A Huge Scam Targeting Kids With Roblox and Fortnite ‘Offers’ Has Been Hiding in Plain Sight
May 19, 2024
auto_awesome
Exploring the deceptive tactics used in Roblox and Fortnite to lure children into fraudulent schemes. Delving into website hijackings pushing scams at young players. Highlighting online fraud targeting kids and efforts to mitigate the issue. Unveiling a scam targeting kids through Fortnite and Roblox.
Scammers exploit vulnerabilities in websites to deceive kids into downloading malware through fake game offers.
CPA Build's scam networks target children through fraudulent game promotions, posing cybersecurity challenges for affected entities.
Deep dives
Scams Targeting Kids with Roblox and Fortnite Offers
A widespread scam involving offers in popular games like Roblox and Fortnite has been uncovered. Security researcher Zach Edwards has been tracking compromised websites belonging to US government agencies, universities, and professional organizations, which push scammy offers intending to deceive children into downloading apps, malware, or submitting personal data. The scams are linked to an advertising company where affiliate users promote fraudulent offers. By exploiting vulnerabilities in website backends, attackers upload 'poison PDFs' that lure individuals with promises of free in-game rewards, ultimately leading them to fake landing pages requesting personal information.
CPA Build's Involvement in Scam Networks
The fraudulent activities are connected to CPA Build, an advertising company, which hosts tasks for users to engage in various offers to earn money. Affiliates, under CPA Build, utilize spamming tactics to drive traffic to scam landing pages generated from 'poison PDFs'. Despite claims of internal fraud checks and compliance policies, CPA Build's involvement in scam networks remains evident through compromised websites and affiliations with scam activities targeting children in online games like Roblox and Fortnite.
Response and Investigations into Compromised Websites
Efforts have been made to address compromised websites affected by the scams. Various entities, including the New York State Department of Financial Services and the US Cybersecurity Infrastructure Agency, have taken steps to remove malicious content and secure impacted sites. While tracing the schemes prove complex due to masking tactics, the significant impact on compromised domains, cybersecurity alerts from global agencies, and continuous tracking of fraudulent activities underline the persistent challenges posed by CPA Build-affiliated scams.
We wanted to bring you one of our favorite stories from 2023: The wide-ranging scams, often disguised as game promotions, can all be linked back to one network.