‘Save Money, Live Better?’ Not if Members Fall for This Growing Scam Targeting Walmart

BOCA RATON, Fla. — In yet another scam to potentially alert members to, cybersecurity researchers have identified more than 120 fraudulent websites masquerading as Walmart in an apparent phishing campaign designed to steal consumers’ credit card information, according to a report by SecurityBoulevard.com.

The report said the fake websites target shoppers, particularly those using mobile devices, by advertising well-known liquor brands at discounts ranging from 40% to 70%. Consumers who attempt to make purchases are directed to checkout pages requesting their credit card number, expiration date and CVV security code.

According to SecurityBoulevard.com, the websites are not affiliated with Walmart and instead are part of a coordinated network of more than 120 nearly identical domains created to mimic the retailer’s branding long enough to capture payment information.

Same Template Used

The report said the scam relies on Walmart’s well-known name and branding to lower consumers’ skepticism.

“The trust hasn’t been earned by the site,” SecurityBoulevard.com said in its analysis. “It’s borrowed from a brand that has nothing to do with it.”

Researchers said all of the fraudulent sites use the same WordPress and WooCommerce template, with identical product catalogs, pricing and images. The primary differences are fabricated U.S. business addresses and telephone numbers assigned to each domain.

According to the report, the sites use steep discounts to encourage impulse purchases before shoppers question the legitimacy of the offers.

Advice for Consumers

SecurityBoulevard.com advised consumers to:

  • Be skeptical of unusually deep discounts, particularly on products such as liquor and electronics.
  • Verify website addresses before entering payment information, noting that legitimate Walmart promotions would not direct customers to unfamiliar “.shop” domains.
  • Use browser security tools or mobile security applications that can identify known phishing and scam websites.

The publication also urged consumers who believe they entered payment information on one of the fraudulent sites to contact their card issuer immediately to determine whether their card should be canceled and replaced. Consumers also should monitor their accounts for unauthorized transactions, including small “test” charges often used by fraudsters, and report the fraudulent websites to the Federal Trade Commission through its fraud reporting portal.

SecurityBoulevard.com said consumers should regard unfamiliar domains impersonating established retailers as a warning sign of potential fraud.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.