Full Report
In this blog we uncover a long-running scheme by scammers selling wood to the people in France during the winter season, and how consumers and businesses can protect themselves from financial and reputation damages.
Analysis Summary
# Incident Report: Winter Wood Scams Targeting French Consumers
## Executive Summary
A long-running cyber-enabled scam targeting consumers in France utilized social media and fraudulent websites to sell non-existent firewood and wood pellets during the winter season. Attackers impersonated legitimate French businesses by stealing SIRET (business registration) numbers to gain trust, resulting in significant financial loss for victims and reputational damage to the impersonated companies. The operation is primarily attributed to independent actors based in Africa working with European-based money mules.
## Incident Details
- **Discovery Date:** Analysis published June 2024 (Long-running operation)
- **Incident Date:** Ongoing, peak activity during winter seasons
- **Affected Organization:** Multiple legitimate French businesses (Impersonated)
- **Sector:** Retail / Energy / E-commerce
- **Geography:** France (Victims), Africa and Europe (Threat Actors)
## Timeline of Events
### Initial Access
- **Date/Time:** Seasonal (Winter months)
- **Vector:** Social Engineering / Advertising
- **Details:** Attackers post highly attractive, low-cost advertisements for firewood and wood pellets on Facebook and other social media platforms to lure victims.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense. The "movement" involved pivoting from social media ads to fraudulent websites or direct communication via messaging apps to finalize the "sale."
### Data Exfiltration/Impact
- **Details:** Theft of consumer funds through direct bank transfers or fraudulent payment links. Impersonation of legitimate businesses using stolen KBIS (business registration) documents and SIRET numbers.
### Detection & Response
- **How it was discovered:** Group-IB Digital Risk Protection (DRP) monitoring identified spikes in fraudulent domains and social media impersonations.
- **Response actions taken:** Domain takedown efforts, social media profile reporting, and cross-referencing SIRET numbers with the official KBIS platform to confirm fraud.
## Attack Methodology
- **Initial Access:** Fraudulent social media advertisements (Facebook Marketplace/Groups).
- **Persistence:** Rapid creation of new social media profiles and domains when old ones are flagged/blocked.
- **Privilege Escalation:** N/A.
- **Defense Evasion:** Using legitimate-looking business credentials (SIRET) and providing fake "official" invoices to bypass victim suspicion.
- **Credential Access:** Theft of business identification data from public registries.
- **Discovery:** Identifying high-demand seasonal goods (wood) and researching legitimate local businesses to clone.
- **Lateral Movement:** N/A.
- **Collection:** Gathering victim PII (address, phone number) for delivery "coordination."
- **Exfiltration:** N/A.
- **Impact:** Financial fraud and brand impersonation.
## Impact Assessment
- **Financial:** High for individual victims; cumulative losses across France are substantial due to the high volume of scams.
- **Data Breach:** Exposure of victim contact information and misuse of corporate business identification data.
- **Operational:** Disruption for legitimate businesses who must handle complaints from defrauded individuals they did not serve.
- **Reputational:** Significant damage to impersonated businesses whose names are associated with fraudulent activity.
## Indicators of Compromise
- **Network Indicators:**
- Fraudulent domains mimicking wood suppliers (e.g., wood-supplies-france[.]com - *defanged*).
- Social media profiles with recently created histories and "too good to be true" pricing.
- **Behavioral Indicators:**
- Requests for direct payment via bank transfer to accounts unrelated to the business name.
- Mismatched SIRET numbers when checked against the official KBIS database.
- Lack of a physical pickup option despite claims of local stock.
## Response Actions
- **Containment:** Reporting fraudulent Facebook accounts and blocking malicious URLs.
- **Eradication:** Coordination with hosting providers to take down scam websites.
- **Recovery:** Assisting victims in identifying the fraud to report to local law enforcement (Gendarmerie/Police).
## Lessons Learned
- **Key Takeaways:** Scammers are increasingly leveraging legitimate business registry data to add a layer of perceived "officialdom" to their schemes.
- **Gaps:** Publicly available business data (SIRET/KBIS) is easily weaponized by threat actors to build trust with unsuspecting consumers.
## Recommendations
- **For Consumers:**
- Always verify business registration numbers at official government portals (e.g., KBIS in France).
- Avoid payments to individuals via social media for commercial goods.
- If a price is significantly lower than the market average, treat it as a high-risk indicator.
- **For Businesses:**
- Implement 24/7 Digital Risk Protection to monitor for unauthorized use of corporate identity and SIRET numbers.
- Proactively search social media for impersonation accounts.