HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Fake Walmart Lookalike Sites Harvest Credit Card Data via Phishing Campaign

Over 120 fraudulent domains mimicking Walmart are stealing shoppers' credit‑card details through discounted liquor offers. The campaign highlights gaps in SOC 2 access‑control and security‑awareness controls that organizations must evidence for audit readiness.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Fake Walmart Lookalike Sites Harvest Credit Card Data via Phishing Campaign

What Happened — More than 120 fraudulent domains mimicking Walmart’s storefront are luring shoppers into purchasing heavily discounted liquor. The sites collect full credit‑card details at checkout and funnel the data to attackers.

Why It Matters for Compliance & Audit Readiness

  • This is a classic phishing‑driven credential compromise that tests the effectiveness of SOC 2 CC6.1 (Logical Access) and CC7.1 (Security Awareness) controls.
  • Demonstrates the need for continuous evidence that employees and customers are educated on brand‑spoofing tactics and that anti‑phishing tools are deployed and logged.

Who Is Affected – Retail & e‑commerce merchants, payment processors, and any organization that accepts online card payments.

Recommended Actions – Review your SOC 2 access‑control policies, verify that security‑awareness training includes brand‑spoofing detection, and collect evidence of phishing‑filter deployments (e.g., Malwarebytes Browser Guard logs). Source: https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card

Technical Notes – The scam uses a cloned WordPress/WooCommerce template, identical product catalogs, and fabricated US addresses. Attack vector: phishing via look‑alike domains (e.g., .shop). No CVE is involved. Source: https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card*

📰 Original Source
https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →