“Once card details were collected, they were exfiltrated to [attack servers controlled by cybercriminals].”

In an email exchange with Lifewire, Schloss said the attack appears to exploit a long-standing issue in Chrome.

“Most people have become good at identifying emails that don’t quite seem right,” argued Hay.

A human hand is pressed against a binary etched glass wall in an image about hackers in the system, cybercrime, people trapped by technology and more.

John Lund / Getty Images

Red envelope representing a phishing email

Just_Super / Getty Images