{"id":132022,"date":"2021-11-29T14:04:38","date_gmt":"2021-11-29T22:04:38","guid":{"rendered":"https:\/\/www.mcafee.com\/blogs\/?p=132022"},"modified":"2024-06-26T01:09:21","modified_gmt":"2024-06-26T08:09:21","slug":"tis-the-season-for-scams","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/","title":{"rendered":"\u2018Tis the Season for Scams"},"content":{"rendered":"<p>Co-authored by: Sriram P and Deepak Setty<\/p>\n<p>\u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and Complaint Center (<a href=\"https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2020_IC3Report.pdf\" target=\"_blank\" rel=\"noopener\">IC3<\/a>) reported losses in excess of $4.1 billion dollars in scams which was a 69% increase over 2019. There is no better time for a scammer celebration than Black Friday, Cyber Monday, and the lead-up to Christmas and New Year. It\u2019s a predictable time of the year, which gives scammers ample time to plan and organize. The recipe isn\u2019t complicated, at the base we have some holiday excitement, sprinkle in fake shopping deals and add some discounts, and ho ho ho we have social engineering scams.<\/p>\n<p>In this blog, we want to increase awareness related to scams as we expect elevated activity during this holiday season. The techniques used to scam folks are very similar to those used to spread malware too, so always be alert and use caution when browsing and shopping online. We will provide some examples to help educate consumers on how to identify scams. The victims of such scams can be others around you like your kids or parents, so read up and spread the word with family and friends. Awareness, education, and being alert are key to keeping you at bay from fraudsters.<\/p>\n<h2>Relevant scams this season<\/h2>\n<p>Although there is a myriad of scams out there, we expect the most common scams and targets this season to be:<\/p>\n<ol>\n<li>Non-delivery scams \u2013 Fake online stores will attempt to get you to purchase items that you will never end up receiving<\/li>\n<li>Deals that get shoppers excited. Supply chain issues recently will give scammers more fodder. Scammers can place bait deals on popular items<\/li>\n<li>Elderly parents\/grandparents looking for cheap medical equipment, medical memberships, or looking to purchase and ship their grandchildren presents for the holidays.<\/li>\n<li>Emotionally vulnerable people might fall prey to romance scams<\/li>\n<li>Children looking for free, Fortnite Vbucks and other gaming credits may fall prey to scams and could even get infected with potentially unwanted programs<\/li>\n<li>Charity scams will be rampant.<\/li>\n<\/ol>\n<p>SMSishing, email-based Phishing, and push notifications will be the most common vectors initiating scams during this holiday season. Here are some common tactics in use today:<\/p>\n<h3><strong>1. Unbelievable deals or discounts<\/strong><\/h3>\n<p>This is a common theme around this time of the year. Deals, discounts, and gift cards can be costly to your bank account. Be wary of URLs being presented to you over email or SMS. Phishing emails, bulk mailing, texting, and typo-squatting are some of the ways that scammers target their prey.<\/p>\n<h3><strong>2. Creating a sense of urgency<\/strong><\/h3>\n<p>Scammers will create a sense of urgency by telling you that you have limited time to claim the deal or that there is low inventory for popular items in their store. It\u2019s not difficult for scammers to identify sought-after electronics items or holiday gifts for sale and offer them for sale on their fake stores. Such scams are believable given the supply chain challenges and delivery shortages over the last few months.<\/p>\n<h3><strong>3. Utilizing Scare tactics <\/strong><\/h3>\n<p>Getting people worried about a life-changing event or disrupting travel plans can be concerning. So, if you get an unexpected call from someone claiming to be from the FBI, police, IRS, or even a travel company, stop and think. They may be using scare tactics to dupe you. Never divulge personal information and if in doubt, ask them a lot of directed questions and fact check them. As an example, check to see if they know your home address, account number, itinerary number, or bank balance depending on who they claim to be. Scammers typically don\u2019t have specific details and when put on the spot, they\u2019ll hang up.<\/p>\n<h3><strong>4. Emotional tactics <\/strong><\/h3>\n<p>Like scare tactics, scammers may prey on vulnerable people. Although there can be many variations of such scams, the more common ones are <em>Romance Scams<\/em> where you end up connecting to someone with a fake profile, and <em>Fake Charity Scams<\/em> where you receive a phone call or an email requesting a donation. Do not entertain such requests over the phone especially if you receive a phone call soliciting a donation. During the conversation, they will attempt to make you feel guilty or selfish for not contributing enough. Remember, there is no rush to donate. Go to a reputable website or a known organization and donate if you must after due diligence.<\/p>\n<h2>Tips to identify a scam<\/h2>\n<p>Successful scams are situationally accurate. You may be the smartest guy in the room, but when you eagerly waiting for that delivery and you see an email update claiming a delivery delay from UPS, you might fall for a scam. This is particularly true in the holiday season and therefore such themes are more prevalent. Here are some tips on how to identify scams early on.<\/p>\n<ol>\n<li>Be suspicious of anything that is <em>pushed<\/em> to you from an unknown source &#8211; emails, SMS, advertisements, phone calls, surveys, social media. This is when you are being solicited to do something you might not have otherwise chosen to\n<ol>\n<li>Avoid going to unknown websites to begin with. You always have the option to r before you click on a link. You can always use some of the following trusted free resources to validate a domain or business\n<ol>\n<li><a href=\"https:\/\/trustedsource.org\/\" target=\"_blank\" rel=\"noopener\">https:\/\/trustedsource.org\/<\/a> &#8211; to look up a URL<\/li>\n<li><a href=\"https:\/\/www.virustotal.com\/gui\/home\/url\" target=\"_blank\" rel=\"noopener\">https:\/\/www.virustotal.com\/gui\/home\/url<\/a> &#8211; to look up a URL<\/li>\n<li><a href=\"https:\/\/www.bbb.org\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.bbb.org\/<\/a> &#8211; to validate a business, charity, etc<\/li>\n<li><a href=\"https:\/\/whois.domaintools.com\/\" target=\"_blank\" rel=\"noopener\">https:\/\/whois.domaintools.com\/<\/a> &#8211; to look up site history. A new or recent domain is less trustworthy. Scammers register new domains based on the theme of their scams.<\/li>\n<\/ol>\n<\/li>\n<li>If you do end up navigating, look for the following to build trust in a link:\n<ol>\n<li>Ensure it&#8217;s an &#8220;https&#8221; domain versus an \u201chttp\u201d. A valid \u201chttps\u201d certificate just means that your data is encrypted enroute to the website. Although this method isn\u2019t indicative of a scam, some scams are hosted on compromised \u201chttp\u201d sites. (example 1))<\/li>\n<li>Closely look at the domain name. They might be indicative of fakes. Scammers would typically register domains with very similar names to deceive you. For example, Amazon.com could be replaced by Arnazon.com or AMAZ0N.com. &#8216;vv&#8217; could be replaced for &#8216;w&#8217;, &#8216;I&#8217; for a 1, etc. Same goes for emails you receive \u2013 take a close look<\/li>\n<li>Another common way of reaching a fake website is due to &#8220;typosquatting&#8221; but this is typically human error, where a user may type an incorrect domain name and reach a fake site.<\/li>\n<li>Most legit sites will have a &#8220;Contact us&#8221;, &#8220;About Us&#8221;, &#8220;Conditions of Use&#8221;, &#8220;Privacy Notice&#8221;\/&#8221;Terms&#8221;, &#8220;Help&#8221;, Social Media presence on Twitter, FB, Instagram, etc. Read up on the pages to learn about the website and even look for website reviews before you make a purchase. Fake websites do not invest a lot of time to populate these \u2013 this could be a giveaway.<\/li>\n<\/ol>\n<\/li>\n<li>Always confirm the sender of and email or text by validating the email address or phone number. For example, if an email claims to be from BankOfAmerica, you would expect their email domain in most cases to be from \u201c@bankofamerica.com\u201d and not from \u201c@gmail.com\u201d. Avoid clicking on links from emails or messages when you don\u2019t know the sender.<\/li>\n<li>If you end up linking to a page because of an email or message, never provide personal details. Any site asking for such information should raise red flags. Even if the site looks legit, Phishing scammers make exact replicas of web pages and try to get you to login. This allows them to steal your login credentials. (Example 4)<\/li>\n<li>Don\u2019t feel pressured to click on a link or provide details to solicitors in such cases especially. Any attempt to gather personal data is a big NO.<\/li>\n<li>Never open attachments from unknown people. Emails with document attachments or PDF Attachments are very popular in spreading malware. The attachment names are typically very enticing to click on. Names like \u201cinvoice.pdf\u201d, \u201creceipt.doc\u201d, \u201cCovid-19 test results.doc\u201d, etc. may invite some curiosity but could also lead to malware.<\/li>\n<li>Ensure you review the hyperlink before you click them. It\u2019s easy to fake the text and get you to an illegit page (Example 2)<\/li>\n<li>Anyone who insists on payments using a pre-paid gift card or wire transfer, instead of your typical credit card is most likely attempting to scam you.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol start=\"2\">\n<li>The end goal of a scammer is that they want to make money &#8211; so be alert with your cards and their activity.\n<ol>\n<li>Avoid using Debit Cards online. Use a prepaid or virtual Credit Card or even better utilize Apple Pay, Google Pay or PayPal for online payments. Payment card services today have advanced fraud monitoring systems<\/li>\n<li>Check CC statements often to look for any unanticipated charges.<\/li>\n<li>If you make a purchase, ensure you have a tracking number and monitor shipments<\/li>\n<li>Disable international purchases if you know you won\u2019t be traveling.<\/li>\n<li>Never wire money directly to anyone you do not know.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h2>What if you are a victim?<\/h2>\n<p>If you believe that you have been a victim of a scam, here are a few tips that might help.<\/p>\n<ol>\n<li>First, get in touch with your Credit Card company and tell them to put a hold on your card. You can dispute any suspicious charges and request an issue of a chargeback<\/li>\n<li>If you have been scammed through popular sites like ebay.com or amazon.com &#8211; contact them directly. If you wired money, contact the wire company directly<\/li>\n<li>File a Police Report. If you gave your personal information away, you might want to go to\n<ol>\n<li>US &#8211; <a href=\"https:\/\/www.identitytheft.gov\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.identitytheft.gov\/<\/a><\/li>\n<li>UK &#8211; <a href=\"http:\/\/www.cifas.org.uk\" target=\"_blank\" rel=\"noopener\">www.cifas.org.uk<\/a><\/li>\n<\/ol>\n<\/li>\n<li>Notify and contribute \u2013 build awareness\n<ol>\n<li>US\n<ol>\n<li><a href=\"https:\/\/reportfraud.ftc.gov\/#\/?pid=A\" target=\"_blank\" rel=\"noopener\">https:\/\/reportfraud.ftc.gov\/#\/?pid=A<\/a> &#8211; (877) 382-4357<\/li>\n<li><a href=\"https:\/\/www.bbb.org\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.bbb.org\/<\/a><\/li>\n<li><a href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.ic3.gov\/<\/a><\/li>\n<li><a href=\"https:\/\/www.fbi.gov\/scams-and-safety\" target=\"_blank\" rel=\"noopener\">https:\/\/www.fbi.gov\/scams-and-safety<\/a><\/li>\n<\/ol>\n<\/li>\n<li>UK\n<ol>\n<li><a href=\"https:\/\/www.actionfraud.police.uk\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.actionfraud.police.uk\/<\/a> &#8211; 0300 123 2040<\/li>\n<li><a href=\"https:\/\/www.gov.uk\/find-local-trading-standards-office\" target=\"_blank\" rel=\"noopener\">https:\/\/www.gov.uk\/find-local-trading-standards-office<\/a><\/li>\n<li><a href=\"https:\/\/www.citizensadvice.org.uk\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.citizensadvice.org.uk\/<\/a><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h2>Example scams:<\/h2>\n<h3>Example 1: Fake SMS messages<\/h3>\n<p>It\u2019s become more common recently to receive text messages for scammers. The following few text messages demonstrate SMSishing attempts.<\/p>\n<ol>\n<li>The first is an attempt to gather Bank Of America details. For the scammer, it\u2019s a shot in the dark. Given, the target is a US number, he attempts to use the phone number that he is sending the text to, as a bank account number and provides a link to a bit.ly page (a URL shortening service) to link to a fake page that poses as a Bank of America login. A successful SMSish would be if the victim entered their details.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">2. The following are fake texts that attempt to entice you click the link. The bait is the Gift card. One can tell that they are a similar theme since they originate from fake phone numbers, which are very similar but not exact. The domain names of the two URLs are totally random (probably compromised URLs). You can tell that back in October, the full URL based SMShing attempts were not very effective which is why in Nov, they probably used keywords like \u201cCOSTCO\u201d and \u201cebay\u201d within the URL and inline to their SMS context, to make it more likely for people to click.<\/p>\n<p>Also note that some of the URLs only have an \u201chttp\u201d versus a \u201chttps\u201d, something we had noted earlier in the blog.<\/p>\n<p>&nbsp;<\/p>\n<h3>Example 2: Fake email link<\/h3>\n<p>One cannot trust an email by the text. You should review the link to ensure it takes you to where it claims to. The following is an example email where the link is not what it claims to be.<\/p>\n<h3>Example 3: Fake Store Scam hosted on Shopify<\/h3>\n<p>Shopify is a Canadian multinational e-commerce company. It offers online retailers a suite of services, including payments, marketing, shipping, and customer engagement tools.<\/p>\n<p>So, where there is money to be made, individuals are looking to take advantage. Shopify scam targets both consumers and business owners. Scammer abuse the power of e-commerce to earn money by implementing fake stores. They observe the product or category, create an attractive logo or image and promote extensively on social media.<\/p>\n<p>Fake Bike Online Purchase store \u2013 Mountain-ranger-com<\/p>\n<p>Site: hxxps:\/\/mountain-ranger-com.myshopify.com\/collections\/all<\/p>\n<p><strong>SSL info:<\/strong><\/p>\n<p>This site is hosted on Shopify, so it has a valid SSL cert which is the first thing we check on where we transact.<\/p>\n<p><strong>Whois Record\u00a0<\/strong><strong>( last updated on 2021-11-19 )<\/strong><\/p>\n<p>Domain\u00a0Name:\u00a0myshopify.com<br \/>\nRegistry\u00a0Domain\u00a0ID:\u00a0362759365_DOMAIN_COM-VRSN<br \/>\nRegistrar\u00a0WHOIS\u00a0Server:\u00a0whois.markmonitor.com<br \/>\nRegistrar\u00a0URL:\u00a0http:\/\/www.markmonitor.com<br \/>\nUpdated\u00a0Date:\u00a02021-03-02T23:39:12+0000<br \/>\nCreation\u00a0Date:\u00a02006-03-03T03:01:37+0000<br \/>\nRegistrar\u00a0Registration\u00a0Expiration\u00a0Date:\u00a02024-03-02T08:00:00+0000<br \/>\nRegistrar:\u00a0MarkMonitor,\u00a0Inc.<br \/>\nRegistrar\u00a0IANA\u00a0ID:\u00a0292<br \/>\nRegistrar\u00a0Abuse\u00a0Contact\u00a0Email:<br \/>\nRegistrar\u00a0Abuse\u00a0Contact\u00a0Phone:\u00a0+1.2083895770<br \/>\nDomain\u00a0Status:\u00a0clientUpdateProhibited\u00a0(https:\/\/www.icann.org\/epp#clientUpdateProhibited)<br \/>\nDomain\u00a0Status:\u00a0clientTransferProhibited\u00a0(https:\/\/www.icann.org\/epp#clientTransferProhibited)<br \/>\nDomain\u00a0Status:\u00a0clientDeleteProhibited\u00a0(https:\/\/www.icann.org\/epp#clientDeleteProhibited)<br \/>\nDomain\u00a0Status:\u00a0serverUpdateProhibited\u00a0(https:\/\/www.icann.org\/epp#serverUpdateProhibited)<br \/>\nDomain\u00a0Status:\u00a0serverTransferProhibited\u00a0(https:\/\/www.icann.org\/epp#serverTransferProhibited)<br \/>\nDomain\u00a0Status:\u00a0serverDeleteProhibited\u00a0(https:\/\/www.icann.org\/epp#serverDeleteProhibited)<br \/>\nRegistrant\u00a0Organization:\u00a0Shopify\u00a0Inc.<br \/>\nRegistrant\u00a0State\/Province:\u00a0ON<br \/>\nRegistrant\u00a0Country:\u00a0CA<br \/>\nRegistrant\u00a0Email:\u00a0Select\u00a0Request\u00a0Email\u00a0Format<\/p>\n<p>The registrar info for the site is valid too, as it is hosted on Shopify. If you look closer, however, one will notice red flags:<\/p>\n<ol>\n<li>Compare these prices listed on other known sites like amazon: Price listed on the fake site versus price listed on Amazon. This is an \u201cunbelievable\u201d deal.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">2. The \u201cAbout Us\u201d doesn\u2019t make much sense when you see the products that are being offered.<\/p>\n<p style=\"padding-left: 40px;\">3. There are no customer reviews about the products listed.<\/p>\n<p style=\"padding-left: 40px;\">4. It has a public email server (gmail) in its return policy<\/p>\n<p style=\"padding-left: 40px;\">5. Looking up the list address in google maps wouldn\u2019t show up anything and looking up the number in apps like true caller shows it&#8217;s fake.<\/p>\n<h3>Example 4: Social Engineering to Steal Credentials<\/h3>\n<p>The goal of this scam is to steal credentials however it could as well be used as a malware delivery mechanism. The screenshot is that of a fake business proposal hosted on OneDrive Cloud for phishing purposes.<\/p>\n<p>The actor aims to mislead the user into clicking on the above reference link. When the user clicks on the link, it redirects to a different website that displays the below fake OneDrive screenshot.<\/p>\n<p>hxxps:\/\/aidaccounts[.]com\/11\/verified\/22\/<\/p>\n<p>If a user enters their OneDrive details, the actors receive them at their backend. This means that this victim has lost their login credentials to the phishing actors. Look at the address bar and trust your instincts. This is in no way related to Microsoft OneDrive. There are other such examples where they do some additional plumbing of the URL to include keywords that make it more believable \u2013 as they did in the SMSishing example above.<\/p>\n<h3>Example 5: Fake Push Notification for surveys<\/h3>\n<p>The goal here is to get the user to accept push notifications. Doing so makes the customer susceptible to other possible scams. In this example, the scammers attempt to get users to fill out surveys. Legit companies online pay users for surveys. A referral code is used to pay the survey taker. The scammer in this case attempts to get others to fill the survey on their behalf and therefore makes money when such surveys use the scammer&#8217;s referral code. Push notifications are used to get the victims to fill out surveys. Previous blogs from McAfee demonstrate similar <a href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/scammers-impersonating-windows-defender-to-push-malicious-windows-apps\/\" target=\"_blank\" rel=\"noopener\">scams<\/a> and how to prevent such <a href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/how-to-stop-the-popups\/\" target=\"_blank\" rel=\"noopener\">notifications<\/a><\/p>\n<p>The initial vector comes to the victim via a spam email with a PDF Spam attachment. In this scenario, Gmail was used as the sender.<\/p>\n<p>Upon opening the PDF, a fake online <a href=\"https:\/\/en.wikipedia.org\/wiki\/PlayerUnknown%27s_Battlegrounds\" target=\"_blank\" rel=\"noopener\">PUBG<\/a> (Players Unknown Battleground) credits generator gets opened. In PUBG, Gamers need credits to participate in various online games and so this scam baits them offering free credits.<\/p>\n<p>Once the user clicks on the bait URL, it opens a google feed proxy URL.<\/p>\n<p>Malicious websites are destined to be block-listed and therefore have short shelf lives. Google\u2019s feed proxy redirects them in adapting to new URLs and therefore utilizes a fast-flux mechanism as a technique to keep the campaign alive. Usage of feed proxy are not new and we have highlighted its use in the past by the <a href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/hancitor-making-use-of-cookies-to-prevent-url-scraping\/\" target=\"_blank\" rel=\"noopener\">hancitor botnet<\/a>.<\/p>\n<p>Clicking on the top highlighted URL, it navigates to a webpage that poses as a PUBG Arcane online credit generator.<\/p>\n<p>To make the online generator look real, the website has added fake recent activities highlighting coins users have earned via this generator. Even the add comments section is fake.<\/p>\n<p>Clicking on continue will bring up a fake progress bar. Now the site shows the coins and cash are ready, however, an automated human verification has failed, and a survey has to be taken up for getting the reward.<\/p>\n<p>A clickable link for this verification is also loaded. Once clicked, a small dialog with 3 options are presented.<\/p>\n<p>Clicking on \u201cwant to become a millionaire\u201d loaded a survey page and prompts you to take it up. It will also prompt you to allow push notifications from this website.<\/p>\n<p>Once you click on \u201cAllow\u201d, notifications to take up a survey or fake personalized offer notifications start popping up. Be it on your desktop or on your mobile, these notifications pop-ups to take up more surveys.<\/p>\n<p>Clicking on the other links too from \u201cHuman Verification\u201d, you will realize that you have finally ended up not gaining anything for your PUBG Arcane gaming, but ended up taking surveys.<\/p>\n<p>Here is another example of a PDF theme we have seen as a lure on the Lenovo tablet offer.<\/p>\n<p>Clicking on this link takes the user to a page that claims it has been protected by a technique to block bots. Persuading you to click on the allow button for enabling popups.<\/p>\n<p>Once you click on the enable button, it then redirects the browser to take up a random survey. In our case, the survey was on household income.<\/p>\n<p>Another such theme that we observed was around the latest Netflix series \u2013 Squid games. Although Series 1 has currently been released, the fake email prompts early access to Season 2.<\/p>\n<p>Scammers spend a lot of time and effort tweaking and tuning their schemes to make it fit just right for you. Avoiding a scam is not full proof but being vigilant is key. Don\u2019t get overly keen when you get offers thrown at you this season. Take a step back, relax and think it through, not only should you do your own research, but you should also trust your instincts. Spending a little extra on products or making donations to a reputable and known organization might be worth the peace of mind during the holidays. Help educate your family and contribute by reporting scams.<\/p>\n<p>Happy Holidays!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In&#8230;<\/p>\n","protected":false},"author":1133,"featured_media":132181,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[],"coauthors":[877],"class_list":["post-132022","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mcafee-labs"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u2018Tis the Season for Scams | McAfee Blog<\/title>\n<meta name=\"description\" content=\"Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u2018Tis the Season for Scams | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-29T22:04:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-26T08:09:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Abhishek Karnik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Abhishek Karnik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"20 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/\"},\"author\":{\"name\":\"Abhishek Karnik\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/dfaabe961cfb62f439791a8dcaef8b9c\"},\"headline\":\"\u2018Tis the Season for Scams\",\"datePublished\":\"2021-11-29T22:04:38+00:00\",\"dateModified\":\"2024-06-26T08:09:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/\"},\"wordCount\":3128,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg\",\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/\",\"name\":\"\u2018Tis the Season for Scams | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg\",\"datePublished\":\"2021-11-29T22:04:38+00:00\",\"dateModified\":\"2024-06-26T08:09:21+00:00\",\"description\":\"Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg\",\"width\":300,\"height\":200},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"\u2018Tis the Season for Scams\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/dfaabe961cfb62f439791a8dcaef8b9c\",\"name\":\"Abhishek Karnik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/d12277b2e0683676282eca22472642c6\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/05\/IMG_8702-96x96.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/05\/IMG_8702-96x96.jpg\",\"caption\":\"Abhishek Karnik\"},\"description\":\"Abhishek Karnik is the Head of Threat Research and Response for McAfee and leads a global team of experts on cybersecurity threats and intelligence with a focus on providing protection content to McAfee products. His team is responsible for Exploit Prevention, Joint Threat Intelligence, AV Protection, URL protection &amp; related response. Together they manage the Threat Landscape across multiple endpoint and cloud products. Abhishek\u2019s passion to keep our customer safe and his contribution to law enforcement efforts have earned him the Intel Achievement Award and the Peter Szor award for his work in fighting cybercrime.\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/abhishek-karnik\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u2018Tis the Season for Scams | McAfee Blog","description":"Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"\u2018Tis the Season for Scams | McAfee Blog","og_description":"Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2021-11-29T22:04:38+00:00","article_modified_time":"2024-06-26T08:09:21+00:00","og_image":[{"width":300,"height":200,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg","type":"image\/jpeg"}],"author":"Abhishek Karnik","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"Abhishek Karnik","Est. reading time":"20 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/"},"author":{"name":"Abhishek Karnik","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/dfaabe961cfb62f439791a8dcaef8b9c"},"headline":"\u2018Tis the Season for Scams","datePublished":"2021-11-29T22:04:38+00:00","dateModified":"2024-06-26T08:09:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/"},"wordCount":3128,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg","articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/","name":"\u2018Tis the Season for Scams | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg","datePublished":"2021-11-29T22:04:38+00:00","dateModified":"2024-06-26T08:09:21+00:00","description":"Co-authored by: Sriram P and Deepak Setty \u2018Tis the season for scams. Well, honestly, it\u2019s always scam season somewhere. In 2020, the Internet Crime and","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#primaryimage","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2021\/11\/300x200_SeasonforScams.jpg","width":300,"height":200},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/tis-the-season-for-scams\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"\u2018Tis the Season for Scams"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/dfaabe961cfb62f439791a8dcaef8b9c","name":"Abhishek Karnik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/d12277b2e0683676282eca22472642c6","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/05\/IMG_8702-96x96.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/05\/IMG_8702-96x96.jpg","caption":"Abhishek Karnik"},"description":"Abhishek Karnik is the Head of Threat Research and Response for McAfee and leads a global team of experts on cybersecurity threats and intelligence with a focus on providing protection content to McAfee products. His team is responsible for Exploit Prevention, Joint Threat Intelligence, AV Protection, URL protection &amp; related response. Together they manage the Threat Landscape across multiple endpoint and cloud products. Abhishek\u2019s passion to keep our customer safe and his contribution to law enforcement efforts have earned him the Intel Achievement Award and the Peter Szor award for his work in fighting cybercrime.","url":"https:\/\/www.mcafee.com\/blogs\/author\/abhishek-karnik\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/132022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/1133"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=132022"}],"version-history":[{"count":4,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/132022\/revisions"}],"predecessor-version":[{"id":195315,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/132022\/revisions\/195315"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media\/132181"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=132022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=132022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=132022"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=132022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}