Why Online Shoppers Are Tuning Out Scam Warnings—And How to Fix That

If you do most of your shopping online, you’ve probably seen the alerts: a browser warning that a site isn’t secure, an email flagged as suspicious, or a message that a deal looks too good to be true. A new report from KnowBe4, released this week, suggests that many people are clicking past those warnings anyway. The result? More shoppers are falling for scams that cost them real money.

The report, which surveyed consumer behavior around online shopping safety, found that a significant number of respondents admitted to ignoring or dismissing fraud alerts during the checkout process. The reasons vary, but the trend is clear: we’re desensitised to warnings, and criminals are taking advantage.

What’s happening

KnowBe4’s 2026 Online Shopping Scam Report pulled data from thousands of consumers and tracked how they responded to simulated scam scenarios. The key finding: a growing share of shoppers overlook obvious red flags when they’re in a hurry, focused on a bargain, or convinced they’re dealing with a trusted brand.

For example, nearly half of participants said they would proceed with a purchase even after receiving a browser warning that the site’s security certificate was invalid. Others said they would click links in unsolicited emails offering discounts on popular items—even when the email address didn’t match the company’s official domain.

These aren’t sophisticated attacks. Many are simple phishing emails or fake storefronts that copy legitimate sites with slight typos in the URL. What’s changing is our willingness to ignore the signs.

Why we’re ignoring the warnings

It’s easy to blame carelessness, but the psychology runs deeper. Several factors are at play:

  • Urgency and FOMO. Scammers often use countdown timers or “limited stock” messages. When you think you might miss a deal, you act fast and skip the safety check.
  • Familiarity bias. A fake ad that mimics Amazon or eBay can feel safe because you’ve bought from those platforms before. The brain shortcuts trust to the brand, not the specific link.
  • Warning fatigue. If you see browser warnings or “this email might be a scam” labels every day, they start to feel like noise. After enough false positives, it’s easy to assume the warning is just a nuisance.
  • Overconfidence. Many shoppers believe they’re too savvy to fall for a scam—right up until they do.

The scams on the rise right now

The report highlights several specific types of shopping scams gaining traction:

  • Phishing emails that look like order confirmations. You receive a receipt for something you didn’t buy, with a link to “cancel” or “view details.” Clicking leads to a credential harvesting page.
  • Fake “your account has been suspended” alerts. These often arrive as text messages or pop-ups, prompting you to verify payment details on a counterfeit site.
  • Social media marketplace fraud. Scammers list items at unrealistically low prices and request payment via gift cards, Zelle, or Venmo before “shipping.” The item never arrives.
  • Lookalike domains. A site like amaz0n-deals.com or bestbuy-discount.store can slip past a quick glance, especially on mobile.

What you can do about it

You don’t need to be paranoid, but a few simple habits can make a big difference. Here’s a practical checklist to use before you hit “buy”:

  1. Check the URL before you enter payment info. Look for typos, extra hyphens, or unusual top-level domains (.co, .xyz, .shop). Legitimate retailers rarely use those.
  2. Hover over links in emails. On a desktop, hover to see the real destination. On mobile, press and hold the link to preview it. If the URL doesn’t match the supposed sender, don’t click.
  3. Pay with a credit card or a service like PayPal Goods & Services. These offer fraud protection. Avoid wire transfers, gift cards, and person-to-person payment apps for purchases from strangers.
  4. Ignore high-pressure tactics. If a deal is only good for the next 10 minutes, let it expire. Real sales will come back.
  5. Use a password manager and enable two-factor authentication. Even if a scammer gets your login credentials, a second factor can block them.
  6. Install an anti-phishing browser extension. Tools like uBlock Origin with strict filters or dedicated anti-fraud add-ons can catch fake sites before you do.

The bottom line

Scammers rely on speed and distraction. The moment you slow down and look closely—at the domain, the sender, the payment method—you break their spell. The KnowBe4 report is a reminder that warnings only work if we pay attention to them.

The best defence isn’t a new tool or a security service; it’s simply taking an extra few seconds to question whether that amazing deal is real. Most of the time, your gut already knows the answer.


Sources:

  • KnowBe4, 2026 Online Shopping Scam Report (released June 25, 2026)
  • Research on consumer behaviour and phishing susceptibility cited in the report (specific statistics not yet released publicly; general trends confirmed by KnowBe4’s announcement)