Black Friday Scams on the Rise: how to Recognize Them Immediately

eLearning Expert Talks
17 November 2025
black friday - Maurizio Zacchi

Hackers exploit the rush for discounts: here are the most common techniques and checks to perform before every online purchase.

  • Hacker attacks during the Black Friday will increase by 400%, with artificial intelligence making scams ten times more effective and almost 40% of Italians already victims of online fraud.
  • Social shopping and Buy Now Pay Later services represent new frontiers for criminals, with TikTok Shop multiplying the risks of cyberattacks.
  • Protection requires essential precautions: verify HTTPS, use prepaid or virtual cards, avoid public Wi-Fi networks, and be wary of excessively advantageous discounts.

The most anticipated time of the year for online shopping is turning into a real festival for cybercriminals. While millions of Italians prepare to hunt for the perfect deal between Black Friday and Cyber Monday, hackers are honing their digital weapons, targeting the shopping frenzy that leads to thoughtless clicks. This year, the situation is particularly critical: artificial intelligence has exponentially expanded the deception capabilities of digital scammers, making their techniques ten times more effective than in the past.

The numbers tell a worrying story. Experts like Cyber Guru predict a 400% increase in hacker attacks during the Black Friday period, while the eCommerce B2c Observatory of the Politecnico di Milano estimates that Italians will spend over 2 billion euros on online purchases between Black Friday and Cyber Monday, with a 9% increase compared to the previous year. However, behind this rush for discounts lies an alarming fact: almost 40% of Italians have already fallen victim to online scams related to sales.

The arsenal of cybercriminals has been enriched with increasingly sophisticated tools. In 2024, over 38 million phishing attacks were recorded worldwide, posing as legitimate marketplaces, with a 25% increase compared to the previous year. Techniques range from classic counterfeit sites imitating famous brands to insidious “Phish n’ Ships” campaigns, which exploit advanced SEO techniques to deceive consumers on marketplaces and have already compromised more than a thousand online stores since 2019.

New consumer habits are opening further gaps for digital crime. Social shopping and Buy Now Pay Later services have now become established frontiers for scammers as well. 25.1% of Italians use social media to discover new brands, with TikTok in a dominant position: users spend an average of 32 hours and 12 minutes per month on the platform. The arrival of TikTok Shop has multiplied the risks of cyberattacks, as reported by the Postal Police.

Every Click Tells Something about Us and Can Become a Gateway for Criminals.

Companies face a vulnerability often underestimated: the improper use of corporate devices by employees. A Netskope report highlights that in 88% of companies, at least one monthly malware download from cloud applications like Google Drive and GitHub occurred during 2024.

Maurizio Zacchi, VP of the Academy of Cyber Guru, a leading Italian platform in training against cyberattacks, emphasizes how cybercriminals exploit human emotions during Black Friday: urgency, fear of missing out, and the desire to save become powerful levers to strike more effectively.

Protection involves precautions that should become automatic. Verifying that a site has the HTTPS address with the security padlock is the first fundamental step: being wary of domains that imitate well-known brands with small spelling variations can save you from trouble. The use of prepaid or virtual cards limits damage in case of fraud, allowing you to set low limits and deactivate cards after each purchase.

Two-factor authentication is an effective barrier even when credentials are compromised, while keeping operating systems and applications updated is equivalent to closing doors that criminals know well. Excessively advantageous offers should always trigger an alarm: a next-generation console at a quarter of the price or a flagship smartphone discounted by 70% are typical signals of scams that rely on urgency to push for hasty decisions.

Public Wi-Fi networks are a danger often ignored. Entering banking data or credentials while connected to a café, hotel, or airport network is equivalent to opening the doors to scammers who intercept information on these unprotected connections. When avoiding them is not possible, the use of a VPN or mobile connection becomes essential. Regularly checking account statements allows you to promptly identify suspicious charges, which can be the first sign of ongoing data theft.

Digital awareness remains the most effective weapon. Phishing and social engineering techniques are constantly evolving, making it necessary to stay updated through reliable sources like CERT-AgID, the Postal Police, or organizations specializing in cybersecurity. Reading reviews from independent sources before purchasing on unknown sites and verifying the presence of real contacts and authentic reviews can make the difference between a deal and a scam. Protecting digital identity also involves taking care of the devices used, because often the first gateway for criminals is not the network itself, but the habit of feeling safe when one shouldn’t.

Originally published on Tom’s Hardware

Related Articles

News

We’re proud to share that Cyber Guru has ranked #73 in TIME magazine’s 2025 list of the World’s Top EdTech Companies, created in collaboration with global market research firm Statista.

AWARENESS TRAINING

  • Awareness

    Continuous training to build knowledge and awareness

  • Channel

    An engaging training experience in TV series format

  • Chatbot NEW

    Conversational mode for workplace training

COMPLIANCE TRAINING

PHISHING TRAINING

  • Phishing

    Personalized adaptive training

  • PhishPro

    The add-on for advanced training

REAL TIME AWARENESS

Cyber Advisor NEW

GenAI cybersecurity assistant Discover Guru, the AI assistant specialized in cybersecurity!

FEATURED RESOURCE

Ebook

Cyber Guru Academy Content Creators

Content that makes a difference Conceiving, designing, and producing training content that generates interest, engagement, and motivation to learn is a daily challenge for Cyber Guru's Academy department. Because it is now clear that training people to defend themselves against cybercrime requires more than just an attractive platform and a multitude of content.