#FactCheck – Myntra Scam Alert: Stay Protected from Deceptive Online Offers

Research Wing
Research Wing
Innovation and Research
PUBLISHED ON
Apr 16, 2024
10

Executive Summary

A misleading  advertisement circulating in social media providing attractive offers like iPhone15, AirPods and Smartwatches from the Indian e-commerce platform ‘Myntra’. This “Myntra - Festival Gifts” scam aims to attract the unsuspecting users into a series of redirects and fake interactions to compromise their personal information and devices. It is important to stay vigilant to protect ourselves from misleading attractive offers. Through this report, the Research Wing of CyberPeace explains about a series of processes that happens when the link gets clicked. Through this knowledge, we aim to provide awareness and empower the users to guard themselves and not fall into deceptive offers that aim to scam them.   

False Claim

The widely shared WhatsApp message claims that Myntra  is offering a wide range of high-valued prizes including the latest iPhone 15, AirPods, various smartwatches among all as a Festival Gift promotion. The campaign invites the users to click on the link provided and take a short quiz to be eligible for the prize.

The Deceptive Scheme

  • The link in the social media post is tailored to work only on mobile devices, users are taken through a chain of redirects.
  • Users are greeted with the Myntra's "Big Fashion Festival" branding accompanied by Myntra’s logo once they reach the landing page, which gives an impression of authenticity.
  • Next, a simple quiz asks basic questions about the user's shopping experience with Myntra, their age, and gender.
  • On the bottom of the quiz, there is a comment section that shows the comments from users who are supposedly provided with the prizes to look real,  
  • After the completion of the quiz, users are presented with a Spin-to-Win mechanism, to win the prize. 
  • After winning, a congratulatory message is displayed which says that the user has won an iPhone 15.
  • The final step requires the user to share the campaign over WhatsApp in order to claim the prize.

 Analyzing the Fraudulent Campaign 

  • The use of Myntra's branding and the promise of exclusive, high-value prizes are designed to attract  users' interest.
  • The fake comments and social proof elements aim to create a false sense of legitimacy and widespread participation, making the offer seem more credible.
  • The series of redirects, quizzes, and Spin-to-Win mechanics are tactics to keep users engaged and increase the likelihood of them falling for the scam.
  • The final step of sharing the post on WhatsApp is a way for the scammers to further spread the campaign and compromise more victims. Through sharing the link over WhatsApp, users become unaware accomplices that are simply assisting the scammers to reach an even bigger audience and hence their popularity.
  • The primary objectives of such scams are to gather users' personal information and potentially gain access to their devices. By luring users with the promise of exclusive gifts and creating a false sense of legitimacy, the scammers aim to exploit user trust and compromise their data, leading to potential identity theft, financial fraud, or the installation of potentially unwanted softwares.
  • We have also cross-checked and as of now there is no well established and credible source or any official notification that has confirmed such an offer advertised by Myntra.
  • Domain Analysis: If we closely look at the viral message, it is clearly visible that the scammers mentioned myntra.com in the url. However, the actual url takes the user to a different domain as the campaign is hosted on a third party domain instead of the official Website of Myntra, this raised suspicion. This is the common way to deceive users into falling for a Phishing scam. Whois information reveals that the domain has been registered not long ago i.e on 8th April 2024, just a few days back. Cybercriminals used Cloudflare technology to mask the actual IP address of the fraudulent website.
  • Domain Name: MYTNRA.CYOU
  • Registry Domain ID: D445770144-CNIC
  • Registrar WHOIS Server: whois.hkdns.hk
  • Registrar URL: http://www.hkdns.hk
  • Updated Date: 2024-04-08T03:27:58.0Z
  • Creation Date: 2024-04-08T02:58:14.0Z
  • Registry Expiry Date: 2025-04-08T23:59:59.0Z
  • Registrar: West263 International Limited
  • Registrant State/Province: Delhi
  • Registrant Country: IN
  • Name Server: NORMAN.NS.CLOUDFLARE.COM
  • Name Server: PAM.NS.CLOUDFLARE.COM

CyberPeace Advisory and Best Practices

  • Do not open those messages received from social platforms in which you think that such messages are suspicious or unsolicited. In the beginning, your own discretion can become your best weapon.
  • Falling prey to such scams could compromise your entire system, potentially granting unauthorized access to your microphone, camera, text messages, contacts, pictures, videos, banking applications, and more. Keep your cyber world safe against any attacks.
  • Never, in any case, reveal such sensitive data as your login credentials and banking details to entities you haven't validated as reliable ones.
  • Before sharing any content or clicking on links within messages, always verify the legitimacy of the source. Protect not only yourself but also those in your digital circle.
  • For the sake of the truthfulness of offers and messages, find the official sources and companies directly. Verify the authenticity of alluring offers before taking any action.

Conclusion:

The “Myntra - Festival Gift” scam is a kind of manipulation in which the fraudsters exploit the trust of the users and take advantage of a popular e-commerce website. It is equally crucial to equip the users by imparting them knowledge on fraudulent behavior tactics like impersonating brands, creating fake social proof and application of different engagement strategies. We are required to remain alert and stand firm against cyber attacks. Be careful, make sure that information is verified and share awareness to help make a safe online environment for all users.

PUBLISHED ON
Apr 16, 2024
Category
#FactCheck
TAGS
#
#FactCheck

Related Blogs