SUBSCRIBE

Fake receipt program targets Amazon retailers

Amazon retailers are being targeted by fraudsters who have created a custom-built a program that generates fakes receipts for nonexistent orders, according to researchers from GFI Software.

The program is designed to create a customized HTML file that closely resembles an actual Amazon.com receipt, wrote Christopher Boyd, senior threat researcher, on GFIโ€™s blog.

A fraudster can fill out the date, item, price, order number and address among other information. Users also have the option of selecting specific Amazon portals, including โ€œ.com,โ€ โ€œ.co.uk,โ€ โ€œ.frโ€ and โ€œ.ca.โ€

When the โ€œgenerateโ€ button is clicked, a file is placed in the computerโ€™s program folder which is nearly identical to the โ€œprintable order summaryโ€ on a legitimate receipt, Boyd wrote.

The scam relies entirely on social engineering, with the fraudster hoping a vendor will be tricked into thinking a product was sold.

โ€œThe gag here is that the scammer is relying on the seller not checking the details and accepting the printout at face value,โ€ Boyd wrote. โ€œAfter all, how many sellers would be aware somebody went to the trouble of creating a fake receipt generator in the first place?โ€

Retailers can protect themselves by checking their own sales records. Amazon.com will also be able to confirm whether a real sale has taken place, Boyd wrote.

Nonetheless, others interested in defrauding Amazon.com retailers have created derivatives of the program. Boyd includedย a screen shot that shows an imitation of the original receipt generator.

Tech Jobs

Categories