Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsRetail/Restaurants/Convenience

Why Are Cyberattacks Targeting Retail? Experts Share Their Thoughts

By Jordyn Alger, Managing Editor
Gift cards and credit cards

Dylan Gillis via Unsplash

June 5, 2025

Harrods, Marks & Spencer, Adidas and more — why are retailers facing this wave of cyberattacks in recent months? A few days after Victoria’s Secret shut down its website due to a cyberattack, Cartier and The North Face revealed the loss of customer data in their own attacks. 

James Maude, Field CTO at BeyondTrust, states, “This is yet another reminder that no brand is too big or too luxurious to be breached.”

While retailers may be targeted, Maude points out that malicious actors may not be after just these organizations. “The retailers themselves are not always the ultimate target and these may well represent supply chain attacks on high net worth individuals. The very nature of their client base makes them a valuable target for reconnaissance and information harvesting which may be used in further highly targeted and sophisticated social engineering attacks. In turn the luxury retailers are often smaller operations focused on brand and quality rather than IT so may be more similar to much smaller organizations in terms of their security maturity.” 

But why are retailers such a target in recent months? In both the United States and the United Kingdom, retail companies are facing notable cyberattacks. Maude believes that the emphasis on user-friendly features can weaken retailers’ website security. 

“In general, the retail sector can find themselves caught in tradeoffs where their focus is on making it as easy as possible to buy an item not making it as secure as possible. Nobody wants to prompt a customer to pass an MFA challenge that might make them think twice about an impulse purchase. Similarly, rewards points and loyalty schemes have become a frequent target for attack as attackers launch credential stuffing campaigns fueled by other breaches to access and cash out rewards and points into untraceable gift cards or goods.”

Below, more security experts share their insights on the cyber risks the retail sector is facing — and how retailers can defend against these threats. 

Why Are Cyberattacks Targeting Retail?

Ben Hutchison, Associate Principal Consultant at Black Duck:

Given the recent increase in cybersecurity attacks and incidents affecting retailers in both the U.S. and U.K., it’s unfortunate that the sector may be seen as a prime target, experiencing a surge in attack frequency and variety. This could be due to new attackers perceiving the sector as vulnerable, while previous attackers may be intensifying their efforts to maximize their gains or cause damage, depending on their motivations.

It’s also noteworthy that a diverse range of attack techniques have been used in recent compromises, suggesting the possibility of additional actors being involved. However, it could also mean that some targets were simply more susceptible to different methods in the attackers’ toolkit. Despite the variety of attacks, there are some common threads, such as the compromise of third-party services and supply chain dependencies, which served as entry points into the affected organizations.

This pattern is evident in recent incidents involving Adidas and MainStreet, based on previous reports, while other high-profile cases appear to have exploited vulnerabilities in the impacted services directly.

All of this underscores the importance for organizations to enhance their cybersecurity and digital resilience. This should not only focus on the technical aspects of their own systems but also include strategies to manage and mitigate risks within their broader supply chain and third-party relationships.

Agnidipta Sarkar, Chief Evangelist at ColorTokens:

Although the Cartier attack originated from a breach of an IT services provider, I believe that these recent cyberattacks are part of a broader trend of cyber threats targeting retailers and fashion brands, called Operation Grand Tour, which includes several other high-profile brands in the past few months. 

These leading brands not only have personal data of High Net Worth Individuals (HNI) and Ultra High Net Worth Individuals (UHNI), which is ideal for phishing, blackmail, or identity theft, they also have sensitive internal documents, such as design blueprints, financials, and supply chain details which can be sold to competitors or counterfeiters. However, the biggest impact is the reputational damage that could happen. 

What business and security leaders need to contemplate is the indication that cyberattacks are increasing, despite the best in class security programs. It is time they adopted zero trust mechanisms to stop lateral movement, using best-in-class microsegmentation tools immediately, especially those that are hyper focused on stopping the proliferation of breaches. Boards should be asking how the security leaders plan to ensure digital operational resilience by using breach ready cyber defense.

Ms. Nivedita Murthy, Senior Staff Consultant at Black Duck:

Retailers are always the biggest targets when it comes to gathering datasets of customer information for further attacks, especially luxury retailers who would cater to high-end clients. While in these cases sensitive information, such as passwords or credit card information, was not stolen, these breaches seem to be the first step towards phishing customers with curated information about their purchase history making them more susceptible to falling victim to fraud. Companies should take protecting customer data their highest priority as even basic information such as names, date of birth, email addresses and purchase history can be used to defrauding unsuspecting customers using the company’s name.

Haviv Rosh, Chief Technology Officer at Pathlock:

One lesson companies should learn is that MFA is no longer a “nice-to-have” option — it is a necessity, especially for critical applications. This is particularly evident given that one of the incidents resulted from a successful credential stuffing attack. 

At the same time, in the face of increasingly widespread and sophisticated threats, security leaders must go beyond just preventive measures. They need to implement comprehensive strategies that address every stage of the cybersecurity incident lifecycle — especially those that allow them to flag malicious activity at an early stage and prevent attackers from moving laterally across a company’s network.  

This includes identifying and prioritizing the protection of their most critical data; network segmentation; immutable backups; and leveraging infrastructure-as-code to rapidly redeploy environments. Incorporating serverless or container-based architectures for modular failover, along with privileged access governance that includes real-time auditing and drift detection, are also essential components. Finally, a critical — yet often overlooked — element of this approach is continuously testing the organization’s incident response plan under real-world conditions. 

KEYWORDS: cyberattack retail cyber security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Digital, tablet and hands

The 2025 Annual Guarding Report: Unrest Inspires Upgrades in Training, Technology

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

January 14, 2026

Is Your Organization Prepared to Navigate Interconnected Threats in 2026?

The 2026 threat environment will be louder, faster, and more interconnected. The most pressing risks, from global political volatility to emerging tech disruptions, will challenge organizations to act amid ambiguity and protect credibility in an era of accelerating uncertainty.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Tax documents and coffee mug

    Cybersecurity experts share how AI could enhance tax-related scams

    See More
  • Padlock with computer keys

    Celebrating Data Privacy Day: Experts share data protection insights

    See More
  • Office supplies

    Security Leaders Share Why 77% Organizations Lose Data Due to Insider Risks

    See More

Related Products

See More Products
  • facility manager.jpg

    The Facility Manager's Guide to Safety and Security

  • surveillance.jpg

    Surveillance, Privacy and Public Space

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing