Email fraud could be the biggest online security fraud this Black Friday - here's how to stay safe

cropped close-up of five people sitting on a bench with shopping bags - only shows their legs
(Image credit: Shutterstock)

Cybersecurity firm Proofpoint has warned that American shoppers are at high risk of being victims of email fraud as Black Friday reaches its height, and has laid the blame with the retailers.

In fact, its study found that more than half of the top 50 online retails across the US are not taking appropriate measures to protect their consumers from email fraud and cybercrime.

With email authentication and verification measures hitting headlines recently, the study found that a further 12% had not even implemented a DMARC record.

Retailers put consumers at risk, says report

Proofpoint cites an external study that suggests consumers will spend on average $875 on core holiday items, including gifts, decorations, and food. This year, holiday retail is expected to bring in around $960 billion.

Separately, TechRadar Pro has covered plenty of studies around cybercrime during Black Friday and Cyber Monday sales, with some studies indicating that attackers spend all year prepping for this season.

The already-hectic weekend is the perfect cover for threat actors to use pressure tactics to rush victims into parting with sensitive information.

Group VP and GM for Sender Security and Authentication at Proofpoint, Robert Holmes, said: “The influx of emails from brands offering great deals during the Black Friday and Cyber Monday shopping period makes it an opportune time for cyber criminals to capitalize on the spike in email traffic and target shoppers with creative and convincing lures and scams.”

In-house research found that one-third of Americans regard familiar branding as sufficient proof that an email is safe.

More than ever, the runup to Christmas is a time to pay close attention to cybersecurity best practices. Proofpoint highlights the need to be aware of imitation sites, dodgy links, and any collection of sensitive data, urging customers to verify before committing to a purchase.

More from TechRadar Pro

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Help! We're drowning in email spam, it's about to get worse and there's nothing we can do to stop it
A man falling into a mobile phone screen.
Safer Internet Day: how to avoid online scams and stay safe online
A person using a smartphone with an ecommerce website showing on a laptop.
Tech deals in 2025: navigating ‘ghost’ discounts and fake reviews
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update
Apple iPhone 16 Pro REVIEW
The iPhone 17 Air looks impressively slim in this new comparison image, but that just makes me more worried about the specs
Matt Murdock smiling in Daredevil: Born Again episode 5 and Kamala Khan looking stunned in The Marvels
Daredevil: Born Again episode 5 just revealed what Kamala Khan has been up to since The Marvels, and now I'm more excited for the next superhero team to appear in the MCU