HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Web Pop‑up Scam Impersonates Apple & Amazon with $149.99 Unauthorized‑Charge Warning

Fraudsters are delivering full‑screen pop‑ups that masquerade as Apple or Amazon alerts, claiming a $149.99 pre‑authorization charge and urging victims to call a single phone number. The tactic is designed to harvest credentials or payment data, highlighting the need for robust security‑awareness controls in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 07, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Web Pop‑up Scam Impersonates Apple & Amazon with $149.99 Unauthorized‑Charge Warning

What Happened — Fraudsters are serving full‑screen pop‑ups that mimic Apple Support or Amazon notifications, claiming a “$149.99” pre‑authorization charge and urging the victim to call a single phone number. The same number appears in both variants and routes callers to live scammers who attempt to obtain account credentials or payment information.

Why It Matters for Compliance & Audit Readiness

  • This is a textbook example of a phishing/social‑engineering attack that SOC 2 CC6.1 (Security Awareness) is designed to mitigate and evidence.
  • Continuous‑compliance programs must document training, simulated phishing results, and incident‑response playbooks to show auditors that the organization can detect and deflect such lures.
  • Verisq’s Security Awareness capability provides ready‑to‑use phishing‑simulation content and audit‑grade evidence of employee readiness.

Who Is Affected – Retail/e‑commerce platforms, consumer‑technology brands, and any organization whose users browse the web without robust awareness controls.

Recommended Actions

  • Incorporate web‑pop‑up phishing scenarios into your security‑awareness curriculum and track completion as SOC 2 evidence.
  • Deploy browser‑level content‑security policies (CSP, X‑Frame‑Options) to block unauthorized full‑screen modals.
  • Verify any urgent charge alerts only through official channels (email, in‑app notifications, account dashboards) before taking action.

Technical Notes – The scam leverages malicious ad networks or compromised sites to inject the modal; no specific CVE is involved. The “Pre‑Authorization” terminology is borrowed to add credibility, and the phone number is a known scam line flagged by multiple complaint databases. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/scams/2026/08/amazon-and-apple-impersonated-in-149-99-unauthorized-charge-scam

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →