Jingle Thief Hackers Exploit the Festive Season with Weaponized Gift Card Scams
## Cybersecurity: Jingle Thief Campaign Overview
Cybersecurity: Jingle Thief Campaign Overview
Cybersecurity researchers have identified a sophisticated campaign targeting global retail and consumer services organizations through credential theft and gift card fraud. This operation, known as "Jingle Thief," exploits vulnerabilities during the festive shopping season.
The campaign is orchestrated by threat actors from Morocco, tracked by Unit 42 as cluster CL-CRI-1032, and has been active since 2021. It overlaps with known threat groups Atlas Lion and STORM-0539, posing a persistent threat to enterprise cloud infrastructure.
Jingle Thief is distinctive due to the attackers' ability to maintain undetected access within compromised organizations for extended periods, often over a year. They map the victim's environment, gaining access to critical systems and gift card platforms. This operational patience and advanced reconnaissance make detection and remediation challenging.
The threat actors primarily operate in cloud environments, using phishing and SMS-based smishing to obtain credentials. They utilize Microsoft 365 capabilities to impersonate legitimate users and conduct large-scale fraud operations.
In one observed instance, attackers maintained access for about 10 months, compromising over 60 user accounts within a single global enterprise. Their operations align with holiday periods to capitalize on reduced staffing and increased transaction volumes, obscuring fraudulent activities.
The Jingle Thief attack lifecycle starts with customized phishing campaigns designed to harvest cloud credentials. Threat actors conduct reconnaissance to gather intelligence on target organizations, enabling them to craft convincing phishing content.
Cybersecurity researchers have identified a sophisticated campaign targeting global retail and consumer services organizations through credential theft and gift card fraud.
Phishing messages often use deceptive URL formatting and are sent from compromised servers. Once credentials are harvested, attackers access Microsoft 365 environments without deploying malware.
After gaining access, attackers conduct extensive reconnaissance within SharePoint and OneDrive, searching for documentation on gift card issuance workflows and organizational details. This helps them maintain a low detection profile.
To expand their reach, threat actors conduct internal phishing campaigns and create malicious inbox rules to monitor communications related to gift card approvals.
Gift cards are attractive targets for cybercriminals due to their rapid monetization potential. Stolen gift cards are resold at discounted rates, enabling quick cash flow. These digital assets are difficult to trace and require minimal information for redemption.
Retail environments are vulnerable due to weak access controls and limited monitoring. Threat actors attempt high-value card issuances, using them in money-laundering schemes.
Attribution and Infrastructure Analysis
Campaign activities primarily originate from Moroccan IP addresses, with consistent device fingerprints and login behaviors. Unlike many threat actors, Jingle Thief operators often do not obscure their Moroccan location.
In April and May 2025, coordinated attacks occurred across multiple global enterprises, demonstrating continued operational capability. This activity was identified through behavioral anomalies by Cortex User Entity Behavior Analytics (UEBA) and Identity Threat Detection and Response (ITDR) systems.
The Jingle Thief campaign highlights the shift in enterprise security towards identity-based threat detection. Organizations must monitor user behavior and identity misuse to detect and respond to these sophisticated fraud operations early.
Based on reporting by GBHackers.



