Vigilance is urged during this 2023 Black Friday and Cyber Monday as AI-generated scams enhance the threat to this year’s festive shoppers and it’s revealed that seven in 10 British people worry that AI will make it easier for criminals to commit online fraud.

But while AI scams like voice cloning, romance scams, and language mimicking are on the rise, 93% of the biggest spenders – millennials aged between 24 and 35 – plan to shop during this coming weekend. And they spend an average of $419.52 per person.

But with cybersecurity threats at an all-time high, how can shoppers and businesses stay cyber safe?
Below is Security HQ’s top tips for staying safe online – and the preventative measures that can be taken while shopping for your latest bargain.

Be aware of phishing and Quishing attacks

SecurityHQ analysts have recently observed a significant increase in Business Email Compromise (BEC) regarding phishing attacks containing QR code (Quishing) and captchas for credentials harvesting. Quishing attacks usually occur via the scanning of a QR code. This technique involves tricking users into scanning a QR code using a mobile phone. The QR code then redirects the user to a phishing or fake website that aims to steal their credentials.

Read the small print

If something seems too good to be true, it probably is. While Black Friday deals can offer huge discounts that are genuine, people still need to make money. Anything ridiculously cheap is a red flag.

What to look for:

It is worth checking the reputation score of retailers to determine if that retailer can be trusted.

A website with no company address, descriptions or specifications on items are all red flags. Look for the details. And do not base purchases solely off star ratings as these can be fake.

Pop-ups that offer free electronics are obvious scams containing malicious phishing links and should be avoided at all costs.

Read the small print. Often cons are perfectly visible if you know what to look for. Like seeing a picture of a laptop being advertised, going to buy said laptop for a reduced rate without reading the small print, and receiving a literal picture of a laptop in the post. The devil is in the detail.

Use reputable websites/companies

Tried and Tested – Using websites that are globally known is a good way to avoid any nasty surprises. Even if it is a couple of rands more, it is worth knowing where your money is going and that your purchase will be tracked and delivered.

Use Antivirus Software that will warn you of potentially dangerous sites in search results as well.

Look For Suspicious Emails, as well as suspicious calls and text messages. Never click on a link you are unsure of – and never provide personal information over the phone.

Stop, look, check, pay

Secure Sockets Layers (SSL) are used to ensure data is encrypted before being transmitted across the Web. It is also an indication that an organisation has been verified. Keep an eye out for HTTPS in the address bar rather than HTTP as this highlights a site uses SSL.

Make sure the website that you intend to shop on is not a copy of a legitimate one. Verify that the date and name of the organisation are consistent with the site you are visiting. And look for typos in the URL. Your best bet is to go directly to the website yourself and do not access it through links on other sites/emails.

When using public Wi-Fi, use a VPN as the most effective way to stay safe and so that hackers do not steal your personal data while you are on an unsecure network.

Check your bank account

Use a credit card or payment method which offers protection (eg. PayPal).

Check your accounts regularly for fraudulent activity.

Only provide enough details to complete your purchase (no extra details required).

Keep your passwords safe and don’t use default credentials

Default credentials used by applications and appliances are often published on the Internet. This can be a big problem. An attacker will typically first scan your network to see where they can move next. If an attacker was lucky enough to identify applications or appliances with default credentials enabled, it won’t take them long to hunt on the Internet for these published credentials.

Finally, keep your passwords safe.