Hello,

We noticed you're browsing in private or incognito mode.

To continue reading this article, please exit incognito mode or log in.

Not a subscriber? Subscribe now for unlimited access to online articles.

A View from

Fake Ad For Apparent Credit-Card Scam Was On Our Site

We were duped into serving a malicious ad.

  • July 26, 2013

Publisher’s note: From July 16 to 22, MIT Technology Review served a fake ad that led to a fake e-commerce site, one that most likely was trying to steal credit-card information. We didn’t mean to; we were duped. We have no way of knowing whether anyone gave the site a credit card number, but we served around 10,000 impressions of the ad. We’re very sorry. We’ve learned from the experience, and have made a number of common-sense changes to make sure we aren’t scammed again.

The scam began with a beguiling e-mail. Our advertising team received an e-mail on July 11 from someone calling himself Nick Sampson, saying (falsely) that he was with an online retailer called Gilt. “I can spend as much as $100,000 per month,” he wrote.

The request struck our team as odd, in that it came directly from the would-be advertiser (in the jargon of the media business, “the client,” and not an agency), and the person was ready to close a sizable deal instantly. Nonetheless, the ad went live on July 16. Soon, another oddity emerged: we weren’t getting click information back from the ad. We suspended it. But after getting an excuse from “Nick” via e-mail, we reinstated it.

On July 22, we got a message from a reader saying that the ad was associated with a Web address listed by Sophos, the security company, as a possible malware site. Only Sophos and BitDefender had flagged the site as potentially dangerous—apparently because it was newly created, one warning sign of malicious activity. Another 31 security vendors called it a “clean site.” And six more had not rated it. (See the details here.)

Why was the site on Sophos’s list? A Sophos rep says there was no evidence the site contained actual malware, but it raised flags in part because it had recently been created. We investigated and quickly understood that our ad was directing people to a fraudulent clone of the real Gilt site. “Nick” was likely part of a scam to steal credit-card numbers. 

The race is on to define the new blockchain era. Get a leg up at Business of Blockchain 2019.

Register now
Want more award-winning journalism? Subscribe to Print + All Access Digital.
  • Print + All Access Digital {! insider.prices.print_digital !}*

    {! insider.display.menuOptionsLabel !}

    The best of MIT Technology Review in print and online, plus unlimited access to our online archive, an ad-free web experience, discounts to MIT Technology Review events, and The Download delivered to your email in-box each weekday.

    See details+

    12-month subscription

    Unlimited access to all our daily online news and feature stories

    6 bi-monthly issues of print + digital magazine

    10% discount to MIT Technology Review events

    Access to entire PDF magazine archive dating back to 1899

    Ad-free website experience

    The Download: newsletter delivery each weekday to your inbox

    The MIT Technology Review App

/3
You've read of three free articles this month. for unlimited online access. You've read of three free articles this month. for unlimited online access. This is your last free article this month. for unlimited online access. You've read all your free articles this month. for unlimited online access. You've read of three free articles this month. for more, or for unlimited online access. for two more free articles, or for unlimited online access.