A photo of a woman using her phone and computer to shop online.

Photo by Firmbee.com on Unsplash

How To Avoid Online Scams While Holiday Shopping

November 22, 2023

While online shoppers expect to get fantastic deals on both Black Friday and Cyber Monday, these heavy holiday shopping days are also great for hackers. Here’s how consumers can protect themselves.

In their excitement to get great deals and unique gifts, shoppers could set themselves up for the risk of their private information being stolen. Therefore, shoppers need to check several critical elements of any site they are purchasing from before hitting the pay button.

The FDIC shared a list of the most common scams to look for in a 2022 report. Some are obvious, while others may not be to the average consumer.


The first is to stay away from fake websites and apps. The FDIC reports that scammers often create fake websites similar to the sites of popular retailers. Therefore, consumers are easily tricked into providing their payment information. The scammers take sensitive information and money and never actually send out the purchased products.

Make sure the website is secure. Secure sites are noted by an “https” at the beginning of their URL, with a lock symbol to the left.

Keep track of items purchased online. With so many shoppers spending most of their time buying gifts online, it can be easy to lose sight of what has already been purchased.


The FDIC reports that scammers will often attempt to contact consumers via phone or email, claiming to be from the U.S. Postal Service or a major shipping company. They state the shopper has a package waiting for delivery, and to confirm this, shoppers are asked to provide personal information. This leads scammers to steal this data and open credit accounts in the victim’s name.

NPR states that many of these online vulnerabilities come via a standard method of communication in today’s world: email. They claim cybercrime continues due to the “inherent insecurity of email, a form of communication that’s typically not encrypted or signed by a verified sender or recipient.”

Robert Holmes of Proofpoint told NPR, “So one way to look at this is like Gmail on Black Friday or Cyber Monday. It’s kind of like JFK airport over Thanksgiving. Imagine you were at JFK airport on one of those days with a lot of people coming and going, and imagine a world where that airport didn’t check IDs or didn’t check passports. That would be a bad world. Lots of nefarious activity would happen on busy days in particular.”

Immediately contact your bank if you feel you have been the victim of fraud. In addition, consumers should consider signing up for alert services. Many credit card issuers, banks, and mobile app providers offer methods that notify shoppers about specific account activity, such as recent logins from unrecognized devices.

Recent News

Massive Data Breach Hits Ticketmaster, Affecting 560 Million Customers

Ticketmaster has fallen victim to a significant cyber-attack, potentially compromising the data of up to 560 million customers. The breach was confirmed by Ticketmaster’s parent company, Live Nation, which revealed that a notorious hacking group, ShinyHunters, is behind the attack. The hackers are demanding a ransom of approximately £400,000 to prevent the data from being sold on the dark web.

Toyota Recalls 100,000+ Tundra and Lexus LX SUVs Over Engine Debris Issue

Toyota has announced a recall for over 100,000 Tundra pickups and Lexus LX SUVs in North America due to potential engine issues caused by machining debris. This recall affects certain 2022-2023 models of the Tundra and LX, which are equipped with the new V6 twin-turbo engine. The V6 twin-turbo engine has faced considerable scrutiny regarding its reliability, especially when compared to the previous naturally aspirated V8 engines.

Wordle and Worldle Battle Over Names

A legal dispute has erupted between the wildly popular word game Wordle and the lesser-known geography game Worldle, centering on the similarity of their names. Wordle, which was developed by Josh Wardle in 2021 and later acquired by the New York Times in 2022 for a substantial sum, has gained immense popularity. In this game, players have six attempts to guess a five-letter word. 

FDA Issues Recall for Crecelac Goat Milk Infant Formula

The U.S. Food and Drug Administration (FDA) has issued a safety alert regarding Crecelac Goat Milk Infant Formula and other infant formula products imported and distributed by Dairy Manufacturers Inc. The alert highlights Cronobacter contamination concerns with Crecelac Infant Powdered Goat Milk Infant Formula. Although Dairy Manufacturers Inc. initiated a recall on May 24, 2024, due to non-compliance with FDA regulations, new findings of Cronobacter contamination have prompted further action.