Nearly a million victims hit by massive BogusBazaar campaign — credit card details stolen, but here’s how to stay safe
Almost a million people around the world have fallen victim to a highly organized fraud campaign, which scammed them out of some $50 million in the past couple of years.
According to a report from SRLabs, a group of cyber-criminals, supported by a wider network of affiliates, were organized into a crime ring dubbed BogusBazaar. This ring automated the creation and rotation of thousands of fake shopping websites – 22,500 domains, to be exact.
Through these shopping sites, the criminals did two things – steal credit card and other payment data, and steal money.
Well-organized group
Stealing credit card information is as straightforward as one can imagine with fake shopping sites – a person would try to purchase something off the site, they would submit their payment information, and never get the item they ordered. PayPal and Stripe data was stolen from the victims in the same manner.
Stealing money worked in a somewhat different way. Some of the victims actually received an item, albeit not the one they ordered, but rather a cheap copy, or a knock-off.
“The operation of fraudulent webshops is a seemingly small but well-organized crime,” Matthias Marx, a security consultant at SRLabs, told The Register. “As each fraud case has a relatively low volume, the fraudsters seem to have managed to evade the attention of the law enforcement authorities despite earning millions.”
The majority of the victims were located in Western Europe, Australia, and America.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The worst part is that the campaign is still ongoing, and is decentralized and automated in a way that makes it difficult for law enforcement to fully eliminate. As soon as one website gets taken down, another one takes its place. The attackers often use expired domains with good standing, making spotting fraud even harder at start.
The majority of the fraudsters seem to be operating out of China.
The internet is filled with scammers and fraudsters, looking to steal people’s money and sensitive information. The best way to stay safe is to always make sure you’re buying from trusted sources and official websites. If you know the shop’s website, type the address in the bar instead of searching for it on Google or other search engines.
If you are being redirected to a website, double check the address and make sure it doesn’t have any weird typos or strange-looking characters.
And finally, always use common sense. If something is too good to be true, it most likely is.
More from TechRadar Pro
Almost a million people around the world have fallen victim to a highly organized fraud campaign, which scammed them out of some $50 million in the past couple of years. According to a report from SRLabs, a group of cyber-criminals, supported by a wider network of affiliates, were organized into…
Recent Posts
- Summer Game Fest Live 2026: The biggest news, trailers, and announcements
- OpenAI rolls out a Lockdown Mode for extra protection against prompt injection attacks
- The Dyson HushJet Mini Cool is the powerful personal fan you won’t want to live without this summer — and it’s surprisingly reasonably priced, too
- Gone in 60 minutes
- GroWell Cap Review: I Have Hair for the First Time in 15 Years
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023