Breakout Session

Catphish: Infiltrating an International Refund Fraud Operation

In the summer of 2023, a refund fraud threat actor attempted to recruit a SHEIN customer service employee to facilitate large amounts of refund requests. SHEIN CTI assumed the identity of the targeted employee, and conducted a month-long operation to gather information from the threat actor. During this investigation, the innerworkings of an international refund fraud operation were uncovered, as well as active operations targeting additional retail organizations. This presentation will focus on how the investigation was planned, and conducted, what intelligence was gathered, and mitigation strategies to prevent groups likes these from conducting future operations against the company. 

" options="'Apple','Google','iCal','Outlook.com','Yahoo'" lightMode="bodyScheme">
April 10, 2024
3:15 pm - 4:00 pm
Capitol 1-2

In the summer of 2023, a refund fraud threat actor attempted to recruit a SHEIN customer service employee to facilitate large amounts of refund requests. SHEIN CTI assumed the identity of the targeted employee, and conducted a month-long operation to gather information from the threat actor. During this investigation, the innerworkings of an international refund fraud operation were uncovered, as well as active operations targeting additional retail organizations. This presentation will focus on how the investigation was planned, and conducted, what intelligence was gathered, and mitigation strategies to prevent groups likes these from conducting future operations against the company. 

Speakers

Steve Diamond

Senior Cyber Threat Intelligence Analyst, SHEIN

Jacob Napierskie

Global Intelligence Center Manager, SHEIN