Mon–Sat, 9:00 AM – 7:00 PM IST India · Remote
Advisory

Festive sale season is peak season for fake shopping sites

The discount that looks too good usually is. Four habits that cost nothing and stop most festive-season shopping fraud before the payment screen.

9 Oct 2026 4 min read Somendra Nath Tiwari, CISSP · discussion on LinkedIn

Fraudulent storefronts are seasonal, and the season is now. They are cheap to build, they live for a few weeks, and they are advertised into exactly the feeds where people are already shopping. By the time the reviews catch up, the domain is gone and a new one is running the same template.

The good news is that almost all of it is defeated by habits rather than by expertise. None of the four below requires you to know anything about security.

Type the address yourself

This is the single highest-value habit on the list. Tapping an advertisement, a forwarded WhatsApp link or a link in an SMS puts you wherever the sender chose. Typing the brand you meant to visit into the address bar, or opening the brand’s own app, puts you where you intended. A fake site cannot intercept a destination you navigated to yourself.

Treat 80–90% off as a warning, not an offer

Real festive discounting on electronics and branded goods runs in a fairly predictable band. When a listing is far outside it — a flagship phone at a third of its price, a “free gift” worth more than the item — the number is not a bargain, it is the bait. The discount is set at whatever level overrides caution, which is why it is always slightly absurd.

Pay only where you already have an account

Apps and sites you have used before, with a payment method you have used before. A checkout that insists on an unusual route — a UPI collect request, a direct transfer to an individual’s account, a QR code you must scan to receive a refund — is not a checkout. Nobody legitimate ever needs you to approve a payment in order to be paid money.

The refund-QR rule

Scanning a QR code or entering your UPI PIN only ever sends money out. It never brings money in. Anyone walking you through a scan “to process your refund” is taking the money, not returning it — no exceptions, no special cases.

Check the small things before the payment screen

  • A domain that is nearly right — an extra hyphen, a swapped letter, an unusual ending bolted onto a familiar brand name.
  • No reachable phone number, no registered address, no returns policy that says anything specific.
  • Reviews that are all five stars, all recent, and all written in the same voice.
  • Pressure timers and “only 2 left” counters that reset when you reload.

Any one of these can appear on a legitimate small retailer. Two or three together, on a site you reached from an advertisement, is enough to close the tab.

If money has already gone

Call the national cybercrime helpline 1930 or file at cybercrime.gov.in. Report within the first few hours if you can — the sooner the bank is notified, the better the chance the transfer can be frozen before it is withdrawn.

Join WhatsApp Community

Frameworks we work against

ISO/IEC 27001ISO/IEC 42001SOC 2PCI DSSRBI Cyber Security FrameworkDPDP Act 2023CERT-In DirectionsNIST CSFplus custom frameworks, mapped on request