← Latest papers
💻 computer science

E-Commerce Phishing Websites in Vietnam: An Exploratory Study

This exploratory study analyzes 607 e-commerce phishing websites in Vietnam from 2022 to 2024 to reveal how attackers increasingly impersonate major platforms like Shopee and Tiki while continuously adapting technical tactics, such as URL structures and protocols, to evade detection.

Original authors: Joshua Dwight

Published 2026-07-29
📖 6 min read🧠 Deep dive

Original authors: Joshua Dwight

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a massive, bustling digital city where people go to buy everything from sneakers to smartphones. In this city, there are trusted shops with bright signs and long lines of happy customers. But lurking in the shadows are "ghost shops"—fake storefronts built by tricksters to look exactly like the real ones. These tricksters, known as phishers, don't just want to steal your wallet; they want to steal your identity, your passwords, and your bank details by convincing you that their fake shop is the real deal. This is the world of phishing, a type of digital deception where bad actors use social engineering (basically, psychological tricks) to make you lower your guard.

To catch these ghost shops, security experts act like digital detectives. They look for clues in the "address" of the website (the URL), check if the shop has a secure lock (HTTPS), and see how closely the fake sign matches the real one. They also use giant databases of known bad guys to see if a new shop has been flagged before. This paper dives deep into one specific neighborhood of our digital city: Vietnam. As Vietnam's online shopping scene explodes with growth, the question isn't just if these ghost shops are appearing, but how they are changing their costumes to fool shoppers.


The Digital Ghost Hunt: What's Happening in Vietnam?

This study is like a time-traveling investigation into the world of online shopping scams in Vietnam. The researcher, Joshua Dwight, decided to play detective by looking at a massive collection of 607 fake e-commerce websites reported by Vietnam's National Cyber Security Center between 2022 and 2024. Think of this as reviewing three years' worth of police reports on "fake store" crimes to see how the criminals are evolving.

The big question was simple: How are these fake shops changing their tactics over time? Are they getting better at looking real? Are they using different tricks to hide?

The "Big Three" Targets

First, the study found that the bad guys aren't random; they have a favorite menu. Just like a burglar targets the most expensive houses, these phishers are going after the biggest names in Vietnamese online shopping. The most impersonated brands were Shopee, Tiki, and Lazada. If you've ever shopped online in Vietnam, you know these names. The data showed that in 2024 alone, Tiki was faked 86 times, Shopee 81 times, and Lazada 39 times. It seems the bigger the brand, the bigger the target.

The Costume Changes: Short URLs and Sneaky Protocols

One of the most interesting findings is how the "addresses" of these fake shops are changing. Imagine a real shop address is usually a long, complicated street name. You might expect a fake shop to try to copy that long address perfectly. But the study found something surprising: the fake addresses are getting shorter.

  • In 2022, the average fake address was about 21.4 characters long.
  • In 2023, it dropped dramatically to just 12.6 characters.
  • By 2024, it bounced back up to 19.9 characters.

The researchers suggest this isn't random. In 2023, the phishers seemed to experiment with very short URLs, perhaps trying to slip past security filters that look for long, suspicious strings of text. It's like a thief switching from wearing a giant, obvious mask to a tiny, barely visible one.

They also changed their "uniforms." Most legitimate shops use a secure lock icon (HTTPS) to look safe. The study found that in 2022, 80.7% of the fake shops used this secure lock. But in 2023? 0%. Instead, the phishers switched to a "relative protocol" (a technical way of saying they didn't use the standard secure or non-secure tags at all) in 98.2% of cases. It's as if the thieves stopped wearing the fake "Security Guard" vests entirely and just blended in by not wearing anything specific at all. By 2024, they went back to wearing the fake vests (HTTPS) in 66.2% of cases. This constant flipping suggests the bad guys are constantly testing what tricks work best to avoid getting caught.

The "Look-Alike" Score

Another clue the detectives used was the "Levenshtein distance." Think of this as a "similarity score." If the real shop is called "Shopee," and the fake one is "Shopee-Official," how many letters do you have to change to make them match? A lower score means they look very similar; a higher score means they look a bit more different.

The study found that the "look-alike" score changed significantly every year:

  • 2022: Average score of 11.27
  • 2023: Average score of 16.54 (They looked more different!)
  • 2024: Average score of 13.38

This suggests that in 2023, the phishers were less concerned with making a perfect copy and more concerned with other tricks (like the short URLs mentioned earlier). They were willing to look a bit more "off" if it helped them stay hidden.

The "Security Scanner" Blind Spot

Here is a scary part of the story. The researcher ran all these fake websites through VirusTotal, a super-popular online scanner that checks if a website is bad using 96 different security engines. You would think a scanner would catch all the bad guys, right?

Not so fast.

  • In 2022, 24% of the fake sites were not flagged as malicious by the scanners.
  • In 2023, that number jumped to 46%.
  • In 2024, 35% were still missed.

This means that nearly half of the time, the automated security systems didn't even realize the shop was fake. The average "badness score" given by the community was only about 3 out of 96, which is very low. It's like having a metal detector that misses almost half the knives.

The Time Gap

Finally, the study looked at how long these fake shops stayed up. In 2022, the government reported a fake shop about 132 days after it was first submitted to VirusTotal. But in 2023 and 2024, the trend flipped! The government reported them about 33 to 47 days before VirusTotal even knew about them. This suggests that in recent years, the local security team in Vietnam has actually become faster at spotting these ghosts than the global scanners, or perhaps the phishers are moving so fast that the global scanners are struggling to keep up.

The Bottom Line

This paper doesn't claim to have solved the problem of online scams. Instead, it paints a vivid picture of a cat-and-mouse game that is getting more intense. The bad guys in Vietnam are smart; they aren't just copying the real shops anymore. They are changing their address lengths, swapping their security uniforms, and sometimes slipping past the very scanners designed to catch them.

The study suggests that as Vietnam's digital economy grows (with online sales hitting $17.3 billion in 2023), the tricks used by phishers are becoming more sophisticated and adaptable. The "one-size-fits-all" security tools might not be enough. The researchers hint that we need better training for people (so they don't get tricked) and smarter, faster ways to detect these ever-changing ghosts. Until then, the ghost shops are still out there, changing their costumes every year to stay one step ahead.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →