tuthelens/Depositphotos.com
The acceleration of cyberattacks from Marks & Spencer to Harrods and Victoria’s Secret in recent months have led to calls for retailers to step up their investments in cybersecurity and digital resilience.
Retailers remain prime targets due to their online presence and the high volume of transactions involving billions of customers’ sensitive data. Retailers catering to high-end clients are seen as particularly vulnerable. Other retailers recently involved in attacks include Adidas, Cartier, Co-Op, Dior, and The North Face.
Risks to retailers include shutting down systems during breaches, with both Marks & Spencer and Victoria’s Secret temporarily taking down their websites in response to such attacks. United Natural Foods — North America's largest publicly-held wholesale food distributor and the main distributor for Whole Foods — said last week that a breach, discovered June 6, shut down its systems for three weeks, leading to $350 million to $400 million in lost sales for the year.
Retailers May Downplay Security Breaches Out of Caution
Retailers also risk stock price hits and regulatory fines as a result of data breaches.
Firms hit by breaches have further been found to underreport incidents to avoid bad press, ultimately risking customer trust. A survey from Vercara found two-thirds of consumers would not trust a company following a data breach.
James Maude — field CTO at BeyondTrust, which develops intelligent identity and access security solutions — believes creating seamless online purchase platforms could be opening doors for cyber attackers. Maude told Security Magazine, “In general, the retail sector can find themselves caught in tradeoffs where their focus is on making it as easy as possible to buy an item not making it as secure as possible.”
He noted that requiring multi-factor authentication (MFA) for online consumers may make them hesitant to make an impulse purchase. Maude added, “Similarly, rewards points and loyalty schemes have become a frequent target for attack as attackers launch credential stuffing campaigns fueled by other breaches to access and cash out rewards and points into untraceable gift cards or goods.”
Beyond prioritizing MFA, industry experts are increasingly recommending zero-trust architecture, which requires continuous verification of all user identities and device integrity, significantly reducing the risk of unauthorized access. The latest breaches targeted third-party relationships within a supply chain.
Majority of Breaches Tied to Human Error, But Cybersecurity Will Become Even More of a Necessity for Retailers Moving Forward
VikingClouds found 95% of data breaches were tied to human error, often linked to inadequate cybersecurity training. VikingClouds said in a blog entry, “The high turnover of retail employees means more people with limited awareness of internal cyber policies.”
In a co-penned article for Information Security Buzz, Dave McGrail, head of business consultancy at Xalient and Chris Woods, founder and CEO at CyberQ Group, advised investing in precautionary incident response and recovery plans -- as well as in AI-driven threat intelligence. The two wrote, “Threats to retailers will only intensify with more ransomware attacks, combined with the security implications of new technologies like AI and machine learning, and the challenges of securing the supply chain.”
Greater collaboration among industry partners and law enforcement is also being called for. Co-op is teaming up with U.K. social impact business The Hacking Games to encourage teenagers to take up cybersecurity careers, rather than be drawn into hacking. The U.K.-based c-store chain cited data showing that 69% of European teenagers have committed some form of cybercrime or online offense.
