Did Google Let a Sephora Scam Rank First? Fact-Checking the Viral Gift Card Theft
Lucas's public account of the theft struck a nerve because her steps matched typical online behavior. She received the $250 card as a graduation gift and wanted to confirm its funds before purchasing skincare products online. She searched for the balance checker on her mobile browser and immediately selected the top result, assuming the first link guaranteed safety.
The malicious page copied Sephora's clean typography, official corporate logos, and color palette with near-flawless accuracy. Lucas input her 16-digit card number alongside the scratch-off PIN located under the metallic film on the back of the physical plastic. The moment she submitted the form, the webpage displayed a fake progress spinner followed by an error message stating that the balance service was temporarily down for scheduled maintenance.
Behind the scenes, a headless browser controlled by the threat actor ingested the plaintext credentials, authenticated with the official Sephora balance checker, verified the active $250 fund, and converted the money into a digital transaction code. By the time Lucas contacted customer service fifteen minutes later, internal records showed the card had been fully redeemed at a third-party checkout terminal hundreds of miles away.