Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
Bitdefender Labs uncovered more than 55 fake-shop campaigns operating across 12 European countries between March and May 2026, impersonating major global brands including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. These counterfeit storefronts lured consumers with fraudulent deals on high-value products and World Cup-themed scams, exploiting brand recognition to steal payment information and distribute counterfeit goods. The investigation highlights a coordinated e-commerce fraud operation targeting European consumers at scale.
Fortra's threat intelligence team has identified a phishing technique called Chameleon SEO Poisoning that leverages manipulated search results and cloaked fake banking websites to harvest credentials while remaining invisible to security scanners. The attackers optimize these pages for high-intent keywords mimicking legitimate banking portals and reported a 40% increase in cases during Q2 2026. The websites employ evasion tactics to detect and avoid security tools, making this approach particularly difficult for traditional detection methods.
Researchers have identified iAuthFlow V2, a phishing toolkit that exploits passkey authentication by registering attacker-controlled passkeys to maintain persistent access to compromised accounts. This capability allows attackers to retain access even after victims reset their passwords or revoke active sessions, representing a significant evolution in phishing attack sophistication that targets modern authentication mechanisms.
Researchers at Allure Security discovered a widespread scam operation leveraging a cheap website template to create hundreds of fraudulent bank domains designed to deceive victims. The investigation began when a suspicious domain mimicking a legitimate financial services client was found hosting an unrelated bank's branding, ultimately revealing a coordinated scheme to build phantom banking sites for scamming purposes. The $25 template appears to have been a key tool enabling scammers to rapidly deploy deceptive financial websites at scale.
Russian threat actors are incorporating OAuth abuse tactics into their targeted phishing campaigns, leveraging legitimate authentication mechanisms to compromise victims. The attacks specifically impersonate State Department communications, making them particularly credible to government and diplomatic personnel.