Safe Online Shopping During the Holidays and Beyond

17 grudnia 2020

The holiday season and New Year is a special time when we want to gift our loved ones and spend carefree moments with them. Due to the pandemic, online shopping in e-commerce stores has become extremely popular. The holidays are also a "hot" time for hackers and internet thieves, who see it as the perfect opportunity to steal our confidential data, infect computer equipment, or extort money. How can we use e-shopping services without the fear of being robbed? The best defense against this threat is knowledge. Here are a few simple steps that we should all take to enhance security before and after shopping.

Before proceeding with online purchases, let us ensure that the operating system of our device is up to date. Systems without manufacturer support may contain various vulnerabilities that cybercriminals are eager to exploit in order to obtain our data.

Let us not forget about web browsers, which must have up-to-date security measures provided by the manufacturer. Hackers are constantly searching for new vulnerabilities in our software to find a loophole and access our data. We should protect our devices by updating the software.

Be Skeptical

When choosing online stores where we want to spend our money and, consequently, our personal data, let us consider their credibility. No one would shop at an unmarked store with boarded-up windows. The same applies online: if something does not look safe, it probably is not safe.

It is best to choose verified services that have good reviews from other users. Additionally, before placing an order, we must ensure that we are on the correct manufacturer's website. Some attackers may attempt to deceive us by creating malicious sites that appear credible and closely resemble well-known services.

Always verify their legality before providing any information.

  • While on the site, check whether the connection is encrypted, i.e., whether the website name starts with https://; providing personal data on sites starting with http:// always carries a risk.
  • The store should have a security certificate, indicated by a padlock preceding the website address. Certificates can also be forged, so let us be smarter than thieves - click on the padlock to check for whom the certificate is issued; if it is for our store, the site is safe.
  • When connecting to banks or online stores, always use your own, properly secured internet networks. 
  • Do not use links provided in emails. Cybercriminals often send phishing emails designed to look like they come from retailers, containing malicious links or requesting personal or financial information. Never provide such information in response to an email! Legitimate companies will not send emails asking for this information. If we want to visit a store's website, we should type the website address directly into the browser's address bar or use a search engine like Google.

Let us be strong

The passwords we use to log into online stores can leak onto the Internet at any time, and theoretically, anyone can gain access to them. However, many of these passwords are still protected by hashes. We recommend using complex passwords that are at least 8 characters long. The more complicated the password, the more difficult the hash.

Additionally, let us secure ourselves with two-factor authentication for shopping and banking services. This type of authorization requires more information for our verification (e.g., an SMS code) to log in. This gives us peace of mind: if someone learns our password, they still cannot access our account without the second authentication factor.

Let us pay

To pay for transactions, traditional cash-on-delivery payment is always the safest option. However, when shopping through Polish services, we often have the option to pay using Blik. This is a fast and secure payment method that involves entering a code from the banking app on our phone and confirming the payment on the phone. However, we advise always checking in the phone app what payment we are confirming, to whom, and for what amount.

If we decide to pay by credit card, at the time of payment authorization, we should check whether we are indeed making a payment to our store. Remember to periodically review our bank account history for unauthorized charges – if we identify any, we should immediately notify our bank and local law enforcement authorities. If we are defrauded during payment, the bank will initiate a chargeback procedure on our behalf.

There are no stupid questions about GDPR - there are free answers!

It involves the bank contacting the payment center on our behalf to report fraud, after which contact is established with the dishonest seller. In cases where the seller cannot demonstrate the validity and legality of the transaction, they are obliged to refund the buyer. The same procedure applies to cases of non-delivery of goods or receipt of the wrong product. Importantly, the regulations concerning so-called card complaints are governed solely by Visa and MasterCard; the normative acts of states do not interfere with these provisions.

We should only make payments via bank transfer on platforms that offer buyer protection. A small shop that only accepts bank transfers is suspicious. When logging into the bank, remember to check whether the domain actually belongs to the bank, and then whether we are indeed initiating a transfer, rather than, for example, authorizing a trusted recipient. If we do not use two-factor authentication for banking, and a criminal has our login details and is a so-called trusted recipient, they can make transfers from our account without needing to authorize them in any way.

After Purchase

If our purchases are devices that connect to the Internet, we should ensure that we change the default passwords set for them. Many Internet-connected devices are compromised due to the failure to change default passwords. Remember to make these passwords at least as strong as those we use to log into online stores.

Ensure that the equipment we purchase always has up-to-date software. To this end, we recommend enabling automatic updates.

Check the privacy and security settings of the device to ensure how our information will be used and stored. It is wise to be certain that we are not sharing more information than necessary.

Enjoy the Holidays, but Wisely

Do not let a moment of inattention or underestimating lurking threats ruin your Holidays. Exercise caution even in situations that seem safe and pose no risk. These few principles will certainly enhance the security of our holiday shopping, so that we do not have to worry about either our money or personal data.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.