Most Black Friday scams are built from the same four parts: a lookalike domain, a cloned storefront, a way to steal payment details, and paid ads or social posts to drive traffic. Defenders catch them by watching the places attackers can’t avoid leaving traces, chiefly certificate transparency logs, domain registration data, hosting records and the page code itself, and then getting the sites taken down.
This post walks through both sides as a career starter should learn them: what the attacker does at each step, what evidence that step leaves, and how an analyst finds and acts on it. Black Friday falls on 27 November in 2026, and fake shops are typically set up in the weeks before, so the detection work starts well ahead of the day.
All examples use a fictional retailer, Acme Gadgets, whose real shop is acme-gadgets.test. Only test or investigate systems you own or have written permission to test.
How attackers build a fake shop
1. Register a lookalike domain
The attacker wants a domain that survives a quick glance in an ad, a WhatsApp forward or a browser tab. Common patterns:
| Technique | Example for acme-gadgets.test |
Why it works |
|---|---|---|
| Typosquatting | acme-gadgest.test |
Swapped letters are missed when reading fast |
| Combosquatting | acme-gadgets-blackfriday.test, acmegadgets-deals.test |
Adds a believable word; no misspelling to notice |
| Different TLD | acme-gadgets.shop, acme-gadgets.store |
Looks official, and retail-themed TLDs are cheap |
| Homoglyphs (IDN) | acme-gаdgets.test with a Cyrillic “а” |
Looks identical; the real name is punycode such as xn--... |
| Subdomain tricks | acme-gadgets.test.deals-portal.example |
The brand appears first; the real domain is at the end |
MITRE ATT&CK tracks this as Acquire Infrastructure: Domains (T1583.001). Registering a domain takes minutes, and many registrars allow privacy protection, so the registrant’s identity is usually hidden.
2. Get a certificate so the padlock appears
Free, automated certificate authorities issue a TLS certificate to anyone who controls a domain. That’s a good thing for the web overall, but it means the padlock proves the connection is encrypted, not that the shop is honest. ATT&CK covers this as Obtain Capabilities: Digital Certificates (T1588.004). Remember this step, because it’s also the attacker’s first mistake: certificates are publicly logged.
3. Clone the storefront
Rather than design anything, the attacker copies the real site. Website-mirroring tools, saved pages or an e-commerce template filled with images lifted from the genuine shop produce something convincing in an afternoon. Typical tells that survive the copy:
- Links in the footer still pointing at the real shop’s pages, or returning 404 errors.
- The real shop’s analytics or tracking IDs still in the HTML source.
- The same favicon and logo files, byte for byte.
- Prices too low to be real, with countdown timers and “only 3 left” banners.
- Contact details limited to a web form, a free email address or a WhatsApp number.
4. Take the money, or the card details
There are two main patterns.
Fake checkout on a fake shop. The page collects card numbers, expiry dates and security codes, then shows an error or a “your order is confirmed” message. Nothing ships. Some shops skip card payments entirely and insist on bank transfer, which is much harder to reverse.
Skimming on a real shop. This one is more serious, because the customer is on the genuine site. The attacker compromises the retailer, or one of the third-party scripts it loads, and adds JavaScript to the checkout page that copies whatever the customer types and quietly sends it to the attacker’s server. These attacks are often called Magecart-style or formjacking. In pseudocode, the pattern looks like this:
Skimmer logic (pseudocode, not working code):
on checkout submit → read all form fields → send them to an external lookalike domain
(e.g. cdn-acme-gadgets-static.example)
Notice the exfiltration domain is itself a lookalike, chosen to blend into a list of legitimate script and CDN hosts.
5. Buy traffic
A fake shop is useless without visitors. Attackers use paid social ads, sponsored search results, influencer-style posts and mass messages on WhatsApp and Telegram. Some use “cloaking”, showing a harmless page to ad reviewers and the scam page to everyone else. ATT&CK lists ad-based delivery as Acquire Infrastructure: Malvertising (T1583.008). Ad accounts and pages are often new and short-lived, which is itself a signal.
How defenders catch fake shops
Every step above leaves evidence. Here’s how an analyst at a retailer, a bank or a brand-protection team finds it.
Watch certificate transparency logs
Certificate authorities publish the certificates they issue to public, append-only certificate transparency logs. If someone gets a certificate for acme-gadgets-blackfriday.test, it appears in those logs, often before the site is promoted. Defenders search them for their brand name.
A simple query against crt.sh, a free public CT search service:
curl -s "https://crt.sh/?q=%25acme-gadgets%25&output=json" \
| jq -r ‘.[].name_value’ | sort -u
Illustrative output for our fictional brand:
acme-gadgets-blackfriday.test
acme-gadgets.test
shop.acme-gadgets.test
www.acme-gadgets-blackfriday.test
www.acme-gadgets.test
The first and fourth lines aren’t Acme’s. In production, teams stream new certificates continuously instead of polling, and alert on brand keywords and close spellings.
Generate and check lookalike permutations
Tools such as dnstwist generate typos, homoglyphs and TLD swaps of a domain and check which are registered:
pip install dnstwist
dnstwist --registered acme-gadgets.test
Illustrative output:
*original acme-gadgets.test 192.0.2.10
addition acme-gadgetss.test 203.0.113.45
transposition acme-gadgest.test 203.0.113.45
homoglyph acme-gаdgets.test 198.51.100.7
tld-swap acme-gadgets.shop 203.0.113.45
Three lookalikes resolving to the same address, 203.0.113.45, is worth a closer look: one operator, several domains.
Check domain age and registration data
A shop registered three weeks before Black Friday, claiming “20 years of trusted service”, has a problem. Look up registration data with WHOIS, its structured successor RDAP, or ICANN’s lookup tool:
whois acme-gadgets-blackfriday.test | grep -Ei “creation date|registrar:|name server”
curl -s https://rdap.org/domain/example.com | jq ‘.events’
Illustrative WHOIS result for the lookalike:
Creation Date: 2026-10-02T14:02:11Z
Registrar: Example Registrar, LLC
Name Server: ns1.cheap-dns.example
Domain age alone doesn’t prove fraud, since every honest shop was new once. Combined with brand impersonation it’s a strong signal.
Analyse the URL and the page, safely
Never open a suspected scam site on your work laptop. Use an isolated VM or an online URL scanner, capture a screenshot and the page resources, and compare:
- Do the HTML, logo and favicon files match the real site’s? Identical file hashes suggest a clone.
- Does the page still load the real shop’s analytics ID or images from the real shop’s domain?
- Where does the checkout form submit? A form action pointing to an unrelated domain is a red flag.
- Do DNS and hosting point to a provider the real brand doesn’t use?
dig +short A acme-gadgets-blackfriday.test
203.0.113.45
dig +short NS acme-gadgets-blackfriday.test
ns1.cheap-dns.example.
Our guide on how to analyse a phishing link safely covers the full workflow, including defanging URLs before you share them in tickets.
Detect skimmers on your own checkout
For skimming, the defender is the retailer’s own security team, and the controls sit on the checkout page:
- Script inventory and change detection: know every script that loads on payment pages and alert when one changes. PCI DSS v4 includes requirements on this for payment pages (requirements 6.4.3 and 11.6.1); the PCI Security Standards Council publishes the standard.
- Content Security Policy (CSP): restrict where scripts load from and where the page can send data.
- Subresource Integrity (SRI): pin third-party scripts to a known hash so a tampered file won’t run.
Content-Security-Policy: script-src ‘self’ https://js.payments.example;
connect-src ‘self’ https://api.payments.example; form-action ‘self’
With that policy, the skimmer’s attempt to send data to cdn-acme-gadgets-static.example would be blocked, and if you configure CSP reporting, you’d get a report showing the attempt. OWASP’s Third-Party JavaScript Management Cheat Sheet goes deeper.
Take it down
Finding a fake shop is half the job. Typical takedown steps, done in parallel:
- Collect evidence: screenshots, URLs, WHOIS records, hosting IPs, CT log entries, ad links, timestamps.
- Report to the registrar’s abuse contact (listed in WHOIS/RDAP) for domain suspension.
- Report to the hosting provider’s abuse contact for content removal.
- Report to browser blocklists, for example Google’s Safe Browsing report form, so browsers warn visitors.
- Report the ads and pages to the social or search platform running them.
- Report to national channels where they exist. In the UK, the NCSC runs a scam website reporting service.
- Warn customers through official channels, and block the domains on your own email and web gateways.
Then keep watching. Operators often move to a new domain within days, and the shared IP addresses, name servers and page fingerprints you recorded help you spot the next one.
A defender’s Black Friday checklist
| When | Task |
|---|---|
| 6–8 weeks before | Set up CT log alerts and lookalike-domain monitoring for every brand name |
| 4 weeks before | Freeze and inventory checkout-page scripts; confirm CSP and SRI are in place |
| 2 weeks before | Agree a takedown playbook: who reports, to whom, with what evidence |
| Black Friday week | Daily review of new lookalikes, ad reports and customer complaints |
| After | Review what was found, how fast takedowns happened, and what to automate |
How shoppers can spot a fake website
The personal-safety side is short, because the technical side does most of the work:
- Type the shop’s address yourself or use a bookmark rather than clicking ads.
- Read the whole domain, especially the part just before the first single slash.
- Be wary of prices far below everyone else’s and pressure tactics such as countdown timers.
- Prefer card payments or protected payment methods over direct bank transfer to an individual.
- Remember the padlock means encrypted, not trustworthy.
The UK NCSC’s guidance on shopping online securely is a good page to share with family.
What a beginner can practise this month
- Run the crt.sh query above for a brand you own or your own name and read the results.
- Install dnstwist in your home lab and run it against
example.comto see the permutation types. - Open a phishing email from your own spam folder (in a safe viewer) and practise the URL triage steps; our post on what a SOC analyst looks for in phishing emails gives you the checklist.
- Write a CSP for a simple test page in your lab and watch the browser console block a script from an unlisted domain.
- Map one fake-shop scenario to ATT&CK techniques and write a half-page detection note.
These are the same skills behind account-takeover defence too, covered in our security fundamentals post.