October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Watch Out for Fake Online Shopping Sites: What the FBI Warning Really Says

The FBI warning about fake online shopping sites was real—but it did not identify named domains. Here is how to verify an unfamiliar store, spot current scam tactics, choose safer payment methods, and act after a fraudulent purchase.
From TheFinanceBase Team15 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI warning behind the headline is real, but it is not a current blacklist of named shopping websites. The FBI’s Internet Crime Complaint Center (IC3) issued the underlying public service announcement on August 3, 2020, and Tom’s Guide published its related article on August 4, 2020. The FBI described patterns reported by victims; it did not identify a fixed group of domains that shoppers should avoid.

Those warning signs remain useful, but online-shopping scams have evolved. Before paying an unfamiliar seller, independently find the retailer’s official website, inspect the complete domain, verify the business and return policy, and use a payment method with meaningful dispute protections. If you already paid or entered personal information, act immediately rather than waiting for the seller to respond.

Did the FBI publish a list of fake shopping websites?

No. The August 3, 2020 IC3 public service announcement did not name specific fake online stores or publish a blacklist. It described a cluster of characteristics found in complaints from victims who had been directed to fraudulent shopping websites.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
HID Corporation 1346 ProxKey III Key Fob Proximity Access Card Keyfob, 1-1/4" Length x 1-1/2" Height x 15/64" Thick (25)
  • Lifetime warranty!
  • Small enough to fit on a key ring
  • Universal compatibility with HID proximity card readers
  • Provides an external number for easy identification and control Can be placed on a key ring for conv
  • Supports formats up to 85 bits, with over 137 billion codes

That distinction matters because scam stores are disposable. Operators can register new domains, copy a legitimate retailer’s product pages, collect payments, and disappear or move to another address. A list of domains from 2020 would not reliably identify the next site used in a scam—and would risk implying that every site not on the list is safe.

The original warning should therefore be read as a risk-pattern alert, not as a list of prohibited domain names.

What the 2020 FBI warning described

Victims told the FBI that they found fraudulent stores through social-media advertisements and search engines, including shopping-result pages. The sites promoted bargain-priced products such as gym equipment, small appliances, tools, and furniture. The consistently low prices persuaded shoppers to buy from sellers they did not know.

In some reported cases, customers ordered one type of product but received disposable face masks shipped from China instead. Some sellers offered partial refunds; others demanded that customers return the unwanted goods to China at their own expense. Victims reported that they were unable to obtain a full refund or the products they had ordered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The PSA listed these reported indicators:

  • Prices significantly below those offered by established retailers.
  • Domains registered within the previous six months.
  • Website text, product descriptions, images, or design copied from legitimate sites.
  • Several stores using the same unrelated address or telephone number.
  • Advertising through social media.
  • Use of .club or .top domains in the reported cases rather than .com.
  • Private domain-registration services that concealed registration details.
  • Free email accounts instead of an address associated with the company’s domain.
  • A polished, professional-looking website that could be created and taken down quickly.

These are clues, not verdicts. A legitimate new business may have a young domain, a small online presence, a free email address, private registration, or no physical storefront. Likewise, a fraudulent site can use a .com address and an attractive design. The strength of the warning comes from the combination and context, not from any single technical detail.

Why this scam is still relevant

The specific 2020 incident is old, but the underlying fraud has not disappeared. The FBI’s shopping-scam guidance continues to warn about nonexistent merchandise, counterfeit goods, misleading sellers, and websites designed to take payment without delivering what was promised.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The scale figures need careful interpretation. The FBI’s 2025 IC3 report recorded 56,478 complaints in the non-payment/non-delivery category, involving $503,373,587 in reported losses. That category is broader than fake online stores: it includes buyers who paid and did not receive goods or received inferior goods, as well as sellers who shipped goods but were not paid. The figures are submitted complaints and reported losses—not a complete count of all fraud—and the FBI says complaints can change as they are analyzed and may include duplicate complaints.

Social-media shopping is a particularly important current route. The FTC reported in April 2026 that shopping scams were the most reported type of social-media scam in 2025. More than 40% of people who reported losing money to a social-media scam said they had ordered something they saw in a social-media advertisement. The FTC also reported $2.1 billion in losses from scams that started on social media in 2025. That is a broad social-media-scam figure, not a total for fake shopping websites alone. See the FTC’s methodology and findings before drawing narrower conclusions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How fake shopping sites reach consumers now

A scam store may begin with a convincing offer rather than an obviously suspicious website. Common routes include:

  • Promoted posts and advertisements on social-media platforms.
  • Sponsored search results, including ads placed above the legitimate retailer.
  • Search-engine-optimization tactics designed to make a fake store appear in ordinary results.
  • Email or text messages containing links to a sale.
  • Influencer-style posts or celebrity and brand impersonation.
  • Links shared by a compromised social-media account.
  • Redirects from advertisements, compromised legitimate websites, promotions, or downloads.

In a 2025 alert, the FBI warned that criminals use fraudulent search advertisements, minor misspellings, and lookalike URLs to imitate legitimate organizations and send users to phishing pages. A June 2026 IC3 warning described malicious traffic-distribution systems that can redirect people after they click an ad, visit a compromised site, sign up for a promotion, or download an application. The destination might be a fake login page, a financial-fraud page, or a malware download.

In other words, the ad platform or search engine is not proof that the destination has been vetted. A sponsored result can still lead to an impersonation site.

What a fake shopping site may be trying to do

The classic version takes payment and never ships. But a modern fake store can have several objectives:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Non-delivery: The store accepts payment and sends nothing.
  • Wrong or counterfeit merchandise: The buyer receives a worthless, fake, or materially different item.
  • Payment-data theft: The checkout page captures a card number, bank information, billing address, or security code.
  • Recurring charges: Fine print or a deceptive checkout enrolls the buyer in a subscription or continuing charge.
  • Identity-data harvesting: The site collects a telephone number, address, date of birth, Social Security number, or other information it does not need to complete a normal purchase.
  • Credential theft: A fake account-login page captures a password that the victim may have reused elsewhere.
  • Phishing or malware: A redirect leads to a fake warning, login page, application download, or other malicious content.

How to check a shopping site before paying

Use this sequence before entering payment details. It is more reliable than trying to identify one suspicious domain ending.

Rank #3
ETEKJOY 100 PCS 125KHz RFID Key Fob Proximity ID Card Token Tag Keypad Card for Door Entry Access Control System for Security Lock Wholesale, Read Only (Blue)
  • Note: These are 125kHz key fobs (tags). If you want to add them to your lock system, please ensure that your system uses the same frequency of unencrypted 125kHz. Not compatible with other frequencies like 13.56MHz. For example, they don't work for Tuya or TTLock smart locks. Not work for encrypted systems.
  • Compatible with other universal 125kHz tags like EM4100/4102. Not compatible with encrypted tags like HID, Indala, Cobra, APCiK, Paradox, Kaba, Isonas, etc.
  • Read only. Not rewritable. You cannot re-program them. Each key fob is already pre-programmed with a unique ID number. The 10-digit number is engraved on the tag casing.
  • Suitable for 125kHz RFID proximity access control system and ID management system. For example, add it to your RFID door lock if applicable.
  • Approx. Size: 1.4*1.1*0.2 inch. Casing Material: ABS Plastic. Package includes 100 PCS.
  1. Start somewhere other than the ad. Type a known retailer address directly, use a saved bookmark, or follow a link from the brand’s verified official account. Do not assume that the first sponsored result is the real company. The FBI specifically recommends typing important URLs directly and checking the destination before clicking advertisements.
  2. Read the complete domain. Look for misspellings, swapped letters, extra words, hyphens, unexpected subdomains, and a domain that is unrelated to the brand being claimed. The familiar brand name may appear only in a subdomain or in the path while the actual registrable domain belongs to someone else.
  3. Compare the exact price. A modest promotion may be legitimate. A product normally sold for hundreds of dollars that is offered far below every established retailer—especially with a countdown timer or pressure to buy immediately—deserves a separate explanation. If there is no credible reason for the discount, leave.
  4. Verify the business identity. Check the physical address, telephone number, company email, return address, shipping origin, and refund terms. Search the address and phone number independently rather than relying on information displayed only on the store.
  5. Search beyond the store’s own reviews. Search the seller’s name with terms such as scam, complaint, review, or fraud. Compare multiple independent sources. A star rating on the seller’s own site proves little, and a sudden collection of generic reviews can be manufactured.
  6. Check domain-registration data. Use ICANN Lookup and review available registration information such as creation date, expiration date, registrar, and nameservers. ICANN’s current system primarily uses RDAP; WHOIS may be used as a fallback depending on the domain and service. A recently created domain is a warning signal, not proof of fraud. Registration data may be redacted or incomplete, and privacy services are also used by legitimate businesses.
  7. Read the shipping and return fine print. Be cautious when the seller does not say where products ship from, gives no realistic delivery window, offers vague refund terms, requires expensive overseas returns, or includes unexpected recurring-billing language. If no shipping time is promised, the FTC says a seller generally must ship within 30 days or provide the buyer with a cancellation option and a full refund.
  8. Inspect the payment path. Prefer a credit card for ordinary online purchases. Walk away if the seller insists on gift cards, cryptocurrency, a wire transfer, or payment through an app outside the marketplace’s normal system. Payment apps are not automatically scams, but an insistence on a difficult-to-reverse method is a major warning sign.
  9. Stop when the page changes unexpectedly. A redirect to a different domain, a fake browser-warning page, an unexpected login request, or a prompt to install software is a reason to close the tab. Do not call a phone number shown in a suspicious pop-up.

The strongest reasons to walk away

One clue alone may have an innocent explanation. Treat the site as unsafe when several of these appear together:

  • An unrealistic price and pressure to act immediately.
  • An unfamiliar seller reached through an unsolicited ad, message, or social post.
  • A new, misspelled, or brand-unrelated domain.
  • Copied product photos, descriptions, or policies.
  • No independently verifiable address or telephone number.
  • A vague return policy, an overseas return address, or no clear refund process.
  • Only a free email address and no credible company identity.
  • Payment demanded by gift card, cryptocurrency, wire transfer, or an insisted-upon payment app.
  • Checkout redirects to another domain or asks for unnecessary identity information.
  • Reviews appear only on the seller’s own website or seem to have been posted in a burst.

What HTTPS and the padlock do—and do not—tell you

HTTPS does not prove that a shopping site is legitimate. It means the connection between your browser and the site is encrypted. It can help protect information while it travels between you and the website, but scammers can obtain HTTPS certificates and operate encrypted fake stores.

The FTC’s online-shopping guidance makes the same distinction: encryption is not the same as business verification. A safe purchase also depends on whether the seller is real, whether its policies are plausible, and whether your payment method gives you a practical way to dispute the transaction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not treat any of these as conclusive proof of safety:

  • A padlock or https:// in the address bar.
  • A professional-looking design.
  • A social-media advertisement.
  • A high star rating shown only by the seller.
  • A tracking number.
  • A .com domain.

Be careful when buying through a marketplace

A major marketplace is not necessarily the seller. A listing may come from an independent third-party merchant, so check who is actually selling the item, who processes the payment, and what buyer-protection rules apply.

Keep the transaction inside the marketplace’s payment and messaging systems. The FTC’s marketplace guidance warns shoppers not to rely only on star ratings and not to pay outside the platform’s system. Moving the payment to a separate link, wire transfer, or direct payment app can eliminate the protections that made the marketplace useful.

Rank #4
10pcs RFID Key Fobs 125khz RFID Writable T5577 fob tag T5577 Proximity ID Card Token Key Tag Rewritable for Access Control Systems & Security Lock
  • Standard 125Khz ID RFID keyfob, support 125khz proximity ID cards token tag duplication. Frequency : 125kHz; Sensing Distance: 2.5 to 10 cm (1 to 4 inch); Data Storage Life: 10 Years
  • Note: These are blank key tags without pre-programmed card numbers. You cannot directly add them to RFID locks or use a card reader to read them. Before using, please write data(card numbers) into them by a 125kHz RFID card writer first.
  • Product Size: 40*30*4mm(1.57*1.18*0.16 inch). High-Quality Copper Coil inside. Casing Material: ABS Plastic. Waterproof and heat-resistant.
  • Chip: ATMEL T5577 (compatible with other universal 125kHz tags). Frequency: 125kHz; It's rewritable, and it can write in 125khz id format and H-ID WG 125khz format, can be customised to 26-bit Prox format. Compatible with T5567 T5577 EM4305.
  • Applications: Hotel key chain, Access control systems, time attendance system, ticketing, packing card. This T5577 proximity key card can copy duplicate em4100 TK4100 ID Card Keychains tags.

A tracking number also does not establish that the seller is genuine. A scammer can provide tracking for a package containing the wrong item, or a tracking number associated with an unrelated delivery. Save the original listing, promised product, shipping date, tracking information, and photographs of what actually arrived.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which payment method gives the best protection?

For ordinary U.S. online purchases, a credit card is generally the strongest choice because it usually offers a practical dispute process for non-delivery, unauthorized charges, and certain billing errors. The FTC advises against buying from sellers who insist on gift cards, wire transfers, payment apps, or cryptocurrency.

How you paid What to do if the transaction is fraudulent Important limitation
Credit card Call the issuer immediately, ask about replacing the card, and dispute the charge as non-delivery, fraud, or merchandise materially different from the listing. For qualifying credit-card billing errors, a written dispute generally must reach the issuer within 60 days of the first statement containing the error to receive the full protections of the Fair Credit Billing Act. Follow the issuer’s instructions.
Debit card Contact the bank immediately and ask whether the transaction can be reversed. Complete the bank’s written-dispute process. Debit-card protections and deadlines differ from credit-card protections. Do not assume the 60-day credit-card rule applies.
Payment app Report the transaction to the app provider and to the linked bank or card. Preserve the transaction details. Protections vary. Risk is higher when a seller pressures you to pay outside a marketplace or by a method that is difficult to reverse.
Wire transfer Contact the bank or wire company immediately and request a reversal or recall. Speed matters, and recovery may not be possible.
Gift card Contact the gift-card issuer, retain the card and receipt, and report the scam. Do not discard the card or purchase record.
Cryptocurrency Contact the exchange or service immediately. Preserve the wallet address and transaction hash. Crypto payments are typically irreversible. Anyone promising guaranteed recovery for an upfront fee may be running another scam.

The FTC’s scam-recovery guidance provides additional steps for the payment method involved.

If your order never arrives

  1. Preserve evidence immediately. Save screenshots of the product page, full URL, advertisement, checkout page, order confirmation, receipt, promised delivery date, tracking information, and every message from the seller. Photograph the package and contents if something arrives.
  2. Contact the seller once in writing. Ask for a shipment or refund, but do not let an unresponsive seller—or repeated promises to ship later—consume the deadline for disputing the payment.
  3. Contact the payment provider. Ask the credit-card issuer, bank, payment app, wire company, gift-card issuer, or marketplace about reversal or dispute options immediately.
  4. Describe the problem accurately. Depending on what happened, it may be non-delivery, an unauthorized charge, a counterfeit item, or merchandise materially different from what was advertised.
  5. Report the seller and the ad. Use the platform where you saw the listing or advertisement, and report the store to the FTC at ReportFraud.ftc.gov.
  6. File an IC3 complaint. Submit the facts at IC3.gov, even if the loss is small or recovery appears unlikely. IC3 says complaints help the FBI analyze trends and may be referred to law-enforcement partners, but it does not guarantee recovery or a personal response to every complaint.

If the transaction involved a dishonest business, you may also contact your state attorney general or local police department when appropriate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you entered information but did not complete the purchase

Not paying does not necessarily mean you are unaffected. Take the following steps based on what you entered:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Password: Change it immediately on the legitimate service associated with that password, and change it everywhere else you reused it. Turn on multifactor authentication, then check recovery email addresses, phone numbers, and active sessions.
  • Card number or bank credentials: Contact the card issuer or bank immediately. Ask whether the account or card should be replaced, and monitor for small test charges, unauthorized withdrawals, and recurring charges.
  • Social Security number or identity information: Use IdentityTheft.gov for the FTC’s identity-theft response steps.
  • Downloaded software or an extension: Do not open it again. Update security software, run a scan, remove detected threats, and change passwords from a device you believe is clean.
  • Address, phone number, or email: Be alert for follow-up phishing messages, fake delivery notices, and calls claiming to be from your bank, the retailer, the FBI, or a recovery service.

Do not get scammed a second time

Fraud victims are often targeted again because criminals know they have already experienced a loss. In a July 2026 warning, the FBI said criminals were impersonating IC3 and FBI personnel through fake websites, social-media profiles, and AI-generated videos. They promised to recover money for people who had already reported fraud.

Best Value
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Do not pay anyone who claims to be an FBI or IC3 agent and demands a fee to recover your money. Do not submit a complaint through a link sent by a stranger. Type www.ic3.gov directly into your browser. IC3 says it does not maintain a social-media presence and does not recover funds through Facebook, Telegram, messaging apps, or public forums.

A simple decision rule

There is no single technical test that proves a store is safe. Use a cumulative risk assessment:

Risk level What it looks like Decision
High Unrealistic price, unknown seller, ad-driven link, copied content, new or lookalike domain, unverifiable contact details, vague returns, or pressure to use an irreversible payment method. Do not buy. Leave the site and report the ad if appropriate.
Medium Unfamiliar domain ending, private registration, young business, limited reviews, free email, or no storefront—but no other major red flags. Verify independently. These clues alone do not prove fraud.
Lower Official brand link, independently verifiable business identity, clear shipping and returns, established independent reviews, credit-card checkout, and meaningful marketplace protection. Risk is lower, not zero. Keep records and use the platform’s normal payment process.

The bottom line

The headline refers to a genuine FBI/IC3 warning from August 2020, not a newly released list of named fake shopping sites. The FBI’s reported clues—dramatic discounts, copied content, young domains, reused contact details, social-media advertising, private registration, and free email—are still useful when they appear together. But none automatically proves that a site is fraudulent, and neither a padlock nor a .com address proves that it is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The safest approach is to bypass the ad, verify the retailer independently, inspect the complete domain and policies, and pay by credit card when possible. If you paid, entered credentials, or downloaded something suspicious, contact the relevant financial institution immediately, preserve evidence, report the fraud, and be skeptical of anyone who later promises to recover your money for a fee.

Frequently Asked Questions

Are all .club or .top shopping websites scams?

No. The FBI said those domain endings appeared among sites reported in its 2020 complaints, but both are legitimate top-level domains. A .club, .top, or unfamiliar domain should be considered in context with the price, seller identity, website content, payment method, and other warning signs.

Can I trust a shopping site because it has HTTPS or a padlock?

No. HTTPS encrypts the connection between your browser and the website, but scammers can use HTTPS too. Verify the business independently and use a payment method with buyer protections.

What if a fake seller gives me a tracking number?

A tracking number does not prove that the seller shipped the correct product. Save the original listing and promised delivery details, photograph the package and contents, and contact your payment provider if the item is missing, counterfeit, or materially different from what you ordered.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does reporting a fake store guarantee that I will get my money back?

No. Reporting to the FTC, IC3, the marketplace, and your payment provider can help document and investigate the fraud, but no agency guarantees recovery. Payment disputes should be started immediately, and you should not wait for an investigation before contacting your card issuer or bank.

The Bottom Line

Do not look for a permanent FBI blacklist. Look for a pattern of risk: an implausible bargain, an unfamiliar or lookalike domain, copied pages, unverifiable business details, weak return terms, and pressure to use an irreversible payment method. Verify the seller independently and use a credit card when possible. If something goes wrong, contact the payment provider immediately and report the fraud through official websites that you type into the browser yourself.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.