Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Holiday scam email season is here. Don’t fall for it.

Sorry, no one is actually going to give you a free Yeti cooler.

An illustration of a person stealing a giant credit card.
An illustration of a person stealing a giant credit card.
This year’s holiday season, scammers are trying to trick us into giving up our credit card numbers by dangling free Yeti coolers in front of us.
Denis Novikov/Getty Images
Sara Morrison
Sara Morrison was a senior Vox reporter who covered data privacy, antitrust, and Big Tech’s power over us all for the site since 2019.

Someone claiming to be Kohl’s really wants to give me a beautiful orange Le Creuset dutch oven.

The email always says this is the chain department store’s second attempt to reach me, although I reckon it’s more like the 50th because I’ve gotten this email many, many times over the last few months. You probably have, too. Maybe it’s not from Kohl’s. Maybe it’s from Dick’s Sporting Goods or Costco. Whoever it claims to be from, the result is the same: You click on a link, fill out some kind of survey, and are asked to enter your credit card info to cover the cost of shipping your free Yeti cooler, Samsung Smart TV, or that Le Creuset dutch oven.

An example of a phishing email claiming to be from Kohl’s. It features a set of Le Creuset cookware and says, “Answer & win a brand new Le Creuset. Get started now. Congratulations!”
Spoiler alert: There is no “fantastic prize” waiting for you on the other side of this scam email.

Those items will never come, of course. These emails are all phishing scams, or emails that pretend to be from a person or brand you know and trust in order to get information from you. In this case, it’s your credit card number. This latest campaign is particularly good at evading spam filters. That’s why you may have noticed so many of these emails in your inbox over the last several months. The fact that they got to your inbox in the first place as well as the realistic presentation of the emails and the websites they link to make them more convincing than the typical scam email. These attacks also usually ramp up during the holiday season. So here’s what you should watch out for.

“Grinch is getting security companies coal and blocked IPs for Christmas, and it’s resulting in more spam with domain hop architecture getting into your inboxes,” Zach Edwards, a security researcher, told Recode. Domain hop architecture is the series of redirects that route user traffic across multiple domains to help scammers hide their tracks and detect and block potential security measures.

Akamai Security Research identified the scam campaign in a recent report. The basic idea behind the scam itself — pretending to be a well-known brand and offering a prize in return for some personal information — isn’t new. Akamai has been following these kinds of grifts for a while. But this year’s version is new and improved.

“This is a reflection of the adversary’s understanding of how security products work and how to use them for their own advantage,” Or Katz, Akamai’s principal lead security researcher, said.

An example of a scam email pretending to be from Costco. It features a woman in a yoga pose in front of a large-screen TV and it reads, “Pure cinematic 8K viewing. Get it now. Costco wholesale Samsung OLED 8K UHD HDR Smart TV. Congratulations! You have been chosen to participate in our loyalty program for free! Answer survey.”
Sorry, but you’ll have to buy a Samsung TV from Costco just like everyone else. This survey is just trying to steal your credit card information.

Basically, these scammers are deploying lots of technical tricks to evade scanners and get through spam filters behind the scenes. Those include (but aren’t limited to) routing traffic through a mix of legitimate services, like Amazon Web Services, which is the URL several of the scam emails I’ve received appear to link out to. And, Edwards said, bad actors can identify and block the IP addresses of known scam and spam detection tools, which also helps them bypass those tools.

Akamai said this year’s campaign also included a novel use of fragment identifiers. You’ll see those as a series of letters and numbers after a hash mark in a URL. They’re typically used to send readers to a specific section of a website, but scammers were using them to instead send victims to completely different websites entirely. And some scam detection services don’t or can’t scan fragment identifiers, which helps them evade detection, according to Katz. That said, Google told Recode that this particular method alone was not enough to bypass its spam filters.

“What we see in this recently released research is new and sophisticated techniques being used, indicating the evolution of the scam, reflecting on the adversary’s intention to make their attacks hard to be detected and classified as malicious,” Katz said. “And, as we can see, it is working!”

But you don’t see any of that. You just see the emails. At best, they’re annoying, and at worst, they could trick you into giving your credit card details to people who will presumably use that information to buy a lot of things on your tab. The fact that they’re in your inbox in the first place adds a veneer of legitimacy, and both those emails and the websites they send victims to look better and therefore might be more convincing than some typical phishing attempts. They also seem to change according to the season or time of year. Akamai’s examples, which it collected weeks ago, have a Halloween theme. More recent phishing emails send users to a website boasting of a “Black Friday Special.”

“The literal holiday banners are unique, so that’s a cool newish addition,” Edwards said.

An example of a scam website claiming to offer a prize from Dick’s Sporting Goods. It has a picture of a Yeti cooler and reads, “Dick’s Sporting Goods, November 21, 2022. Congratulations! You’ve been chosen to receive a brand new Yeti M20 Cooler! To claim, simply answer a few quick questions regarding your experience with us. Attention, this survey offer expires today, November 21, 2022. Start survey.”
Dick’s Sporting Goods isn’t giving away a Yeti Cooler, even if you fill out a survey.

And it’s all being deployed on an apparently massive scale, which is why most people reading this have probably gotten not just one of these emails, but an onslaught of them, extended over a period of months.

Or, as one of my co-workers said to me when she forwarded me an example of just one of the many scam emails she’s received in her Gmail inbox: “help.”

A spokesperson for Google told Recode that the company is aware of the “particularly aggressive” campaign and is taking measures to stop it.

“Our security teams have identified that spammers are using another platform’s infrastructure to make a path for these abusive messages,” they said. “However, even as spammers’ tactics evolve, Gmail is actively blocking the vast majority of this activity. We are in contact with the other platform provider to resolve these vulnerabilities and are working hard, as always, to stay ahead of the attacks.”

Google also recently put out a blog post warning users about common holiday season scams, and the fake giveaway was at the top of the list.

“Received an offer that looks too good to be true? Think twice before clicking any links,” Nelson Bradley, manager of Google Workspace Trust and Safety, wrote.

Google also noted that it blocks 15 billion spam emails every day, which it believes to be 99.9 percent of the spam, phishing, and malware emails its users are being sent. In the last two weeks, Bradley wrote, there’s been a 10 percent increase in malicious emails. To be fair, I think there are more fake Kohl’s giveaway emails sitting in my spam filter than in my inbox.

The spokesperson added that Gmail users can use its “report spam” tool, which helps Google better identify and prevent future spam attacks. Beyond that, the typical how to avoid getting phished tips still apply. Check the sender’s email address and the URL it’s linking out to. Don’t give out your personal information, especially not your account passwords or credit card numbers. Take a few seconds to think about why Kohl’s would just randomly decide to give you Le Creuset bakeware or Dick’s would give you a Yeti cooler worth hundreds of dollars just for answering a few basic survey questions. The answer is that they wouldn’t.

You could also just spend your Black Friday shopping for real items in real stores (or on their real websites) and giving your credit card details to real employees. Good luck out there; the Google spokesperson said the company expects that the scam campaign will “continue at a high rate throughout the holiday season.” So it’ll almost certainly continue even after Black Friday ends.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh