The cybercriminal calendar: How fraudsters celebrate the holidays

The cybercriminal calendar: How fraudsters celebrate the holidays

Data from Zimperium’s analysis division, zLabs, shows clear spikes around holiday seasons – such as Halloween or Christmas, but also during widespread retailer events such as Black Friday or Cyber Monday. Krishna Vishnubhotla, VP of Product Strategy, Zimperium, explores how holiday-based phishing campaigns hide in the deluge of seasonal marketing materials and delivery notifications from retailers and their partners.

Cybercriminals celebrate the holidays too. Every peak shopping season, Black Friday, Cyber Monday, Christmas, the New Year sales, brings a surge in consumer spending, a flood of marketing messages and a perfect storm of distraction.

That noise isn’t a problem for fraudsters. It’s their greatest asset.

The same flood of promotional emails, deal alerts and shipping notifications that consumers expect during the holidays is exactly what fraudsters hide behind. When every brand is competing for your attention, a malicious message blends right in. And the data confirms it, phishing spikes predictably, every single holiday season.

Holiday phishing

Zimperium’s latest research, From Carts to Credentials: Inside the Holiday Surge of Mobile Threats, puts hard numbers behind what security teams have long suspected. The inbox remains a battleground, but the real story is happening on mobile.

The data is striking. Phishing sites impersonating major retail brands spike at four predictable moments every year the Fall Amazon Prime event, Black Friday, the Christmas season, and the New Year sales. Amazon is the most impersonated brand by a significant margin, but it doesn’t stop there. Rakuten, eBay and other high-traffic retailers are equally in the crosshairs. Fraudsters don’t just follow consumer behaviour – they mirror it, almost in real-time.

The mechanics are straightforward but devastatingly effective. Limited-time deals create urgency, and urgency kills judgment. A 2024 report found that 62% of consumers will act on a holiday deal the moment they see it, and 35% openly admit to accepting more risk in their purchasing decisions during the season. Fraudsters don’t need sophisticated technology to exploit that. They just need a convincing enough offer and the right moment.

The destination is just as dangerous as the bait. In 2025, 120,000 fake retail apps were identified globally. 65% of them deliberately mimicked real brands to harvest credentials. The phishing sites behind these campaigns are engineered to look legitimate: over three-quarters use HTTPS, the very signal consumers have been trained to trust. And they’re built to evade detection. A quarter of mobile phishing sites are live for less than 24 hours, appearing, stealing and disappearing before security teams even know they existed.

Phishing the whole retail delivery chain

Retailers are the headline target, but the attack surface runs much deeper.

The modern shopping experience involves a long chain of services and devices sitting between purchase and delivery. Payment processors, digital wallets, logistics companies, delivery services, most of which run on mobile devices. Zimperium’s data shows the same seasonal spikes hitting all of them, at exactly those four moments of the year. That’s not a coincidence. By impersonating every link in the transaction chain, fraudsters construct a complete illusion of legitimacy. The more touchpoints they own, the more convincing the deception.

Mishing

Mobile phishing or mishing has become the defining tactic of holiday fraud. Most people have learned to spot a suspicious email. Far fewer can reliably distinguish a fraudulent SMS or push notification from a real one. Fraudsters know this. Zimperium data shows the average user is 6 to ten times more likely to fall for mishing than traditional email phishing, and 82% of phishing sites now specifically target mobile devices. During the holidays it gets worse. Mishing sites double in November and December, then quadruple in January. The timing is deliberate. Delivery services and payment processors rely on SMS and push notifications as their primary customer touchpoints, giving fraudsters the perfect template to impersonate. The inbox is no longer the front line. Mobile is.

Where consumers’ whims and enterprise risks collide

Behind every holiday shopper is an employee. The mobile device being used to chase Black Friday deals is almost certainly the same one being used to access corporate email, proprietary data and enterprise systems. That convergence is exactly what makes mishing so dangerous at an organisational level. One employee clicking a fraudulent shipping notification doesn’t just put their personal credentials at risk. It puts the entire enterprise at risk. BYOD and COPE policies have blurred the line between personal and professional environments, and a successful mishing attempt can cross that line in seconds, exposing single sign-on credentials, installing mobile malware, and opening a direct pathway into enterprise networks.

Holiday fraud isn’t just a consumer problem. It never was. The seasonal playbook of cybercriminals, particularly those targeting mobile, deserves a permanent place in enterprise security strategy. The holidays come around every year. So do the fraudsters.

Browse our latest issue

Intelligent Retail.tech

View Magazine Archive