Technology
China's vast cyber trafficking network dupes Americans using fake shops
A Chinese network running countless fake online shops has scammed over 800,000 people in the U.S. and Europe, according to The Guardian.
These shops dupe people into sharing card details and other sensitive personal data by touting to offer discounted goods from Dior, Nike, Lacoste, Hugo Boss, Versace, and Prada, as well as many other premium brands.
A woman shopping online (Kurt “CyberGuy” Knutsson)
How this online scam works
The Chinese network has more than 22,500 fake online shops that are live, according to an international investigation by The Guardian, Die Zeit, and Le Monde. These online shops lure people into giving away their credit card and debit card details, names, phone numbers, email and postal addresses by claiming to offer designer brands at a discount.
GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE
There are two levels of this scam. In the first level, fake payment gateways trick people into entering their credit card information, but they don’t charge them. This lets the scammers steal card details without taking money. In the second level, the criminals set up fake online stores or other platforms where they actually take money from people.
The Chinese network uses expired domains to host its fake shops, which helps them avoid detection by websites or brand owners. The network is reported to have a database of 2.7 million of these orphaned domains and runs tests to check which ones are best to use.
To date, approximately 800,000 people, primarily in the U.S. and Europe, have shared their email addresses, with 476,000 of them also providing their debit and credit card details, including the three-digit security numbers. The first fake shops in this network were established in 2015. Since then, the group may have attempted to steal up to approximately $54.2 million.
‘TOP GUN’ PRODUCER SAYS HE DOESN’T BELIEVE CLAIMS AI WILL REPLACE KEY JOBS
Man shopping online (Kurt “CyberGuy” Knutsson)
RECLAIM YOUR PRIVACY BY DISABLING YOUR CELL PHONE CARRIER’S DATA TRACKING
What did affected people say
Many people thought these fake online shops were legit and placed orders, thinking they were getting a great deal. Melanie Brown from Shropshire, England, told The Guardian she was looking for a new handbag and found a leather bag from her favorite German designer, Rundholz, at 50% off on one of these fake online shops. Tempted by the deal, she added it to her cart, along with other designer clothes from Magnolia Pearl, totaling £1,200, which is the equivalent of approximately $1,529for 15 items. However, Brown never received the items.
The Guardian interviewed 19 people from the U.S. and the U.K., revealing these websites were not designed to sell counterfeit goods. Most received nothing, while a few got incorrect items. One German shopper paid for a blazer but got cheap sunglasses. A British customer received a fake Cartier ring instead of a shirt, and another got a non-branded blue jumper instead of the Paul Smith one they ordered.
SUBSCRIBE TO KURT’S YOUTUBE CHANNEL FOR QUICK VIDEO TIPS ON HOW TO WORK ALL OF YOUR TECH DEVICES.
What does this online scam mean for your privacy and security
The fake online shop scam doesn’t immediately cause monetary harm to you. As The Guardian reports, “many who tried to shop never lost money. Either their bank blocked the payment or the fake shop itself did not process it.”
However, in all cases, these scammers obtained your data, including your address and card details. This data can be used in many ways. The scammers can use it to steal more money than you’d spend on the online shop. They can impersonate your bank or someone you know to trick you into giving them money. Additionally, they can sell this data to dark web criminals or companies for marketing purposes.
A man working on his laptop (Kurt “CyberGuy” Knutsson)
MASSIVE DELL DATA BREACH HITS 49 MILLION USERS — WHAT THIS MEANS FOR YOUR PRIVACY AND SECURITY
7 proactive measures to take to protect your data
Online shopping scams can affect anyone and everyone. Here are seven steps you should take to protect your money and your personal data:
1. Invest in personal data removal services: If you ever got scammed through these fake online shops, your data is probably out there online. Personal data removal services can help by scouring the many people search and data broker websites for your data and requesting its removal.
While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for personal data removal services here.
CYBERSECURITY EXPERTS SOUND ALARM OVER US POWER GRID VULNERABILITIES
2. Avoid tech support phone scams: Since the hackers have your name and contact number, they may try to get in touch with you, posing as an employee of a popular tech company. They might say they’re from Apple, Microsoft, Amazon or any other big company. Always verify if the tech support person you’re talking to actually works for the company.
3. Be cautious when shopping online: Only shop on reputable, well-known websites that you trust. Be wary of unfamiliar online stores offering steep discounts on luxury brands. Check the website’s URL and security credentials (look for https:// and a lock icon) before entering payment information. Use credit cards rather than debit cards for online purchases, as credit cards offer better fraud protection.
4. Be wary of mailbox communications: Scammers may also try to scam you through the mail. The fake online shops have access to your address. They may impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions and security alerts.
5. Monitor your accounts and transactions: You should regularly check your online accounts and transactions for suspicious or unauthorized activity. If you notice anything unusual, report it to the service provider or the authorities as soon as possible.
6. Use identity theft protection: Identity theft protection companies can track personal information like your home title, Social Security number, phone number and email address and notify you if it’s used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals. See my tips and best picks on how to protect yourself from identity theft.
7. Secure your devices and accounts: Use strong, unique passwords for all your online accounts and enable two-factor authentication whenever possible. Keep your devices updated with the latest security patches and use strong antivirus software.
The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android & iOS devices.
Kurt’s key takeaways
Online scams are a growing problem, and you must stay vigilant. Scammers are trying their best to access your data to sell it to companies or other scammers. Tech giants need to implement more stringent measures to protect you from being scammed. Also, when shopping online, make sure you buy from trusted vendors and double-check before entering any personal information. In addition, be sure to follow the seven steps we outlined above to protect your money and your personal data. You’ll be glad you did.
Do you think online shopping is unsafe? Have you started buying stuff offline due to concerns about privacy and security? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
YouTube Music starts putting lyrics behind a paywall
Free YouTube Music accounts are now seeing their access to lyrics limited, according to multiple reports. Google started testing lyrics as an exclusive feature for Premium users in September, but it appears that it’s now receiving a wider rollout. It seems that free users will be limited to viewing lyrics for five songs per month, though we’ve reached out to Google for confirmation.
Once that limit is reached, users will only be able to see the first couple of lines. Everything beyond that will be blurred out, and they’ll be prompted to “Unlock lyrics with Premium.” The banner warning users about their limited lyric views remaining appears prominently when you open the tab, complete with a countdown.
Technology
SoundCloud data breach exposes 29.8 million user accounts
NEWYou can now listen to Fox News articles!
Hackers have exposed personal and contact information tied to SoundCloud accounts, with data breach notification service Have I Been Pwned reporting impacts to approximately 29.8 million users. The breach hit one of the world’s largest audio platforms and left many users locked out with error messages before the company confirmed the incident.
Founded in 2007, SoundCloud grew into an artist-first service hosting more than 400 million tracks from over 40 million creators. That scale made this incident especially concerning. SoundCloud said it detected unauthorized activity tied to an internal service dashboard and launched its incident response process. At the time, users reported 403 Forbidden errors, especially when connecting through VPNs.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter
149 MILLION PASSWORDS EXPOSED IN MASSIVE CREDENTIAL LEAK
SoundCloud confirmed unauthorized activity after users reported access errors, triggering an internal incident response. (iStock)
What data was exposed in the SoundCloud breach
SoundCloud initially said attackers accessed limited data and did not touch passwords or financial information. The company said the exposed information matched what users already show publicly on profiles.
Later disclosures painted a much bigger picture.
According to Have I Been Pwned, attackers harvested data from approximately 29.8 million accounts. That data included:
- Email addresses
- Usernames and display names
- Profile photos and avatars
- Follower and following counts
- Geographic locations, in some cases
While no passwords were taken, linking emails to public profiles creates real risk. That combination fuels phishing, impersonation and targeted scams.
Who is behind the attack
Security researchers tied the breach to ShinyHunters, a well-known extortion gang. Sources told BleepingComputer that the group attempted to extort SoundCloud following the data breach. SoundCloud later confirmed those claims. In a January update, the company said attackers made demands and launched email-flooding campaigns to harass users, employees and partners. ShinyHunters has also claimed responsibility for recent voice phishing attacks targeting single sign-on systems at Okta, Microsoft and Google. Those attacks targeted corporate SaaS accounts to steal data and extort.
Why this breach matters even without passwords
At first glance, this may sound less serious than breaches involving passwords or credit cards. That assumption can be dangerous. Email addresses tied to real profiles allow scammers to craft convincing messages. They can pose as SoundCloud, brands or even other creators. With follower counts and usernames, messages feel personal and believable. Once attackers gain trust, they push links, malware or fake login pages. That is often how larger account takeovers begin.
What SoundCloud users should expect next
SoundCloud has not said whether more details will be released. The company did confirm the attack and the extortion attempt, but it has not answered follow-up questions about the scope or internal controls. For users, the long-term risk comes from how widely this dataset spreads. Once published, exposed data rarely disappears. It circulates across forums, marketplaces and scam networks for years.
We reached out to SoundCloud for comment, and a representative told us, “We are aware that a threat actor group has published data online allegedly taken from our organization. Please know that our security team—supported by leading third-party cybersecurity experts—is actively reviewing the claim and published data.”
SoundCloud has said it has found no evidence that sensitive data, such as passwords or financial information, was accessed.
Ways to stay safe after the SoundCloud breach
If you have or had a SoundCloud account, now is the time to act. Even limited data exposure can lead to targeted scams if you ignore it.
1) Watch for phishing and impersonation emails
Scammers often move fast after a breach. Watch your inbox for messages that mention SoundCloud, music uploads, copyright issues or account warnings. Do not click links or open attachments from unexpected emails. When in doubt, go directly to the official website instead of using email links. Strong antivirus software adds another layer of protection here.
Nearly 29.8 million accounts had emails and public profile data harvested, raising concerns about phishing and impersonation. (Cyberguy.com)
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
2) Change your SoundCloud password anyway
Passwords were not exposed, but changing them is still smart. Create a new password that you do not use anywhere else. If remembering passwords feels impossible, consider using a password manager to generate and securely store strong passwords. This reduces the risk of reuse across platforms.
Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
3) Turn on two-factor authentication
Two-factor authentication (2FA) adds a critical barrier if someone tries to access your account. Even if attackers guess or obtain a password later, they still need a second verification step. Enable 2FA anywhere SoundCloud or connected services offer it.
4) Lock down your email account
Your email is the real target after most breaches. If someone gains access to it, they can reset passwords everywhere else. Use a strong, unique password for your email account and turn on two-factor authentication. Review recovery emails and phone numbers to make sure they still belong to you.
DATA BREACH EXPOSES 400,000 BANK CUSTOMERS’ INFO
5) Reduce your online data footprint
Attackers use breached emails to search data broker sites and social platforms for more details. The less data available, the harder you are to target. Consider a data removal service to limit how often your email and personal details appear across the web.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com
6) Check your other accounts for suspicious activity
Attackers often reuse exposed email addresses to test logins across streaming services, social media and shopping accounts. Watch for password reset emails you did not request or login alerts from unfamiliar locations. If something looks off, act fast.
Security researchers linked the breach to the ShinyHunters extortion group, which later attempted to pressure SoundCloud for payment. (Thomas Trutschel/Photothek via Getty Images)
Kurt’s key takeaways
Data breaches no longer stay contained to one app or one moment in time. Even when attackers expose information that looks harmless, the fallout can last much longer. The SoundCloud breach shows how public profile data paired with private contact details creates real exposure. Staying alert, limiting data sharing and using strong security habits remain your best defense as breaches continue to escalate.
Have you checked which old or forgotten accounts still expose your email and could be putting you at risk right now? Let us know your thoughts by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Former Tumblr head Jeff D’Onofrio steps in as acting CEO at the Washington Post
After what can generously be called a contentious tenure as the CEO of The Washington Post, Will Lewis is stepping down following mass layoffs this week. Jeff D’Onofrio, former CEO of Tumblr from 2017 to 2022, will step in as acting CEO and publisher. D’Onofrio has been CFO at the Post since June of last year, meaning he’s had a front row seat to Jeff Bezos’ dismantling of the once storied paper for the last nine months.
D’Onofrio’s resume doesn’t include extensive experience in traditional news media, nor many notable success stories. He was briefly the general manager of Yahoo News while it was still a Verizon property, before shifting his focus solely to Tumblr. Under his leadership, Tumblr tried to clean up its image by banning adult content, but its traffic fell by 30 percent. Yahoo had purchased Tumblr for $1.1 billion in 2013. By 2019, it was sold to Automatic, the owner of WordPress, reportedly for less than $3 million.
-
Indiana1 week ago13-year-old rider dies following incident at northwest Indiana BMX park
-
Massachusetts1 week agoTV star fisherman, crew all presumed dead after boat sinks off Massachusetts coast
-
Tennessee1 week agoUPDATE: Ohio woman charged in shooting death of West TN deputy
-
Indiana7 days ago13-year-old boy dies in BMX accident, officials, Steel Wheels BMX says
-
Politics5 days agoTrump unveils new rendering of sprawling White House ballroom project
-
Politics1 week agoDon Lemon could face up to a year in prison if convicted on criminal charges
-
Austin, TX1 week ago
TEA is on board with almost all of Austin ISD’s turnaround plans
-
San Francisco, CA5 days agoExclusive | Super Bowl 2026: Guide to the hottest events, concerts and parties happening in San Francisco