logo

[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)

ID: 94b8c7b6-162c-56e6-b041-eefce547b7ee

STIX ID: report--94b8c7b6-162c-56e6-b041-eefce547b7ee

Feed Name: SANS ISC Diary

Threat Score
55/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

...
...

This report documents a scam campaign where attackers compromise legitimate sites (likely WordPress) to publish thousands of fake marketplace listings that rank in search engines (SEO poisoning). Victims redirected to these listings are sent through cloned checkout/payment pages that harvest card and personal data; the author validated the behavior with test purchases and observed declined and subsequent unauthorized charge attempts. The report includes multiple indicators of compromise (marketplace, redirector, and payment page domains) and demonstrates an active, low-to-moderate sophistication fraud operation targeting consumers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.