Sunday, December 1, 2024

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » Freebie Bots: The Latest Threat to Retailers this Holiday Season and Beyond

SBN

Freebie Bots: The Latest Threat to Retailers this Holiday Season and Beyond

by Alexa Bleecker on December 1, 2022

Special Thanks to Kasada Research and Threat Intelligence Team for their contributions and insights

Introduction: What are Freebie Bots?

Steep discounts drove Cyber Monday online sales to hit a record of $11.3 billion this year. But some of those discounts were created by mistake. And you better believe people were taking advantage of the errors – with some scoring items that were nearly free, or in some cases, 100% off.

These glitches don’t just happen during the holiday season. Human errors occur all year long. And now automated scripts called Freebie Bots exploit these errors on retail websites. This enables tens of thousands of users to automatically purchase mispriced or misdescribed items every couple of seconds or less. Once the items are received, the users then resell these items for a massive profit.

Newsletter
AWS Hub
Predict 2025

Opportunistic people who use Freebie Bots can receive upwards of $100,000 per month in free (or almost free) goods – costing retailers millions of dollars on a monthly basis, according to our research.

Freebie Bots: Costing Retailers Millions

eCommerce companies and consumers alike are all too familiar with scalper bots, purchasing and reselling tickets, sneakers, and in-demand holiday items for a profit. Freebie Bots are a mix of scraper and scalper bots, leveraging similar communities and technology that have made them especially difficult to detect and easy to access, with their own twist. 

Freebie Bot Successful Checkout

Figure 1: Example of Discord message within a Freebie community, automating the discovery of a pricing error and checkout for a graphic card.

Unlike scalper bots, Freebie bots don’t just scoop up hot gifts and electronics like PS5s and graphics cards. They target any item that could be resold on secondary marketplaces including Amazon, eBay, and Facebook Marketplace for a profit. 

Freebie Bots may even be more detrimental for retailers than scalper bots, as they aren’t limited to only buying items where demand greatly exceeds supply. Any good could be priced or described incorrectly, either by misplacing a decimal or making an error when copy and pasting. It only takes seconds for a Freebie Bot to swoop in and purchase thousands of items – all before the human error is discovered and fixed. When traditional scalpers successfully purchase goods to resell, at least the retailers are selling their goods at full price. With Freebie Bots, retailers end up selling items at a loss when they fulfill mispriced orders.

“Retailers are already facing pressures this holiday season due to inflation and the annual recurrence of Grinch Bots. Adding Freebie Bots to the mix gives retailers another headache to deal with, one that directly hits their revenues, as they’re compelled to fulfill orders made with pricing errors.” – Sam Crowther, Founder, Kasada

3 Critical Problems With Freebie Bots for Retailers:

  1. Revenue loss: Retailers’ bottom lines take a direct hit when they fulfill the orders made by Freebie Bots, which they usually do to honor the mistake that was made. 
  2. Poor user experience: Legitimate customers have a negative online experience due to Freebie Bots – not only because products are out of stock, but because the websites have slow performance due to bot traffic. This in turn, results in brand and reputational damage.
  3. Added operational costs: Freebie Bots take a toll on retailers’ websites, resulting in high costs to process infrastructure on their sites to support the additional traffic. The infrastructure tax can actually cost more than having to honor the sale of the mispriced goods for many retailers.

In this blog, we’ll share data on the Freebie Bot activity we’ve observed leading up to Thanksgiving and Black Friday 2022 as well as throughout the Cyber Five holiday sales weekend, and what to expect in the coming months.

Freebie Bot Findings – Before Black Friday

Prior to Black Friday, Kasada saw Freebie Bots expand from targeting only the largest retailers to now hundreds of eCommerce organizations of all sizes, due to economies of scale. It costs very little to design and operate a bot that can scan various sites. The bot operators themselves can yield even bigger profits from selling Freebie Bots as a service to other people who want to try and acquire merchandise for free.

In October and November 2022, the Kasada Threat Intelligence Team observed Freebie Bots targeting over 250 retail companies with more than 7 million daily messages sent within the Freebie communities.

Freebie Bots Before Black Friday

Figure 2: Kasada research findings in just one month, before Black Friday week. 

Within the month leading up to Black Friday week, our team found that one Freebie Bot Community secured the following:

  • Total retail value of goods: Secured close to 100,000 products for a combined retail value of $3.4 million
  • Total cost of goods: Freebie Bots only spent $882 total
  • Top items purchased: Offbrand Sleeveless Halter Neck Mini Dress, 2020 MacBook Air Laptop, and Deep Cleansing Facial Mask

Freebie Bot Findings – During the Cyber Five Holiday Sales Weekend

Freebie Bots ramped up operations in a big way for Black Friday and Cyber Monday. Reseller arbitrage (the gap between the purchase price and the resale price) broadens as a result of holiday sales events, which increases the financial opportunity for bot operators. 

Kasada researchers observed Freebie Bot activity over the Cyber Five Holiday weekend, which represents Thanksgiving until Cyber Monday. As you can see in the graph below, Freebie Bot checkout activity steadily increased the week of Black Friday.

Freebie Bot Checkouts Black Friday

Figure 3: Freebie Bot completed checkouts steadily ramped up activity from Sunday, November 20, 2022 to Black Friday, November 25, 2022.

Here is the Freebie Bot example that we saw during the 2022 Black Friday and Cyber Monday weekend:

  • Total retail value of goods: Secured $500,000 worth of products using just one Freebie Bot that targeted one retailer
  • Total cost of goods: 610 people spent a total of $85.36 using Freebie Bots
  • Top items purchased: Dog Collars, LED Strips, and Dinosaur Toy Hand Puppets

Freebie Bots – After Cyber Monday and Beyond

Just because the Cyber Five holiday sales are over, it doesn’t mean that Freebie Bots are going away. In fact, they are prevalent year-round and don’t need to rely on hype releases or peak-selling events to profit. They just need people to make mistakes. And because we’re human, we all make mistakes, right? 

Freebie Bots will continue to exploit these errors for financial gain in 2023 – not only because there’s an opportunity to make money, but because they’re hard to detect and stop. 

Bots are watching and waiting for price glitches and inaccurate product descriptions. Freebie Bots are constantly searching for the highest discounts by percentage, mostly from 70 to 100% off.

Unfortunately, Freebie Bots are becoming increasingly more difficult for retailers and eCommerce providers to detect and stop because they are evolving. They inherit many of the same stealthy techniques used by Grinch Bots to evade detection. The automated nature of the way Freebie Bots operate makes it nearly impossible for online companies to keep up with the speed at which they conduct their attacks.

What You Can Do to Stop Freebie Bots

Freebie Bots are costing some retailers millions of dollars every month of the year. In addition to impacting your inventory, revenue, and brand, Freebie Bots also increase infrastructure expenses. Retailers, at great cost, need to maintain a strong site architecture in order to handle this demand without crashing or becoming unavailable to regular shoppers. Preventing Freebie Bots from gaining access in the first place would significantly lower these costs.

If you’re a retailer or eCommerce provider, you should look for an anti-bot solution that identifies automation at its source, adapts quickly to changes, and has an experienced team behind the scenes.

Ready to learn which threats are targeting your organization? Request a threat assessment today.

*** This is a Security Bloggers Network syndicated blog from Kasada authored by Alexa Bleecker. Read the original post at: https://www.kasada.io/freebie-bots-the-latest-threat-to-retailers/

December 1, 2022December 1, 2022 Alexa Bleecker account takeover, automated threats, black friday, Bot Defense, bot detection, bot management, bot mitigation, bot protection, Christmas shopping, cyber monday, eCommerce holiday sales, Ecommerce Security, freebie bots, holiday readiness, Industry Trends, retail threats, Web Apps
  • ← More than a Data Store. An Intelligent Approach to Flow Data Usage
  • Are you Having These 5 Disagreements about Kubernetes? You Should Be! →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Mobility Field Day

Upcoming Webinars

Hacker Tactic: Avoid Blind Spots with Your Windows Event Logs
Simplifying Network Access: Secure Modern Connectivity with Tailscale
Staying Ahead: Top Internet Trends Shaping Networking and Security
DevSecOps “Friends”, Webinar Series: The One with Platform Engineering (and the Happy Developers)
Managing Dependencies at Enterprise Scale

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

Interpol, African Nations Arrest 1,006 in Sweeping ‘Operation Serengeti’
Protecting Web-Based Work: Connecting People, Web Browsers and Security
Exabeam Allies With Wiz to Integrate CNAPP With SIEM Platform

Industry Spotlight

QNAP’s Buggy Security Fix Causes Chaos
Application Security Cybersecurity Data Privacy Data Security DevOps Endpoint Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight IoT & ICS Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

QNAP’s Buggy Security Fix Causes Chaos

November 26, 2024 Richi Jennings | Nov 26 0
U.S. Agencies Seize Four North Korean IT Worker Scam Websites
Cloud Security Cybersecurity Data Security DevOps Endpoint Featured Identity & Access Industry Spotlight Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence 

U.S. Agencies Seize Four North Korean IT Worker Scam Websites

November 22, 2024 Jeffrey Burt | Nov 22 0
Here’s Yet Another D-Link RCE That Won’t be Fixed
Application Security Cyberlaw Cybersecurity Data Privacy Data Security Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight IoT & ICS Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Here’s Yet Another D-Link RCE That Won’t be Fixed

November 21, 2024 Richi Jennings | Nov 21 0

Top Stories

Interpol, African Nations Arrest 1,006 in Sweeping ‘Operation Serengeti’
Cloud Security Cybersecurity Data Security Featured Identity & Access Incident Response Malware Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Interpol, African Nations Arrest 1,006 in Sweeping ‘Operation Serengeti’

November 27, 2024 Jeffrey Burt | 4 days ago 0
Exabeam Allies With Wiz to Integrate CNAPP With SIEM Platform
Application Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X 

Exabeam Allies With Wiz to Integrate CNAPP With SIEM Platform

November 27, 2024 Michael Vizard | 4 days ago 0
Supply Chain Ransomware Attack Hits Starbucks, UK Grocers
Cloud Security Cybersecurity Data Security Featured Identity & Access Incident Response Malware Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

Supply Chain Ransomware Attack Hits Starbucks, UK Grocers

November 26, 2024 Jeffrey Burt | Nov 26 0

Security Humor

Randall Munroe’s XKCD ‘D Combinatorics’

Randall Munroe’s XKCD ‘D Combinatorics’

Download Free eBook

7 Must-Read eBooks for Security Professionals

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2024 Techstrong Group Inc. All rights reserved.
×