Skip to content
Security basics for everyone

Black Friday scams: how attackers build fake shops and how defenders catch them

Black Friday scams explained for cyber beginners: how attackers build fake shops with lookalike domains, clones and skimmers, and how defenders catch them.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

Most Black Friday scams are built from the same four parts: a lookalike domain, a cloned storefront, a way to steal payment details, and paid ads or social posts to drive traffic. Defenders catch them by watching the places attackers can’t avoid leaving traces, chiefly certificate transparency logs, domain registration data, hosting records and the page code itself, and then getting the sites taken down.

This post walks through both sides as a career starter should learn them: what the attacker does at each step, what evidence that step leaves, and how an analyst finds and acts on it. Black Friday falls on 27 November in 2026, and fake shops are typically set up in the weeks before, so the detection work starts well ahead of the day.

All examples use a fictional retailer, Acme Gadgets, whose real shop is acme-gadgets.test. Only test or investigate systems you own or have written permission to test.

How attackers build a fake shop

1. Register a lookalike domain

The attacker wants a domain that survives a quick glance in an ad, a WhatsApp forward or a browser tab. Common patterns:

Technique Example for acme-gadgets.test Why it works
Typosquatting acme-gadgest.test Swapped letters are missed when reading fast
Combosquatting acme-gadgets-blackfriday.test, acmegadgets-deals.test Adds a believable word; no misspelling to notice
Different TLD acme-gadgets.shop, acme-gadgets.store Looks official, and retail-themed TLDs are cheap
Homoglyphs (IDN) acme-gаdgets.test with a Cyrillic “а” Looks identical; the real name is punycode such as xn--...
Subdomain tricks acme-gadgets.test.deals-portal.example The brand appears first; the real domain is at the end

MITRE ATT&CK tracks this as Acquire Infrastructure: Domains (T1583.001). Registering a domain takes minutes, and many registrars allow privacy protection, so the registrant’s identity is usually hidden.

2. Get a certificate so the padlock appears

Free, automated certificate authorities issue a TLS certificate to anyone who controls a domain. That’s a good thing for the web overall, but it means the padlock proves the connection is encrypted, not that the shop is honest. ATT&CK covers this as Obtain Capabilities: Digital Certificates (T1588.004). Remember this step, because it’s also the attacker’s first mistake: certificates are publicly logged.

3. Clone the storefront

Rather than design anything, the attacker copies the real site. Website-mirroring tools, saved pages or an e-commerce template filled with images lifted from the genuine shop produce something convincing in an afternoon. Typical tells that survive the copy:

  • Links in the footer still pointing at the real shop’s pages, or returning 404 errors.
  • The real shop’s analytics or tracking IDs still in the HTML source.
  • The same favicon and logo files, byte for byte.
  • Prices too low to be real, with countdown timers and “only 3 left” banners.
  • Contact details limited to a web form, a free email address or a WhatsApp number.

4. Take the money, or the card details

There are two main patterns.

Fake checkout on a fake shop. The page collects card numbers, expiry dates and security codes, then shows an error or a “your order is confirmed” message. Nothing ships. Some shops skip card payments entirely and insist on bank transfer, which is much harder to reverse.

Skimming on a real shop. This one is more serious, because the customer is on the genuine site. The attacker compromises the retailer, or one of the third-party scripts it loads, and adds JavaScript to the checkout page that copies whatever the customer types and quietly sends it to the attacker’s server. These attacks are often called Magecart-style or formjacking. In pseudocode, the pattern looks like this:

Skimmer logic (pseudocode, not working code):
on checkout submit → read all form fields → send them to an external lookalike domain
                                            (e.g. cdn-acme-gadgets-static.example)

Notice the exfiltration domain is itself a lookalike, chosen to blend into a list of legitimate script and CDN hosts.

5. Buy traffic

A fake shop is useless without visitors. Attackers use paid social ads, sponsored search results, influencer-style posts and mass messages on WhatsApp and Telegram. Some use “cloaking”, showing a harmless page to ad reviewers and the scam page to everyone else. ATT&CK lists ad-based delivery as Acquire Infrastructure: Malvertising (T1583.008). Ad accounts and pages are often new and short-lived, which is itself a signal.

How defenders catch fake shops

Every step above leaves evidence. Here’s how an analyst at a retailer, a bank or a brand-protection team finds it.

Watch certificate transparency logs

Certificate authorities publish the certificates they issue to public, append-only certificate transparency logs. If someone gets a certificate for acme-gadgets-blackfriday.test, it appears in those logs, often before the site is promoted. Defenders search them for their brand name.

A simple query against crt.sh, a free public CT search service:

curl -s "https://crt.sh/?q=%25acme-gadgets%25&output=json" \
  | jq -r ‘.[].name_value’ | sort -u

Illustrative output for our fictional brand:

acme-gadgets-blackfriday.test
acme-gadgets.test
shop.acme-gadgets.test
www.acme-gadgets-blackfriday.test
www.acme-gadgets.test

The first and fourth lines aren’t Acme’s. In production, teams stream new certificates continuously instead of polling, and alert on brand keywords and close spellings.

Generate and check lookalike permutations

Tools such as dnstwist generate typos, homoglyphs and TLD swaps of a domain and check which are registered:

pip install dnstwist
dnstwist --registered acme-gadgets.test

Illustrative output:

*original      acme-gadgets.test           192.0.2.10
addition       acme-gadgetss.test          203.0.113.45
transposition  acme-gadgest.test           203.0.113.45
homoglyph      acme-gаdgets.test           198.51.100.7
tld-swap       acme-gadgets.shop           203.0.113.45

Three lookalikes resolving to the same address, 203.0.113.45, is worth a closer look: one operator, several domains.

Check domain age and registration data

A shop registered three weeks before Black Friday, claiming “20 years of trusted service”, has a problem. Look up registration data with WHOIS, its structured successor RDAP, or ICANN’s lookup tool:

whois acme-gadgets-blackfriday.test | grep -Ei “creation date|registrar:|name server”
curl -s https://rdap.org/domain/example.com | jq ‘.events’

Illustrative WHOIS result for the lookalike:

Creation Date: 2026-10-02T14:02:11Z
Registrar: Example Registrar, LLC
Name Server: ns1.cheap-dns.example

Domain age alone doesn’t prove fraud, since every honest shop was new once. Combined with brand impersonation it’s a strong signal.

Analyse the URL and the page, safely

Never open a suspected scam site on your work laptop. Use an isolated VM or an online URL scanner, capture a screenshot and the page resources, and compare:

  • Do the HTML, logo and favicon files match the real site’s? Identical file hashes suggest a clone.
  • Does the page still load the real shop’s analytics ID or images from the real shop’s domain?
  • Where does the checkout form submit? A form action pointing to an unrelated domain is a red flag.
  • Do DNS and hosting point to a provider the real brand doesn’t use?
dig +short A acme-gadgets-blackfriday.test
203.0.113.45
dig +short NS acme-gadgets-blackfriday.test
ns1.cheap-dns.example.

Our guide on how to analyse a phishing link safely covers the full workflow, including defanging URLs before you share them in tickets.

Detect skimmers on your own checkout

For skimming, the defender is the retailer’s own security team, and the controls sit on the checkout page:

  • Script inventory and change detection: know every script that loads on payment pages and alert when one changes. PCI DSS v4 includes requirements on this for payment pages (requirements 6.4.3 and 11.6.1); the PCI Security Standards Council publishes the standard.
  • Content Security Policy (CSP): restrict where scripts load from and where the page can send data.
  • Subresource Integrity (SRI): pin third-party scripts to a known hash so a tampered file won’t run.
Content-Security-Policy: script-src ‘self’ https://js.payments.example;
  connect-src ‘self’ https://api.payments.example; form-action ‘self’

With that policy, the skimmer’s attempt to send data to cdn-acme-gadgets-static.example would be blocked, and if you configure CSP reporting, you’d get a report showing the attempt. OWASP’s Third-Party JavaScript Management Cheat Sheet goes deeper.

Take it down

Finding a fake shop is half the job. Typical takedown steps, done in parallel:

  1. Collect evidence: screenshots, URLs, WHOIS records, hosting IPs, CT log entries, ad links, timestamps.
  2. Report to the registrar’s abuse contact (listed in WHOIS/RDAP) for domain suspension.
  3. Report to the hosting provider’s abuse contact for content removal.
  4. Report to browser blocklists, for example Google’s Safe Browsing report form, so browsers warn visitors.
  5. Report the ads and pages to the social or search platform running them.
  6. Report to national channels where they exist. In the UK, the NCSC runs a scam website reporting service.
  7. Warn customers through official channels, and block the domains on your own email and web gateways.

Then keep watching. Operators often move to a new domain within days, and the shared IP addresses, name servers and page fingerprints you recorded help you spot the next one.

A defender’s Black Friday checklist

When Task
6–8 weeks before Set up CT log alerts and lookalike-domain monitoring for every brand name
4 weeks before Freeze and inventory checkout-page scripts; confirm CSP and SRI are in place
2 weeks before Agree a takedown playbook: who reports, to whom, with what evidence
Black Friday week Daily review of new lookalikes, ad reports and customer complaints
After Review what was found, how fast takedowns happened, and what to automate

How shoppers can spot a fake website

The personal-safety side is short, because the technical side does most of the work:

  • Type the shop’s address yourself or use a bookmark rather than clicking ads.
  • Read the whole domain, especially the part just before the first single slash.
  • Be wary of prices far below everyone else’s and pressure tactics such as countdown timers.
  • Prefer card payments or protected payment methods over direct bank transfer to an individual.
  • Remember the padlock means encrypted, not trustworthy.

The UK NCSC’s guidance on shopping online securely is a good page to share with family.

What a beginner can practise this month

  • Run the crt.sh query above for a brand you own or your own name and read the results.
  • Install dnstwist in your home lab and run it against example.com to see the permutation types.
  • Open a phishing email from your own spam folder (in a safe viewer) and practise the URL triage steps; our post on what a SOC analyst looks for in phishing emails gives you the checklist.
  • Write a CSP for a simple test page in your lab and watch the browser console block a script from an unlisted domain.
  • Map one fake-shop scenario to ATT&CK techniques and write a half-page detection note.

These are the same skills behind account-takeover defence too, covered in our security fundamentals post.

Questions

What are the most common Black Friday scams?

Fake shops on lookalike domains, ads promoting deals that don't exist, phishing messages about orders or deliveries, and payment-card skimming on compromised legitimate shops.

How do defenders find fake shops before customers do?

Mainly by monitoring certificate transparency logs and new domain registrations for brand names and lookalikes, then checking hosting and page content to confirm a clone.

Does HTTPS mean a shop is safe?

No. HTTPS means the connection is encrypted. Anyone who controls a domain can get a certificate, including scammers.

Can I take down a fake website myself?

Anyone can report one to the registrar, the host and browser blocklists. Brands and their security teams usually get faster results because they can show the impersonation clearly.