Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Exploit Fake Avast Site for Credit Card Data

Cybercriminals Exploit Fake Avast Site for Credit Card Data

Posted on February 25, 2026 By CWS

Cybercriminals have developed a new phishing campaign, leveraging the trusted brand of the cybersecurity company, Avast, to steal sensitive financial information. This scheme involves a fake website that convincingly mimics Avast’s official portal to trick users into providing their credit card details.

Deceptive Tactics Used in Phishing

The fraudulent website is meticulously designed to resemble the legitimate Avast site, utilizing official logos and color schemes to establish credibility instantly. Victims are shown a fictitious transaction of €499.99, prompting urgent action due to a misleading cancellation deadline of 72 hours, while also stating transactions older than 48 hours are irreversible. This contradiction is often missed by users anxious about the financial loss.

The attackers enhance the site’s authenticity by embedding the real Avast logo from the company’s content delivery network. The fixed transaction amount appears realistic for a software subscription, urging users to act quickly.

Technical Aspects of the Scam

Malwarebytes researchers have discovered that the scam utilizes dynamic JavaScript to insert the current date into the fake transaction record, making the fraudulent charge seem recent. This technique is designed to maximize the shock value for unsuspecting visitors, whether they are actual Avast customers, former subscribers, or individuals concerned about potential identity theft.

The campaign’s broad target audience includes opportunists attempting to claim non-existent refunds, as no authentication is required to proceed to the data collection forms.

Data Collection and User Manipulation

The scam’s technical framework efficiently validates and exfiltrates user data while simulating a support interaction. Once victims provide their contact information, they are prompted to enter their full credit card details, which are verified using the Luhn algorithm to ensure validity before being sent via a POST request.

A live chat feature is also embedded, allowing attackers to interact with hesitant users and encourage them to complete the form. After the data is stolen, users are redirected to a confirmation page, further misleading them by suggesting the removal of security tools that could alert them to the fraud.

Protecting Against Phishing Threats

To safeguard against such threats, users should be aware that legitimate companies never request full credit card numbers for refunds. If a suspicious charge arises, visit the company’s official site directly rather than clicking links in unsolicited messages. Those who have provided their details should immediately contact their bank to cancel the compromised card and dispute charges.

It is also essential to update passwords for any associated accounts and use detection tools like Scam Guard for suspicious messages. Keeping operating systems and applications up-to-date and running comprehensive security scans can help prevent further risks.

Cyber Security News Tags:Avast, credit card theft, cyber attack, Cybersecurity, fake websites, fraud prevention, identity theft, online security, phishing scam, scam detection

Post navigation

Previous Post: UK Imposes $20M Fine on Reddit for Child Data Breaches
Next Post: Cortex XDR Vulnerability Enables Covert Command Channels

Related Posts

Kali Vagrant Rebuilt Released – Pre-configured DebOS VMs via Command Line Kali Vagrant Rebuilt Released – Pre-configured DebOS VMs via Command Line Cyber Security News
International Criminal Court Hit by New Sophisticated Cyber Attack International Criminal Court Hit by New Sophisticated Cyber Attack Cyber Security News
Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code Cyber Security News
Kimsuky and Lazarus Hacker Groups Unveil New Tools That Enable Backdoor and Remote Access Kimsuky and Lazarus Hacker Groups Unveil New Tools That Enable Backdoor and Remote Access Cyber Security News
Google Disrupted World’s Largest IPIDEA Residential Proxy Network Google Disrupted World’s Largest IPIDEA Residential Proxy Network Cyber Security News
CVE MCP Server Transforms Claude Into Security Analyst CVE MCP Server Transforms Claude Into Security Analyst Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm
  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm
  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark