© 2025 THE COOL DOWN COMPANY. All Rights Reserved. Do not sell or share my personal information. Reach us at hello@thecooldown.com.
Some of the fake storefronts are using AI-generated product listings to appear more credible.
Photo Credit: iStock
Elaborate phishing scams on social media are driving shoppers to fake online stores for discounted Legos, Calvin Kleins, and more, only to steal credit card details in real time.
According to Group-IB, the group it calls Milk Dragon has run its scam campaign for at least a year, creating lookalike e-commerce sites for familiar brands and retailers. Their bait is deep discounts on major brands, placed where deal hunters are likely to click, as TechRadar reports.
As email providers get better at detecting spam and phishing emails, scammers are now using social platforms to lure victims in, especially Facebook and TikTok groups and pages focused on bargains.
Shoppers who click through can land on spoofed stores that carry malware called BytePress, which sends checkout-form entries back to attackers. Group-IB said some fake storefronts use AI-generated product listings to look more credible.
What makes this scam unique is that submitting the purchase isn’t necessary for the theft to happen. BytePress can stream keystrokes in real time, so card details and other personal information may be exposed before the form is ever sent, if at all.
The tactic itself is familiar, but the losses remain enormous. TechRadar cited FTC Consumer Sentinel data showing 376,830 complaints in the “online shopping and negative reviews” category in 2023, totaling nearly $400 million in reported losses.
💡These best-sellers from Quince deliver affordable, sustainable luxury for all
Starting at $50
Starting at $99
Starting at $60
Starting at $80
The typical reported loss was $126, and most reports involved financial losses.
Scammers appear to exploit familiar shopping habits, targeting people who join Facebook deal groups or scroll TikTok for steep discounts.
They can also bypass protections shoppers often assume will keep them safe. Once submitted details pass through attacker-controlled systems to a legitimate website, attackers can also intercept prompts for one-time passwords or other multi-factor authentication checks sent back to the victim.
A one-time password prompt after clicking a social media deal does not mean the purchase is safe. In the Milk Dragon setup, attackers may route the transaction through real retailer infrastructure, so that extra code may not protect the purchase as shoppers expect.
Because BytePress can collect information as you type, recognizing a suspicious page before you enter anything is crucial.
Online shopping scams are showing up everywhere in many forms. These stories cover counterfeit marketplace goods, fake checkout experiences, relentless discount ads, and shady AI-using sellers.
• Amazon shoppers say counterfeit or mislabeled products can slip through routine purchases unnoticed.
• In South Korea, fake stores are hooking Gen Z shoppers with checkouts that never deliver.
• Parents say discount-saturated Temu ads can follow casual browsing long after interest fades.
• Shady online sellers sent shoppers AI-generated sweater listings that looked better than reality.
Get TCD’s free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.
© 2025 THE COOL DOWN COMPANY. All Rights Reserved. Do not sell or share my personal information. Reach us at hello@thecooldown.com.