairly quickly. The core BogusBazaar crew handles all of the software development and server management.

A single BogusBazaar server, most of which are hosted in the US and use Cloudflare, can usually present 200 shops, with some hosting up to 500 storefronts. These sites use WordPress with the WooCommerce plugin, though in the past Zen Cart and OpenCart were also used.

[5]FTC: Please stop falling for social media scams, you've given crooks at least $650M so far this year

[6]Serial extortionist of medical facilities pleads guilty to cybercrime charges

[7]Ten nations tell social media, banks, and telcos to get better at stopping scams

[8]US charges 16 over 'depraved' grandparent scams

The spoofed payment pages are decoupled from the actual store fronts, meaning if one bogus payment site is taken down for fraud, another can be rotated in easily to keep on scamming. BogusBazaar has apparently got very good at automating the process for creating new websites, which tend to reuse expired domains, especially those with a good reputation on Google.

The fake shop sites themselves are run by BogusBazaar affiliates, who pay the core team for the software and server access in what the report terms a fraud-as-a-service franchising model. Most franchisees are operating out of China, and their victims are largely in the US, the UK, France, Australia, and other Western nations.

[9]

Unfortunately, SRLabs' report isn't an autopsy, and the firm estimates BogusBazaar is still operating tens of thousands of websites. The firm says it has shared its findings with the authorities and relevant internet providers, though didn't mention what actions had been taken so far against the fraud ring. ®

Get our [10]Tech Resources



[1] https://www.srlabs.de/blog-post/bogusbazaar

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjxKXqCnUe@-XY@VV8jy9QAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjxKXqCnUe@-XY@VV8jy9QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjxKXqCnUe@-XY@VV8jy9QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/10/07/ftc_social_media_scams/

[6] https://www.theregister.com/2024/03/20/serial_extortionist_of_medical_facilities/

[7] https://www.theregister.com/2024/03/14/global_fraud_summit_communique_meta/

[8] https://www.theregister.com/2024/05/01/us_charges_16_grandparent_scammers/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjxKXqCnUe@-XY@VV8jy9QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://whitepapers.theregister.com/



Ok, Reg

Kevin McMurtrie

No more deleting posts saying that Cloudflare is serving organized crime. You've just reported it yourself.

Given how many times the organized crime connection has been reported, and given how long these fake store toolkits have been on Cloudflare, it would be difficult to argue that it's not intentional by Cloudflare.

Are the deleted posts in the room with us now?

diodesign

There's a line between saying an internet provider is being used by criminals and an internet provider is actively involved in a crime. If any comments have been moderated in the past, it's possibly because a line was crossed and flagged in a way we couldn't ignore legally.

Pretty much every internet platform gets used for wrong at some point.

C.

Re: Are the deleted posts in the room with us now?

Kevin McMurtrie

I know anything can be abused - I'm a software developer of Internet applications and services. I've had battles with legitimate services being abused in constantly adapting ways. Sometimes features had to be cut.

What I'm talking about is the action. Is there an investigation of abuse complaints? Are any steps taken to reduce future abuse? I haven't seen any of that from Cloudflare. They are not be the worst but, unlike other networks, they are in a position of power where people can't firewall and forget their entire address space. Their public DNS is even a clever means of evading hostname blocks.

A scourge

Sorry that handle is already taken.

fake online stores spanning 22,500 domains

I believe it. I've been looking for some spare parts to suit a bicycle brand that recently ceased to exist. So far the only online stores I've been able to find listing the parts are scams. Some of them even post-date the bankruptcy.

Fortunately it's easy to pick the scam sites because always seem to be selling $1,000+ wheelsets for $9x.xx and $5,000+ bikes for $29x.xx. So they're designed to rope in idiots rather than deceive normal consumers.

Do more than anyone expects, and pretty soon everyone will expect more.