Your IP:Unknown

·

Your Status: Unknown

Skip to main content

Malicious shopping and delivery websites target consumers during the discount season

Published on March DATE, 2026

NordVPN’s Threat Protection Pro™ data shows a sharp rise in cyberattacks targeting holiday shoppers, with a 250% jump in fake shopping websites and an 86% increase in malicious postal service sites. Ultimately, fraudsters are weaponizing holiday urgency, combining retail impersonation and delivery scams to catch potential victims at their most vulnerable.

Key takeaways

According to NordVPN’s Black Friday scam data, scammers took advantage of the Black Friday and Cyber Monday rush, resulting in a 250% increase in fake shopping sites during the past month. eBay spoofing attempts went up by 525%, and fake Amazon sites rose by 232%. Since 68% of consumers cannot identify phishing websites, searching for online deals has become significantly riskier.

After people place orders, criminals switch to SMS phishing, also known as "smishing," and send fake tracking links. Malicious postal service websites increased by 86% in just one month. DHL is still the most impersonated brand overall, with fake sites up 206%, but the United States Postal Service (USPS) saw the biggest jump, with impersonations rising by 850%. These scams often say packages are "on hold" because of unpaid fees, taking advantage of people’s worries about missing holiday deliveries.

These attacks work so well because they create a sense of urgency and target people on their phones. In 2024, text message scams have caused $470 million in losses, which is five times more than in 2020. To stay safe, users should check website addresses carefully and use official apps instead of clicking on tracking links sent by text or email.

Methodology

The statistics mentioned above were acquired by analyzing aggregated data gathered by NordVPN’s Threat Protection Pro™ service from August 1, 2025, to October 31, 2025. NordVPN is not endorsed by, maintained by, sponsored by, affiliated with, or in any way associated with the owners of the mentioned brands. Brand names are indicated solely for the purpose of accurately reporting information related to brands that were most likely to be impersonated for spreading malware.

A bar chart with three key takeaways from NordVPN’s Research Lab.