Filed Under: Tech

How Grinch bots are trying to steal Christmas

By ,

The Grinch is coming to rob holiday cheer, just not through the chimney. Grinch bots are here to steal Christmas deals online. These virtual scalpers are scanning the internet, buying up all the goodies consumers want for the holidays. They then resell the products on sites like eBay at much higher prices.

‘It’s absolutely legal’

“It’s absolutely legal,” said Jason Kent, a hacker-in-residence for Cequence Security. Kent’s job is to stop bots from buying out retailers.

“They’re usually tech-savvy people that started doing this with Supreme, or sneakers, or something like that. They realize they can just do this anywhere,” he said.

After honing their skills year-round, Kent said these Grinch bots are hitting the holidays hard. Based on his perceptions, activity starts to really pick up in October and sustains until January.

With an already limited supply of hot-ticket items like PS5s, it’s harder than ever to compete against computers.

“What they do, instead of creating an account for themselves, is they go buy accounts, and they’ll have somebody farm out 300 accounts,” Kent explained. “So they’ll be logged in 300 times, there’ll be 300 people against you.”

And there’s perfectly legal software to do this. Take Australia-based KodaiAIO, which claims on its website to be “locked and loaded to destroy releases on nearly all major retailers.”

On social media, the company brags about so-called cookouts, where bots score dozens of gaming consoles or sneakers. The software even shows the suggested resale value on the score. Sophisticated software like this makes it hard to track people down.

“It looks like they’re coming from everywhere instead of just wherever they’re sitting in their basement,” Kent said.

Efforts to outlaw

Some lawmakers are trying to outlaw this practice, recently re-introducing the ‘Stopping Grinch Bots Act.’

“Our Grinch Bots Act works to level the playing field and prevent scalpers from sucking hardworking parents dry this holiday season,” Rep. Paul Tonko (D-NY) said.

But cybersecurity experts like Kent are doubtful simply making the practice illegal will stop people from doing it, especially when their online identity is so well hidden and when the software comes from outside the U.S.

“I don’t think this legislation is going to work,” Kent said. “What I think they need to do with this legislation is just simply turn it around to the retailers, ‘You must put something in place to stop this activity.'”

For now, if you can’t beat the bots, bypass them. A Grinch bot can’t walk into a store to buy that coveted gaming console on the shelf.

SIMONE DEL ROSARIO: THE GRINCH IS COMING TO STEAL YOUR HOLIDAY CHEER, JUST NOT THROUGH THE CHIMNEY.

INSTEAD, IT’S TAKING PLACE ONLINE WITH GRINCH BOTS.

SO, WHAT IS A GRINCH BOT? AND WHAT’S BEING DONE TO STOP IT?

THESE VIRTUAL SCALPERS ARE SCANNING THE INTERNET, BUYING UP ALL THE GOODIES YOU WANT FOR THE HOLIDAYS.

THEN SELLING IT BACK TO YOU AT A MUCH HIGHER PRICE.

JASON KENT: IT’S ABSOLUTELY LEGAL.

SIMONE DEL ROSARIO: JASON KENT’S JOB IS TO STOP THESE BOTS FROM BUYING OUT RETAILERS.

JASON KENT: THEY’RE USUALLY TECH SAVVY PEOPLE THAT STARTED DOING THIS WITH SUPREME, OR SNEAKERS OR SOMETHING LIKE THAT. THEY REALIZE THEY CAN JUST DO THIS ANYWHERE.

SIMONE DEL ROSARIO: AND AFTER HONING THEIR SKILLS YEAR ROUND, THEY’RE HITTING THE HOLIDAYS HARD.

WITH AN ALREADY LIMITED SUPPLY OF HOT-TICKET ITEMS LIKE P-S-5S, IT’S HARDER THAN EVER TO COMPETE AGAINST COMPUTERS.

JASON KENT: WHAT THEY DO, INSTEAD OF CREATING AN ACCOUNT FOR THEMSELVES, IS THEY GO BUY ACCOUNTS, AND THEY’LL HAVE SOMEBODY FARM OUT 300 ACCOUNTS. SO THEY’LL BE LOGGED IN 300 TIMES, THERE’LL BE 300 PEOPLE AGAINST YOU.

SIMONE DEL ROSARIO: AND THE SOFTWARE IS PERFECTLY LEGAL. TAKE AUSTRALIA-BASED KODAI AIO, WHICH CLAIMS TO BE “LOCKED AND LOADED TO DESTROY RELEASES ON NEARLY ALL MAJOR RETAILERS.”

THEY BRAG ABOUT SO-CALLED COOKOUTS, WHERE BOTS SCORE DOZENS OF GAMING CONSOLES OR SNEAKERS. THEY EVEN SHOW THE SUGGESTED RESALE VALUE ON THE SCORE.

SOPHISTICATED SOFTWARE LIKE THIS MAKES IT HARD TO TRACK DOWN THE PEOPLE DOING IT.

JASON KENT: IT LOOKS LIKE THEY’RE COMING FROM EVERYWHERE INSTEAD OF JUST WHEREVER THEY’RE SITTING IN THEIR BASEMENT.

SIMONE DEL ROSARIO: SOME LAWMAKERS ARE TRYING TO OUTLAW THIS PRACTICE, RECENTLY RE-INTRODUCING THE “STOPPING GRINCH BOTS ACT.”

NEW YORK REP PAUL TONKO SAYS IT “WORKS TO LEVEL THE PLAYING FIELD AND PREVENT SCALPERS FROM SUCKING HARD WORKING PARENTS DRY THIS HOLIDAY SEASON.”

BUT WILL SIMPLY MAKING IT ILLEGAL STOP PEOPLE FROM DOING IT? ESPECIALLY WHEN THEIR ONLINE IDENTITY IS SO WELL HIDDEN? AND WHEN THE SOFTWARE COMES FROM OUTSIDE THE U-S?

JASON KENT: I DON’T THINK THIS LEGISLATION IS GOING TO WORK. WHAT I THINK THEY NEED TO DO WITH THIS LEGISLATION IS JUST SIMPLY TURN IT AROUND TO THE RETAILERS, ‘YOU MUST PUT SOMETHING IN PLACE TO STOP THIS ACTIVITY.’

SIMONE DEL ROSARIO: FOR NOW – IF YOU CAN’T BEAT THE BOTS, BYPASS THEM. YOU KNOW WHAT A GRINCH BOT CAN’T DO? WALK INTO A STORE TO BUY THAT COVETED CONSOLE ON THE SHELF.

ARE YOU HAVING TROUBLE FINDING GIFTS IN STOCK THIS SEASON?

LET ME KNOW IN THE COMMENTS BELOW.

The Grinch is coming to rob holiday cheer, just not through the chimney. Grinch bots are here to steal Christmas deals online. These virtual scalpers are scanning the internet, buying up all the goodies consumers want for the holidays. They then resell the products on sites like eBay at much higher prices.

‘It’s absolutely legal’

“It’s absolutely legal,” said Jason Kent, a hacker-in-residence for Cequence Security. Kent’s job is to stop bots from buying out retailers.

“They’re usually tech-savvy people that started doing this with Supreme, or sneakers, or something like that. They realize they can just do this anywhere,” he said.

After honing their skills year-round, Kent said these Grinch bots are hitting the holidays hard. Based on his perceptions, activity starts to really pick up in October and sustains until January.

With an already limited supply of hot-ticket items like PS5s, it’s harder than ever to compete against computers.

“What they do, instead of creating an account for themselves, is they go buy accounts, and they’ll have somebody farm out 300 accounts,” Kent explained. “So they’ll be logged in 300 times, there’ll be 300 people against you.”

And there’s perfectly legal software to do this. Take Australia-based KodaiAIO, which claims on its website to be “locked and loaded to destroy releases on nearly all major retailers.”

On social media, the company brags about so-called cookouts, where bots score dozens of gaming consoles or sneakers. The software even shows the suggested resale value on the score. Sophisticated software like this makes it hard to track people down.

“It looks like they’re coming from everywhere instead of just wherever they’re sitting in their basement,” Kent said.

Efforts to outlaw

Some lawmakers are trying to outlaw this practice, recently re-introducing the ‘Stopping Grinch Bots Act.’

“Our Grinch Bots Act works to level the playing field and prevent scalpers from sucking hardworking parents dry this holiday season,” Rep. Paul Tonko (D-NY) said.

But cybersecurity experts like Kent are doubtful simply making the practice illegal will stop people from doing it, especially when their online identity is so well hidden and when the software comes from outside the U.S.

“I don’t think this legislation is going to work,” Kent said. “What I think they need to do with this legislation is just simply turn it around to the retailers, ‘You must put something in place to stop this activity.'”

For now, if you can’t beat the bots, bypass them. A Grinch bot can’t walk into a store to buy that coveted gaming console on the shelf.

Recent Reports


Get unbiased straight facts, context, and perspective!