Scammers are targeting cloud systems to make off with hauls of gift cards
- Atlas Lion used phishing to infiltrate gift card systems and impersonate authorized employees
- Attackers mapped infrastructure, avoided malware, and exploited internal workflows to steal gift cards
- Gift cards are fast, untraceable, and easily resold; access lasted nearly a year
A Moroccan hacking collective has been targeting companies issuing gift cards for years, infiltrating their systems, stealing the cards, and likely reselling them on the black market for profit, new research has claimed.
Researchers at Unit 42 from Palo Alto Networks dubbed the campaign “Jingle Thief”, since it’s most active during the festive season.
As per the report, the group tracked as “Atlas Lion”, or “Storm-0539”, would first carefully pick its target, and try to learn as much about it as possible, before reaching out to its employees with convincing phishing lures. These lures would help them gain initial access, which they would then use to map out the IT infrastructure, with a specific focus on SharePoint and OneDrive.
Why gift cards?
They would then look for gift card issuance workflows, ticketing system exports or instructions, VPN configuration and access guides, spreadsheets or internal tools used to issue or track gift cards, organizational virtual machines, Citrix environments, and more.
Instead of dropping malware (which would probably raise a few alarms), to gain an even better foothold on the victim, the attackers would rely on internal phishing, targeting employees with fake IT service notifications, ticketing updates, and more.
After identifying gift card issuance processes, they would impersonate authorized users to request or approve gift card transactions, effectively stealing them.
Gift cards are popular with cybercriminals because they’re fast, fungible, and hard to trace. The value they provide is almost instant, and comes without the banking traces usually found in wire transfers.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Once redeemed, the funds from gift cards move into accounts, or are spent, which makes both recovery, and attribution, rather difficult. At the same time, cybercrooks can easily resell and convert them on dark web marketplaces.
Atlas Lion is playing for the long run, Unit 42 concluded, saying that in the campaign it observed, they maintained access for almost a year, and compromised more than 60 user accounts within a single global enterprise.
The researchers didn’t say how much money was stolen this way.
Via The Hacker News
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

The best antivirus for all budgets
Atlas Lion used phishing to infiltrate gift card systems and impersonate authorized employees Attackers mapped infrastructure, avoided malware, and exploited internal workflows to steal gift cards Gift cards are fast, untraceable, and easily resold; access lasted nearly a year A Moroccan hacking collective has been targeting companies issuing gift cards…
Recent Posts
- AI leaders call for tougher protections against AI-aided bioweapons
- 5 Best Smart Speakers (2026): Alexa, Google Assistant, Siri
- I’m an outdoors expert — here are 9 easy-pitch tents I’d recommend for a fuss-free camping trip
- Samsung’s updated Health app unsurprisingly comes with new AI-powered features
- Amazon develops a warehouse robot workers can speak to
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023