Opens in a new tab
vmblog logo 2024 wht (updated)

Risks lurking around the holiday shopping season – do's and don'ts from a security architect

Share: 

David Marshall | Published: December 22, 2023

By Georgia Weidman, Security Architect at Zimperium 

The holiday season is in full swing and cybercriminals are making their lists, checking them twice, and going after consumers, hoping they’re too focused on the holiday rush to stay cyber safe. Zimperium’s 2023 Banking Heists Report uncovered the extent to which financially motivated threat actors are targeting banking applications, finding that 29 malware families targeted 1,800 banking applications across 61 countries last year. To show how much that’s grown, last year’s report uncovered 10 prolific malware families targeting 600 banking apps. It’s clear that applications holding sensitive financial data are the most lucrative for cybercriminals, so this holiday season, it’s best to heed advice from security professionals on how to avoid these attacks. Below are a handful to start out with!

Tread carefully while shopping on social media apps

Scrolling through Instagram these days may feel like stepping over landmines of ads highly targeted to user behavior and searches. We’re bombarded with ads as we try to scroll through photos of friends and family. But it’s important to recognize that quite a few of them are actually scams. The key here is to trust your instincts and proceed with caution. For example, a legit Amazon ad is harmless, but what about Amazon.CORN? These sneaky and barely perceptible changes can lead to a devastating cyber theft incident. Always be sure you’re going to authentic sites and that they’re protected by SSL/TLS.

If you find yourself creating an account with a new vendor, it’s extra important during the holiday shopping season to create different passwords for different sites. Scam sites are sometimes created with seemingly good deals to harvest credentials so they can try those same credentials elsewhere. And although that sale from a brand-new site may seem like a steal, many new sites lack fully baked security and are more susceptible to accidentally giving up your credentials or PII to bad actors later. When shopping via social media, don’t fall victim to malware through malicious links that require you to download a linked application. Rather, download the application from a trusted app store instead of following an opaque link to download an app from an unknown source.

QR code are the new hype – and the new attack delivery method

QR codes have risen in popularity because of how easy it is to share links and information simply with the scan of a camera. As a result, they are ubiquitous this holiday shopping season. At their root, however, a QR code is just a URL and, just like mentioned above, it’s important to make sure we know where we’re actually going. These days, mobile devices will display the URL that the QR code is leading users to before they scan it. I’ve been a penetration tester for many years performing security awareness training and I have seen how easy it is to distribute printed flyers with QR codes that were ostensibly BOGO coupons for the local deli that led users to give up a surprising amount of personal information.

Public Wi-Fi is not the safest space to browse the web

Between shopping, holiday parties, and seasonal travel, it’s important that you stay cyber safe when using public Wi-Fi when out and about. Do not make financial transactions such as online banking, trading, or shopping when you’re using a computer in an airport lounge, hotel, or library. If you must use a public Wi-Fi network, consider using a VPN for an added layer of protection and be sure you’re transacting with SSL/TLS protected web sites.

Your package is not lost, it’s just a phishing scam

Despite the effort that has been made to educate the public of phishing scams, cybercriminals continue to ramp up their efforts because, frankly, it’s still wildly successful. For example, users may receive a text message or email that their FedEx or UPS package could not be delivered because the address or name was wrong. By simply clicking on the link, they can remediate the issue. This classic example of a phishing scam is something cybercriminals will be using more than ever this holiday season.

Yes, progress has been made in security awareness, but users don’t yet understand that any mechanism that can deliver a URL can be used to phish. Be that QR codes, SMS, Facebook Messenger, X DMs, or even secure messaging products like Signal and WhatsApp. Security awareness practitioners and cybercriminals have been in an arms race for years. Users must be cognizant of all possible paths scammers can use to deliver phishes and to think before they click.

During the holiday shopping season, cybercriminals ramp up their persistence in phishing for financial and personal information. They know that we are often too busy to look deeply into a text, call, email, QR code, etc. This is the essence of social engineering – exploiting human vulnerability for financial gain. If you’re an organization looking to protect your employees and sensitive company data, share these best practices throughout the year in engaging security awareness programs to make sure your workforce is educated and secure when the holiday season comes around.

##

ABOUT THE AUTHOR 

Georgia Weidman, Security Architect at Zimperium

georgia weidman 

Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, mentor, angel investor, and the author of Penetration Testing: A Hands-On Introduction to Hacking. Her work in the field of smartphone exploitation received a DARPA Cyber Fast Track grant and she has been featured internationally in print and on national television including ABC, BBC, Fox, NBC, and in the PBS documentary Roadtrip Nation: Life Hackers. She has presented and trained around the world including venues such as Black Hat, DEF CON, NSA, Oxford, RSA, and West Point.