Food-delivery fraudsters deploy hacked accounts, stolen credit card info to skim from orders
Full article546 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The grifters advertise their food delivery payment services on Telegram.
Food delivery apps have taken off during the pandemic, and it looks like fraudsters have taken notice.
Fraud detection company Sift said Thursday it has seen a rash of scams within the chat app Telegram that target restaurants and delivery apps for theft.
It’s a low-level grift that goes like this:
The fraudsters advertise in Telegram forums that they can illicitly buy food orders at steep discounts, around 60%-75% off. Diners send a direct message with a screen shot of their food app shopping cart and delivery address.
The diner then pays the fraudster for the discounted meal in cryptocurrency, and the fraudster in turn covers the full cost through a new account, stolen credit card information or a hacked account.
Diners get their food at a discount, restaurants are stuck with bogus payments, and the crooks get away with a profit. And all of it happens in a chat app that requires no particular cybercrime skill to access.
“The Dark Web can be difficult to access and with frequent marketplace shutdowns by law enforcement, bad actors are looking for new places to commit crime,” said Brittany Allen, trust and safety architect at Sift. “End-to-end encrypted messaging platforms like Telegram are attractive options as they are more accessible and it is easier to go undetected when committing low-level fraud.”
Fraudsters advertised their services heavily on Super Bowl Sunday in particular, the company said.
Sift said it also saw a 14% increase in payment fraud afflicting restaurants and food delivery apps from the third quarter to the fourth quarter of 2020.
The scheme that Sift uncovered isn’t the first to exploit the newfound popularity of food delivery apps.
“We’ve learned that fraudsters visit food delivery websites to test out credit card details they bought on the dark web — manually or using bots — before trying them out on more high-stakes goods,” Riskified wrote in August. “In this practice, scoring a meal is simply a bonus on the way to more lucrative fraud.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fraudsters-food-delivery-sift-telegram/