Black Friday punch-ups will give way to Cyber Monday fraud

happygeek 0 Tallied Votes 314 Views Share

Black Friday has historically been a very American phenomenon, marking the start of the seasonal Xmas shopping rush and happening the Friday after Thanksgiving. In the past it has led to scenes of semi-rioting and chaos in some stores as the Walmartarati fight over bargain electrical goods. The UK got a taste of the madness yesterday, with shoppers working themselves into a frenzy at various Walmart-owned ASDA supermarket stores across the country. Some of the most violent scenes were witnessed at the West Belfast, Northern Ireland branch of ASDA where one woman was hospitalized and of pensioners being pushed to the ground and a disabled woman trampled on and having her arm broken in the process have emerged. Most of the carnage apparently caused by attempts to grab TVs and tablet PCs that were heavily discounted for the sale.

If that weren't bad enough, the chaos looks like it could continue after the calm of the weekend with Cyber Monday. Cyber what now? Cyber Monday happens the Monday after Thanksgiving in the US, and is nothing more than an attempt to cash in on the whole Black Friday thing but within the online retail sector rather than the high street. If you've not heard of it, you've not been paying attention as the marketers first launched the Cyber Monday concept way back in 2005 when shop.org used the term in a press release. Since then it has really taken hold and consumers seem to have fallen for the marketing drivel, with statistics showing that it has become one of the biggest 'spending days' of the year with more than $1 billion in a single day in the US alone. It has, of course, also 'gone global' and now some security experts are warning that Cyber Monday is as popular with fraudsters as it is with shoppers.

James Nunn-Price, UK head of cyber security at Deloitte, says that "spammers will be using the opportunity to send out increased amounts of fake offers and phishing emails, hoping that consumers will have their guard down and be tricked into giving up their personal details". And that's just for starters. "We also expect to see more instances of cybersquatting, where fraudsters set up fake websites which look like the real thing" Nunn-Price warns. Coupon-sites and discount-code distributors are likely to be the main focus for the fraudsters, so watch out when looking for those bargains.

It's not just the consumers that are being targeted though, retailers themselves are likely to see losses through an increase in fraudulent payments. "Companies’ fraud controls will be tested as they try to process high volumes of orders as fast as possible, and smaller online businesses, some of whom might have manual back office processes, may struggle to perform thorough checks" Nunn-Price says, concluding "companies pushing Cyber Monday deals should make sure they are able to safely deal with the extra transactions".

Dani AI

Generated

As flagged, the seasonal shift from in‑store chaos to online volume makes Cyber Monday a prime opportunity for scammers. The pressure to move orders quickly increases false negatives in fraud screening; attackers exploit that predictable window with phishing, typosquatting, coupon scams, account takeover and card‑not‑present (CNP) fraud.

Key consumer precautions:

  • Prefer credit cards or virtual/one‑time card numbers where available; these limit liability compared with debit cards.
  • Always confirm the retailer domain in the browser (type known URLs rather than clicking email links); watch for small typos and odd subdomains.
  • Check for HTTPS and a valid certificate before entering payment data; avoid purchases over public Wi‑Fi.
  • Use unique passwords and enable multi‑factor authentication on retail accounts.
  • Treat ‘too good to be true’ coupon sites and unsolicited offers as high risk; validate coupons via the retailer’s official site.
  • Monitor bank statements and enable real‑time transaction alerts; report suspicious charges immediately.

Practical steps for merchants:

  • Test peak‑load checkout and fraud workflows before the sale window; stress testing prevents both outages and rule failures.
  • Deploy layered defenses: AVS/CVV, 3‑D Secure, tokenization, device fingerprinting and velocity/geolocation rules; tune rules to reduce false positives.
  • Hold high‑risk orders (high value, shipping/billing mismatch, new account + high spend) for short manual review with a clear SOP.
  • Use DMARC/DKIM/SPF for corporate email to reduce phishing spoofing and monitor for typosquat domains; register common misspellings and set takedown processes.
  • Work closely with the payment gateway/acquirer for chargeback management and rapid dispute data collection.
  • Train front‑line support to recognise social engineering and record logs for forensic follow up.

Criminals follow volume. Balancing automated screening with targeted manual review, pre‑season testing, and clear incident procedures materially reduces both consumer harm and merchant losses.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.