NordVPN's Threat Intelligence team uncovered a coordinated fraud operation targeting Pokémon Trading Card Game collectors through fake storefronts promoted on Google, Instagram, and Facebook. The sites pose as legitimate retailers, often claiming to operate from France or Canada and using professional Shopify themes, pre-order language, and scarcity messaging to rush collectors toward checkout, with operators buying sponsored placements tied to specific cards so the stores surface the moment shoppers search for hard-to-find inventory. Some victims reported receiving a physical thank-you card, coupon, or cheap booster pack after ordering, a touch designed to make the store look legitimate and delay a chargeback while the buyer keeps waiting for a product that never ships. NordVPN flagged holobooster.com, poketurbo.com, pokelios.com, and tcgora.com as part of the operation, which runs a hit-and-run pattern of launching a domain, collecting payments, then shutting it down before victims or platforms respond.





