A network of more than 120 fraudulent websites impersonating Walmart is actively stealing credit card information from online shoppers. The scam sites feature convincing Walmart branding and offer name-brand liquor at steep discounts of 40% to 70% off, luring victims to checkout pages that capture full payment card details including card numbers, expiration dates, and CVV codes. Security researchers at Malwarebytes discovered the operation, which exploits the trust consumers place in the Walmart brand.
The fraudulent sites follow a consistent pattern across all domains. Each site uses the same WordPress and WooCommerce template, displaying identical product catalogs, pricing, and images. The only variations between sites are fabricated US business addresses and phone numbers. All domains use the .shop top-level domain rather than legitimate Walmart URLs, though this detail may go unnoticed by mobile shoppers who are the primary targets of the campaign.
The scam relies on psychological manipulation through extreme discounts that encourage impulsive purchases. Premium liquor brands advertised at 60% to 70% off create urgency that bypasses normal caution. The familiar Walmart logo, color scheme, and layout further reduce suspicion, causing shoppers to trust the site without verifying its legitimacy. This borrowed credibility makes the scam particularly effective against consumers who would normally hesitate on unfamiliar websites.
Victims who have entered payment information on these sites should assume their cards are compromised. The stolen data can be used for unauthorized purchases or sold to other criminals. Small test transactions often appear first as fraudsters verify the card works before making larger purchases. The scale of the operation, with over 120 active domains, suggests a coordinated effort designed to maximize reach before detection and takedown.
Security experts recommend several protective measures. Shoppers should verify they are on legitimate retailer domains before entering payment details, particularly when deals seem unusually generous. Browser extensions like Malwarebytes Browser Guard can automatically block known phishing sites. Anyone who has already provided card information should contact their card issuer immediately to request cancellation and replacement, monitor accounts for suspicious activity, and report the fraudulent domain to the FTC at reportfraud.ftc.gov. The complete list of 120 malicious domains has been published as indicators of compromise for security teams to block.
Source: https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card


