Jingle Thief Unwrapped: How Moroccan Hackers Turned Gift Cards into a Holiday Heist

Moroccan threat actors are jingling all the way to the bank with the Jingle Thief campaign. Targeting gift card systems during festive seasons, these cyber grinch impersonators steal credentials through phishing and smishing, bypassing Microsoft 365 defenses. Secure your holiday shopping, because these naughty list members are leaving no trace except sleigh bells.

Pro Dashboard

Hot Take:

Jingle Thief: Making the Holidays Less Merry and More Scary! Forget “Jingle Bells,” we’re all about “Jingle Swells”—as in swelling their bank accounts with fraudulent gift cards! These Moroccan cyber grinches have turned festive cheer into fear, proving once again that when it comes to cybersecurity, you better watch out, you better not cry, because these hackers are coming to town!

Key Points:

  • Jingle Thief targets global retail and consumer services using phishing and smishing to steal credentials.
  • The campaign exploits Microsoft 365 services for reconnaissance and long-term access, focusing on cloud environments.
  • Gift cards are the preferred loot due to their ease of redemption and lack of traceability.
  • Threat actors maintain a covert presence by creating inbox rules and registering rogue devices.
  • The operation is linked to Morocco with little attempt to hide geographic origins.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?