Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cybercriminals Exploit Fake Avast Website to Steal Users Credit Card Information

Cybercriminals have initiated a sophisticated phishing campaign by creating a counterfeit Avast website aimed at extracting credit card details from unsuspecting users.

Cybercriminals have initiated a sophisticated phishing campaign by creating a counterfeit Avast website aimed at extracting credit card details from unsuspecting users.

The fraudulent site closely resembles Avast’s legitimate portal, incorporating the official Avast logo sourced from the company’s content delivery network. It features standard navigation links such as “Home,” “My Account,” and “Help,” styled to match the authentic site.

Central to the page is a prominent alert that falsely claims a charge of €499.99 for an Avast product. The page asserts a 72-hour cancellation window, despite also mentioning that transactions older than 48 hours cannot be reversed, creating a deliberate inconsistency to confuse users.

The fraudulent website specifically targets French-speaking individuals , exploiting Avast's reputable brand to deceive individuals into disclosing sensitive financial information such as card numbers, expiration dates, and CVVs.

The displayed date next to the false charge updates according to the visitor’s system time, making it appear as if the charge occurred “today.” The €499.99 amount remains constant, chosen to be significant yet plausible for a premium software subscription.

No actual payment takes place. The operation is designed to psychologically manipulate victims into believing their card was charged, compelling them to submit their information under the guise of obtaining a refund.

Beneath the counterfeit receipt, the webpage presents a “refund form” requesting comprehensive personal details. Users are prompted to provide their name, email, phone number, address, and city, ostensibly for identity verification purposes.

The fraudulent site closely resembles Avast’s legitimate portal, incorporating the official Avast logo sourced from the company’s content delivery network.
Daniel Brooks · Thehackingpost

Upon form completion, a pop-up appears requesting credit card information , including the number, expiry date, and CVV code, purportedly needed to “process the refund.”

For authenticity, the site validates card numbers using the Luhn algorithm, a legitimate banking verification method. The collected information is transmitted to a send.php script via a POST request, sending all entered details directly to the attackers’ server.

After submission, users receive a message stating, “Your application is being processed. Thank you for your inquiry.” A final misleading button labeled “Uninstalling Avast” further disguises the scam, encouraging users to remove legitimate security software.

To enhance deception, the fake site includes a Tawk.to live chat widget, enabling operators to monitor victims in real time and engage with them. This interaction is used to reassure hesitant users, guiding them through the fraudulent refund process.

The phishing scheme targets various victim profiles, including actual Avast customers seeking refunds, confused users with outdated subscriptions, non-customers alarmed by the fake charge, and opportunists attempting to secure an unearned refund. The site does not request account details or license keys, compromising all visitor types through the same form.

Advertisement

Users can protect themselves by identifying common warning signs:

Unexpected charges or refund offers referencing “today’s date.” Forms requesting full credit card details for a refund. Absence of login verification or license requests. Urgent cancellation periods or countdowns. Requests to remove security software.

Conducting a system scan with a reputable security product such as Avast, Malwarebytes, or Microsoft Defender is strongly advised .

If individuals have already shared card details, they should promptly contact their bank, cancel the card, and contest unauthorized charges.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories