Black Friday, Christmas, Sales: Cybercriminals Are Waiting for You
Every year, at the same time, the queues move to virtual carts. Promotions explode, ads flash, "must-have" deals multiply... and in the shadows, cybercriminals are rubbing their hands.

Every year, at the same time, the queues move to virtual carts. Promotions explode, ads flash, "must-have" deals multiply... and in the shadows, cybercriminals are rubbing their hands. Because while you are hunting for the best deal, they are hunting for the weakness.
Black Friday, like the end-of-year holidays, has become a peak season for phishing, fake sites, banking data theft and scams. We buy more. We buy fast. We let our guard down. And the risk becomes real.
In my book Être en cybersécurité, I devote a whole chapter to the risks tied to online payments. Here, for the occasion, is a practical summary to (re)read before you confirm your next purchase.
Why are the holidays the peak season for cyber scams?
The figures give the measure of the phenomenon. In 2025, Cybermalveillance.gouv.fr assisted more than 500,000 victims, 20% more than in 2024, and phishing ranked first among threats, across every audience, up 70% in a year. Commercial scams, for their part, rose by 170%, driven in particular by the fraudulent sites that proliferated. On the enforcement side, the DGCCRF had already blocked close to 80 fraudulent websites since January 2025, at a faster pace than the year before.
This is no accident of the calendar. The first trap is urgency, the feeling that you are going to miss a "70% off" deal if you do not pay right now. That is exactly what scammers exploit: the emotion, the adrenaline of the purchase, the speed of the decision. The golden rule fits in one sentence, never trade security for convenience.
Passwords and two-factor authentication: the bare minimum
Let's start with the obvious that many still neglect. Change your passwords to something more effective than "raspberry56", and turn on two-factor authentication everywhere you can.
These are your first lines of defense. Too many users keep on using reused or easy-to-guess passwords. That is no longer acceptable. A strong, unique password, stored in a secure manager, should be the norm.
How do you recognize a fake online store?
Before you pull out your card, check the merchant. Always.
- Read the reviews (Trustpilot, Google, forums).
- Type the site's name followed by "scam" into a search engine.
- Check the "legal notices" or "contact" page (physical address, company registration number) and do not hesitate to run searches on those same addresses and registration numbers.
Even when the site looks professional, fake sites have become impossible to spot with the naked eye. All it takes is a strange subdomain, a ".co" instead of a ".com", a sponsored but fraudulent Google ad, or a copy of a perfectly legitimate website.

One of the most widespread techniques today is the cloning of popular sites, backed by advertising. You search for "Nike deals" on Google, and the first link may be a fake site, sponsored and perfectly ranked. Always look at the exact address in the navigation bar: a single character too many or too few can be a trap. The breaches the DGCCRF finds on these sites are always the same ones, fake discounts, products supposedly in stock, false seller identity.
How do you pay online without exposing your bank card?
Saving your card on a site is convenient. It is also dangerous. Even the big platforms can be hacked, and if your details are stored there, they can be exfiltrated. Refuse the automatic saving of your card and take the time to enter it for each purchase. It is slower, it is safer.
Better still, separate your online purchases from your main account.
- Open a secondary account with no permanent balance.
- Transfer only the amount you need into it.
- Link a separate payment card to it.
Better yet, use a virtual bank card. Single-use or time-limited, with a spending cap, it becomes useless if it is stolen. Almost every bank offers them today: turn on the option.
Finally, never send your banking details by email, or on Instagram, WhatsApp or Messenger. Some merchants, or people posing as them, ask for exactly that. Refuse categorically: no serious site works this way.
Should you be wary of delivery texts and emails?
This is the flagship scam of the holiday season, arriving at the precise moment when you really are expecting a parcel. The script is well rehearsed: a text message or an email, apparently sent by La Poste, Colissimo, Chronopost, Mondial Relay, DPD or UPS, announces a blocked parcel and asks for a few euros in "delivery" or "customs" fees. The link leads to a fake carrier site that siphons off your credentials and your banking data.
That data does not sit idle. Cybermalveillance.gouv.fr reports that it often feeds, within hours or days, a second attack: the fake bank adviser who calls you posing as your bank, to empty the account. The messages are all the more credible because they sometimes use your name, taken from a data breach, another phenomenon that is exploding, since assistance requests for personal data breaches jumped by 107% in 2025.
The countermeasure is simple, never click the link in a delivery text message. Go directly to the carrier's official site, with the tracking number you received when you ordered, and forward the suspicious message to 33700 in France.
Has AI made phishing undetectable?
For a long time, the spelling mistake gave the scam away. That time is over. Generative AI now writes phishing emails that are more convincing than ever, perfect spelling, natural style, professional appearance.
The scam no longer sounds like a crook from a made-for-TV movie.
It sounds like a sales rep from Amazon.
Combined with the data breaches that feed personalization, this industrialization kills off the old reflex of "I can spot a scam by its typos". Spelling is no longer what you should be watching, context is: a demand for urgent action, a link to a domain you did not choose, an unexpected request for payment.
Giving a gift also means protecting
If you are giving a gift card, a subscription or a tech product, do not forget to warn your loved ones. Pass these tips on to them.
Christmas should not be a gateway to fraud.

Going further: Être en cybersécurité
All these tips, and many more, come from my book Être en cybersécurité, a handbook designed to give you back control in a digital world that moves too fast.
👉 Available online and from partner bookshops.
Shop smart, not vulnerable
Cyberspace is not a risk-free supermarket.
It is a minefield. With every click, you expose your data, your money, your identity.
So this week, while everyone is hunting for the best deal, look instead for the right posture.
And remember, a promotion is never worth the loss of your security.
Sources
- Phishing ranked the number one threat in 2025 (up 70%), more than 500,000 victims assisted (up 20%) and commercial scams (up 170%): Cybermalveillance.gouv.fr, 2025 activity report and state of the threat.
- Close to 80 fraudulent websites blocked since January 2025, at a faster pace than in 2024: economie.gouv.fr, DGCCRF press release, 8 September 2025.
- Parcel delivery phishing, impersonated carriers, follow-up fake bank adviser scam and reporting to 33700: Cybermalveillance.gouv.fr.
- Seven tips to avoid cyber scams: Cybermalveillance.gouv.fr.
- Black Friday, advice to guard against online scams: Service-Public.gouv.fr.
- The reflexes to secure your online purchases: CNIL.
Frequently asked questions
Why are Black Friday and the holidays riskier from a cybersecurity standpoint?
We buy more, faster, and we let our guard down. This period becomes a peak season for phishing, fake sites and banking data theft. In 2025, phishing ranked as the number one threat in France according to Cybermalveillance.gouv.fr, up 70% in a year.
How can I check that an online store is trustworthy before buying?
Read the reviews (Trustpilot, Google, forums), type the site's name followed by "scam" into a search engine, and check the legal notices (address, company registration number). Always verify the exact address in the navigation bar: a ".co" instead of a ".com" or one extra character can be a trap.
How can I pay online more safely during the sales?
Never save your card on the platforms, enter it for each purchase, and favor a virtual bank card (single use, spending cap, limited duration) or a dedicated secondary account funded with only the amount you need.
How do I recognize a fake parcel delivery text or email?
A message announcing a blocked parcel and asking for a small delivery or customs fee is almost always a scam. Fraudsters impersonate Colissimo, Chronopost, Mondial Relay, La Poste, DPD or UPS to push you toward a fake site. Do not click: go to the carrier's official site and forward the text message to 33700 in France.
Are email scams harder to spot today?
Yes. Generative AI writes phishing emails with perfect spelling and a natural style. The scam no longer sounds like a crook: it reads like a professional message from a major brand. Spelling is no longer the signal to watch, context is.
How do I report a scam spotted during Black Friday?
In France, forward fraudulent text messages to 33700. Report a fake site or a misleading practice on SignalConso (DGCCRF) and on Cybermalveillance.gouv.fr. If you have lost money, you can file a complaint online through the THESEE platform.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
