Scammers Abuse Virtual Shopping Lists to Trick Walmart Customers



Scammers Abuse Virtual Shopping ListsThreat actors are abusing virtual shopping lists to trick Walmart customers into transferring money or disclosing personal information, according to researchers at Malwarebytes. Links to the lists are distributed via Google Ads that impersonate Walmart support. 

As a result, someone who searches for Walmart’s customer service will see the ad at the top of the search results. If the user clicks the ad, they’ll be redirected to a Walmart List containing a scammer’s phone number.

Walmart Lists is a feature on Walmart’s website and app that allows users to write their own shopping lists, which can be shared with other people. However, instead of “eggs” or “milk,” the scammers have written “Walmart Customer Support” alongside a phone number.

If a user calls this number, they’ll be connected with a scammer who informs them that a warrant is out for their arrest due to a recent transaction from their bank account that was sent to a narco-trafficking group. The scammer, impersonating a bank employee or law enforcement investigator, attempts to trick the victim into transferring the rest of their money into a Bitcoin account in order to prevent additional transactions.

Malwarebytes offers the following recommendations to help users avoid falling for social engineering attacks:

  • Sponsored results, or ads, can be dangerous due to ongoing and relentless malvertising campaigns. Learn to spot a regular search result from an ad, and if possible avoid clicking on ads.
  • Even if you are on an official website, the content you see may not be legitimate. This is a particularly hard one because people will naturally trust that the brand’s own site will be safe. But scammers and spammers can inject content in comments, or custom pages.
  • Scare tactics and pressure to act quickly are almost always malicious. Unfortunately, most brands also have these promotions that expire soon and customers believe they need to buy the product now or lose out on a deal. Having said that, your local store will never threaten you on the phone with an arrest warrant.
  • Scammers will often tell their victims to keep everything confidential and not discuss it with other family members or bank clerks. This is only in the scammers’ interest to not be exposed; by all means you should ask for clarification and seek help from others.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Malwarebytes has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews