Scroll to top
Threat Intelligence Factor's research team tracks real-world phishing, impersonation and social-engineering campaigns as they happen. See All Reports →

Stepping Into a Scam: Anatomy of a Fake Storefront

By Guy Ushomirsky, Factor Security Research · 10 Jun 2026

A shopper searching for a well-known footwear brand finds what looks like an official store, at an attractive price. They add an item to the cart and check out — and their payment details go to an attacker instead. Factor's research team recently examined a phishing site built to run exactly that sequence, ranking highly in search results and closely mimicking the brand it impersonated.

  1. Red Flags Hiding in Plain Sight

    Domain age. Scam storefronts typically run on domains registered days or weeks earlier, built to support a short campaign before being taken down. Legitimate retailers, by contrast, tend to hold domains for years. This site's domain was 29 days old at the time it was identified — consistent with a short-lived, throwaway setup rather than an established retailer.

    A URL that doesn't match. The address was close to, but not the same as, the brand's official domain. The real brand does not ship to Argentina; the fake site claimed it did, a detail apparently designed to bait a specific regional audience. Verifying the exact domain in the address bar remains one of the simplest checks available before entering payment information.

    Discounts across the entire catalog. Every product on the site carried a steep markdown — a pattern designed to create urgency and discourage the kind of careful comparison that might otherwise reveal inconsistencies.

    A single, fixed region. The site displayed an Argentina flag in the header with no option to change region, unusual for a global retail brand and consistent with a page built for one targeted audience rather than a genuine international storefront.

    Forced account creation. Legitimate retailers commonly allow guest checkout. This site required account creation before purchase — a pattern that lets an attacker capture email addresses and passwords, which are frequently reused elsewhere, in addition to payment details.

    Visible backend errors. Some pages on the site returned raw database error messages. Well-built retail platforms do not expose stack traces to shoppers; visible errors of this kind are a reliable signal of a hastily assembled site.

  2. Why This Pattern Keeps Working

    None of these signals is dramatic on its own — a new domain, a slightly wrong URL, an aggressive discount. Together, they describe a storefront built quickly, for a narrow audience, with no long-term investment in looking legitimate beyond the surface. That combination is common across fake retail campaigns, and recognizing the pattern is more reliable than looking for any single red flag in isolation.

  3. What This Means for Mobile Shoppers

    A large share of this kind of shopping traffic now happens on mobile, where address bars are truncated, checkout flows move quickly, and the visual cues shoppers rely on to spot a fake site on desktop are harder to see. Real-time inspection of a link at the moment it is opened — rather than relying on the user to manually verify each detail — is the layer of defense that closes that gap, which is the focus of Factor's approach to mobile threat detection.

Fake online store mimicking a well-known retail brand