Saturday, June 20, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network Social Engineering 

Home » Security Bloggers Network » Safe Practices for Online Shopping: Guarding Against Bad Actors

SBN

Safe Practices for Online Shopping: Guarding Against Bad Actors

by Social-Engineer on August 22, 2024

Online shopping has revolutionized the way we purchase goods, offering convenience and accessibility like never before. However, with these benefits come risks, primarily in the form of cybercriminals who exploit unsuspecting shoppers. Practicing good cyber hygiene is essential to ensure a safe online shopping experience. Here, we’ll discuss the best practices for safe online shopping and highlight examples of bad actors to avoid.

safe practices for online shopping

Understanding the Threats

In the realm of online shopping, cybercriminals employ a variety of strategies to compromise sensitive information:

  • Phishing Emails: Deceptive emails designed to mislead a person into revealing sensitive information.
  • SMiShing Texts: Similar to phishing but conducted via SMS, these messages may direct a person to malicious websites or prompt them to download malware.
  • Fake Websites: Often used in conjunction with the 2 previously mentioned attacks, bad actors may create a website that mimics legitimate retailers to steal money and personal data.

These threats are not just limited to the direct interactions mentioned above. Cybercriminals are continuously developing new tactics to infiltrate one’s security, such as using compromised ads on legitimate sites or directing them to fraudulent payment gateways.

Why They Work

The success of online shopping scams is largely due to their exploitation of human psychology and trust. For example:

The Too-Good-To-Be-True Flash Sale: Scammers use this tactic to create a sense of urgency, pushing you to make impulsive decisions spurred by the fear of missing out (FOMO) on a great deal. They may claim to offer a high-end product at an extremely low price.

The Holiday Phishing Scam: These scams increase during festive periods when shoppers are more active online. Emails that appear to come from well-known delivery companies or online retailers ask for personal details or advance payments, playing on the trust shoppers have in these familiar entities.

The Gift Card Scam: An unsuspecting individual may receive a message claiming they have won a gift card. This may even happen while browsing on known retail sites, an advertisement may pop-up congratulating the individual on their “fortune”. Here, the promise of freebies is used to lure shoppers into providing personal information to “claim their gift” or making purchases on fraudulent sites.

These tactics are particularly effective because they mirror the look and feel of legitimate promotional activities, making them harder to distinguish from real offers.

Safe Practices

To defend yourself while engaging in online shopping, adopt the following practices:

  • Verify Website URLs: Always check the URL or address of websites. Secure websites start with “https://” and often include a padlock icon in the address bar. However, this should not be the only indicator…always be skeptical of URLs that contain slight spelling errors or unusual domains, as these are common indicators of fraudulent sites. If you are still unsure, you can use online link checkers like urlscan.io or urlvoid.com. These sites can scan and verify the link for you to protect you from malicious and illegitimate websites.
  • Scrutinize Deals: If an offer seems too good to be true, it likely is. Verify such deals by visiting the retailer’s official website directly rather than clicking on a potentially dangerous link.
  • Monitor Your Accounts: Regularly review your bank and credit card statements for any unauthorized charges. Quick detection can limit damage and facilitate the resolution process.
  • Be Wary of Public Wi-Fi: Avoid making purchases or accessing sensitive accounts over public Wi-Fi networks. If necessary, use a VPN to secure your connection.
  • Strengthen Your Security: Utilize strong, unique passwords for each online account and enable multi-factor authentication (MFA). MFA will make it much more difficult for cybercriminals to gain access even if they manage to obtain your password. If possible, the use of a Passkey may provide an even stronger layer of security.
  • Lock Your Accounts: In the USA you can lock down all 3 credit bureaus by freezing your accounts for free. This is a good practice to stop any thieves from using your identity for purchases or opening new lines of credit.

Conclusion

By understanding the strategies employed by cybercriminals and adhering to best practices in online security, you can significantly reduce the risks associated with online shopping. Stay informed about the latest scam tactics, remain vigilant about your online activities, and prioritize your cybersecurity. With these measures in place, you can enjoy the benefits of online shopping without falling prey to pitfalls.

Written by
Josten Peña
Human Risk Analyst
Social-Engineer, LLC

*** This is a Security Bloggers Network syndicated blog from Security Through Education authored by Social-Engineer. Read the original post at: https://www.social-engineer.org/general-blog/safe-practices-for-online-shopping-guarding-against-bad-actors/

August 22, 2024August 22, 2024 Social-Engineer General Social Engineer Blog
  • ← DEF CON 32: What We Learned About Secrets Security at AppSec Village
  • With Quantum coming, NIST readies new software supply chain protection →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

4 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

4 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
SailPoint Acquires Entro to Continuously Detect and Monitor Non-Human Identities
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
CVE-2026-35273: Active Exploitation of Oracle PeopleSoft Zero-Day Vulnerability
Kodak Confirms Data Breach Claimed by ShinyHunters Extortion Gang
Microsoft Defender Zero-Day Privilege Escalation Vulnerability (RoguePlanet)
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | 2 days ago 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 1 day ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | 2 days ago 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 3 days ago 0

Security Humor

Fortinet® Follies

Fortinet® Follies

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
Managing the AppSec Toolstack
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.