Fake Listings on Trusted Platforms Used to Lure Victims into Tech Support Scams
What Happened – Researchers at Malwarebytes discovered a fraudulent listing on BuzzFeed that pretended to be official Malwarebytes support. The listing displayed a phone number previously used in tech‑support scams impersonating other security brands, and it was designed to convince callers to grant remote access to their devices. Similar fake listings appear across marketplaces, social‑media sites, and classified‑ad platforms, leveraging the host’s reputation to increase credibility.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a gap in employee security‑awareness controls (SOC 2 CC6.1) that must be documented and continuously monitored.
- Highlights the need for evidence‑based phishing‑simulation programs to prove readiness during a SOC 2 audit.
- Shows that third‑party platform misuse can become a compliance risk if not tracked as part of your incident‑response and vendor‑monitoring processes.
Who Is Affected – Online marketplaces, classified‑ad sites, social‑media platforms, advertising networks, and their end‑users (consumers and businesses).
Recommended Actions
- Incorporate “fake‑listing” detection into your security‑awareness curriculum and run regular simulated phishing exercises.
- Establish a monitoring process for brand‑misuse on third‑party platforms and document remediation steps.
- Update incident‑response playbooks to include social‑engineering scenarios that originate from marketplace listings.
Technical Notes – The attack vector is classic social engineering via phishing‑style fake listings; no software vulnerability or CVE is involved. Scammers rely on brand impersonation, trusted domain cues, and the assumption that platform‑hosted content has been vetted. Source: Malwarebytes Labs