The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Retail Industry
157 threat reports.
- CISA Elevates Two Critical Vulnerabilities to KEV Catalog Amid Active Exploitation
- Ghost Service Accounts: The Hidden Threat in Your M365 Environment
- TeamFiltration Campaign Exploits Forgotten Service Accounts in Chilean Organizations
- Psychedelic Stealer Targets Ukraine Through Fake Cloudflare ClickFix Campaign
- Autonomous AI Agents Execute Massive Credit Card Theft Campaign
- Entertainment Turned Weapon: How Cybercriminals Hide Advanced Malware in Popular Film Torrents
- BigCommerce Ribon App Breach: How Third-Party Integrations Became the New Attack Vector
- Abandoned CDN Domain Hijack Exposes Supply Chain Blind Spot in Thousands of Websites
- Critical WordPress Plugin Flaw Enables Mass Web Shell Deployment Campaign
- WordPress Under Fire: CVE-2026-27540 Plugin Flaw Enables Mass Webshell Attacks
- Account Recovery Becomes the New Attack Path as MFA Strengthens Defenses
- CISA's September 2026 KEV Update: Four Critical Vulnerabilities Under New Federal Mandate
- StyleSmuggler Attack: How CVE-2026-75650 Exposes Critical E-Commerce Security Gaps
- DoppelCart Fraud Network Exposes Massive E-Commerce Security Gap
- StyleSmuggler Zero-Day: How CVE-2026-75650 Compromised Magento E-commerce Security
- StyleSmuggler Zero-Day: How Advanced Backdoors Bypass E-Commerce Security
- StyleSmuggler Zero-Day Compromises Magento and Adobe Commerce Stores
- IDScan's Massive Data Breach Exposes 153 Million Driver's Licenses on Dark Web
- Breeze Comet Cybercrime Group: Direct Manipulation of Global Financial Payment Systems
- Breeze Comet's Sophisticated Attack on Brazilian Payment Systems Exposes Critical Infrastructure Vulnerabilities
- ClickFix Attackers Exploit Polygon Blockchain in Campaign Against 31 Organizations
- ShinyHunters Exposes 12.9M Carhartt Records After Databricks Platform Compromise
- PayRange API Vulnerability Exposes Critical Payment Infrastructure
- Carhartt Breach Analysis: How Synthetic Data Inflated ShinyHunters' 2026 Attack Claims
- Advanced Android Banking Malware: ToxicPanda 2.0 and GoldDigger Threaten Global Financial Security
- Zombie Card Attack Exposes Critical Flaw in Visa Contactless Payment Security
- SafePal Data Exposure Incident: A Wake-Up Call for Crypto Security
- WindRelay Malware: A New Threat to Contactless Payments
- Immediate Action Required: SAP Commerce Cloud CVE-2026-58231 Exploited Days After Patch Release
- Critical Adobe Commerce Vulnerability CVE-2026-71362: Immediate Action Required
- Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231
- Levi Strauss 2026 Cyberattack: A Social Engineering Case Study
- Critical Vulnerability in Watchfire Controller Software: CVE-2026-5846
- H96 TV Streaming Devices Exploited for Ad Fraud in 2026
- Fastjson CVE-2026-16723: Critical RCE Vulnerability Under Active Exploitation
- Europol's Crackdown on 'The Com' Network: 4,340 URLs Flagged for Removal
- Chick-fil-A Data Breach 2026: Credential Stuffing Attack Compromises Customer Accounts
- OnTrac Data Breach 2026: What You Need to Know
- Chick-fil-A Credential Stuffing Attack Exposes Customer Data
- Upbound Group's 2026 Data Breach Results in $13 Million Acima Fraud
- Cybercriminals' Quest for 'Clean' Residential Proxies in Carding Schemes
- Phishing Attacks Exploit Hidden Text to Bypass AI Security Filters
- Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
- Protecting SaaS Applications from ShinyHunters' OAuth Exploits
- Lidl Data Breach: Safeguarding Customer Information in the Digital Age
- Vidar Infostealer Exploits Malvertising to Target SMBs in 2026
- Scattered Spider Hacker Traced via Windows Device ID
- Alleged Scattered Spider Hacker Extradited to the United States
- Cybercriminals Exploit Shop App in Advanced Phishing Attack - June 2026
- Scattered Spider Hackers Plead Guilty in TfL Cyberattack
- ShapedPlugin Supply Chain Attack: A Wake-Up Call for WordPress Security
- OptinMonster WordPress Plugin Hacked in CDN Supply-Chain Attack
- Coupang Data Breach 2025: A Wake-Up Call for E-Commerce Security
- Critical Vulnerabilities in SAP NetWeaver and Commerce Cloud - June 2026
- Meta AI Support Exploit Leads to Massive Instagram Account Hijack
- Toshiba and Muji Websites Compromised by Malicious Polyfill.io Scripts
- Magecart Attack Leverages Stripe API to Steal Credit Card Data
- CISA Highlights Critical Magento Vulnerability CVE-2026-45247 Amid Active Exploitation
- Carnival Corporation's 2026 Data Breach: A ShinyHunters Operation
- Urgent Update: WP Maps Pro Vulnerability (CVE-2026-8732) Threatens WordPress Sites
- 7-Eleven Data Breach: A Wake-Up Call for Cloud Security
- Apple's 2025 App Store Fraud Prevention Milestones
- Ukrainian Authorities Uncover Major Infostealer Operation in 2026
- 7-Eleven Data Breach 2026: ShinyHunters Expose 600,000 Records
- Critical Vulnerability in Funnel Builder Plugin Leads to WooCommerce Checkout Skimming
- Critical Vulnerability in Funnel Builder Plugin Leads to Credit Card Theft
- AI Agents Enable Sophisticated Cyberattacks in Latin America
- Unveiling AI-Driven E-Commerce Fraud Schemes in 2026
- SAP Releases Critical Security Patches for Commerce Cloud and S/4HANA
- Škoda Online Shop Data Breach: A Wake-Up Call for E-Commerce Security
- Inditex Data Breach 2026: Lessons in Third-Party Risk Management
- Cordial and Snarky Spider's Rapid Data Theft and Extortion Attacks
- Scattered Spider Hacker Arrested in Finland Faces U.S. Charges
- BlackFile's Vishing Attacks: A Wake-Up Call for Retail and Hospitality Sectors
- BlackFile Extortion Group's Vishing Attacks on Retail and Hospitality
- Rituals Data Breach 2026: Safeguarding Customer Information
- NGate Malware Exploits HandyPay App to Steal NFC Payment Data
- NGate Malware Exploits HandyPay App to Steal NFC Data in Brazil
- Seiko USA Website Defaced: Hackers Claim Customer Data Theft
- Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
- JanaWare Ransomware: A Persistent Threat to Turkish Homes and SMBs
- Magento 2026: PolyShell Vulnerability Exploited in Credit Card Skimming Attacks
- Hasbro's 2026 Cyberattack: A Wake-Up Call for Corporate Cybersecurity
- Magecart E-Skimmer Infections Reach Record Highs in 2025
- Venom Stealer: The New Frontier in Automated ClickFix Attacks
- TikTok Business Accounts Compromised in 2026 AiTM Phishing Attack
- WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
- PolyShell Attacks Compromise Over Half of Vulnerable Magento Stores
- Surge in Agentic AI-Driven Retail Fraud in 2026
- Magento 'PolyShell' Vulnerability: Unauthenticated RCE Threatens E-Commerce Security
- Magento's 'SessionReaper' Vulnerability: A Critical Threat to E-Commerce Security
- LiveChat Phishing Attack Exposes Sensitive User Data
- Starbucks 2026 Data Breach: Credential Theft via Phishing
- Loblaw Data Breach 2026: Customer Information Exposed
- Critical Security Flaws in Apeman Cameras: A 2025 Analysis
- LeakBase 2026: Global Law Enforcement Takedown of Major Cybercrime Forum
- Europol's Project Compass Dismantles The Com Cybercriminal Network
- Olympique de Marseille's 2026 Cyberattack: A Case Study in Incident Response
- ManoMano Data Breach 2026: Lessons in Third-Party Risk Management
- FBI Reports Surge in ATM Jackpotting Attacks in 2025
- ShinyHunters Expose 600K Canada Goose Customer Records in 2026 Data Breach
- Critical Vulnerability in TP-Link VIGI Cameras: Authentication Bypass Exploit (CVE-2026-0629)
- Panera Bread's 2026 Data Breach: A Cautionary Tale of Vishing Attacks
- Credential Stuffing Attempt at PcComponentes: 2024 Incident Overview
- Predator Bots Hit APIs at Scale: Are Your Defenses Ready for Autonomous Threats?
- Magecart Web Skimming Campaign Exposes Payment Providers and Customers
- Target 2026 Source Code and Git Server Breach Highlights DevSecOps Urgency
- Coupang’s $1.17B Insider Data Breach Puts Spotlight on Retail Security
- Coupang Suffers Massive 2024 Data Breach: 33.7 Million Users Impacted by Credential Abuse
- Askul Hit by RansomHouse: 740,000 Customer Records Stolen in 2023 Ransomware Attack
- PayPal Subscriptions Abused for Advanced Phishing Campaigns in 2024
- Coupang’s 2024 Insider Breach: Ex-Employee Exposes 33.7 Million Customer Records
- Japan’s 2024 Ransomware Surge: How Long-Tail Attacks Crippled Key Sectors
- Holiday Season Phishing Surge: Fake Rewards, Tax Refunds, and Retail Scams Hit US Consumers
- M&S & Co-op Group 2025: Identity-Based Vishing Unleashes Ransomware Chaos
- Arizona AG Files 2024 Suit Against Temu Over User Data Harvesting
- Leroy Merlin Customer Data Breach Exposes Personal Information in France
- Inside the 2024 Korea IP Camera Mass-Hack: A Wake-Up Call for IoT Security
- Coupang Data Breach 2024: 33 Million Customers Exposed in Massive Retail Incident
- Asahi Group Data Breach: 1.9 Million Records Exposed in 2023 Cyberattack
- 2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted
- Superbox Android TV Botnet: The Silent Takeover of Consumer Home Networks
- Logitech Suffers 2024 Data Breach from Clop Extortion Attack
- 2024 Uhale Android Photo Frame Breach: Supply Chain Malware Risk
- Google Targets Smishing Triad: 2025 Lawsuit Disrupts Phishing-as-a-Service Operations
- Global Credit Card Fraud Rings Dismantled in Europol-Led €300M Operation
- Europe Hit by Massive NFC Relay Malware Attacks Targeting Payment Cards in 2024
- CISA Adds Adobe/Magento & WSUS Exploits to 2025 KEV Catalog
- Morocco’s 'Jingle Thief' Heist Shows Retailers’ Holiday Cyber Weaknesses
- How Chinese Gangs Engineered a $1B+ US Credit Card Fraud Wave via Smishing in 2025
- Global Smishing Triad Campaign: 194,000 Malicious Domains Power Massive Phishing Surge
- SessionReaper in the Wild: How a 2025 Adobe Commerce Flaw Fueled E-Commerce Breaches
- Toys "R" Us Canada Faces Customer Data Leak in 2024 Breach
- Over 250 Magento Stores Breached Overnight Through Critical Adobe Commerce Flaw
- Jingle Thief: How Hackers Exploited Cloud to Steal Millions in Retail Gift Cards (2025)
- Mideast & African Hackers Launch Multi-Vector Attacks on Governments, Banks, and Retailers in 2024
- Critical SessionReaper Flaw Exploited in Adobe Magento: 2025 Breach Analysis
- Jingle Thief: A 2024 Look at Cloud Gift Card Fraud in Retail
- Muji Halts Online Sales After Supply Chain Ransomware Hits Logistics Partner
- MANGO Data Breach 2024: Third-Party Vendor Incident Exposes Customer Data
- Bling Libra’s 2024 Extortion: Lessons from a Modern Ransomware Attack
- FBI Disrupts BreachForums Data Extortion Portal Tied to Salesforce Attacks
- Storm-1175 Exploits GoAnywhere Zero-Day to Orchestrate Ransomware Attacks in 2024
- Salesforce 2025 Supply Chain Data Breach: An Executive Overview
- How Qilin Ransomware Disrupted Asahi’s Breweries in 2025
- ShinyHunters Extorts 39 Firms in Salesforce OAuth Supply Chain Breach
- Motility Software Suffers Major Ransomware Breach Impacting Over 766,000 Clients
- Harrods Suffers Major Supply Chain Breach: 430,000 Customer Records Exposed in 2025
- Asahi Group 2025: Ransomware Attack Halts Japan's Largest Brewer
- Inside the 2025 Co-op Scattered Spider Cyberattack: Lessons and Impact
- Persistent Exploitation of Hikvision Camera Vulnerabilities (2017–2025): Lessons for IoT Security
- Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks
- DPRK Leverages ClickFix Job Scams to Infest Crypto Firms with BeaverTail Infostealer
- Scattered Spider Strikes: 2024 Ransomware Attack on Transport for London Exposes Critical Gaps
- 2025 Salesforce Data Breach: Supply Chain Extortion Hits Retail Sector
- 2025 Retail Salesforce Data Heist: Extortion Attack Exposes Cloud Security Gaps
- Session Hijacking and Browser Cookies: The State of Web App Security in 2024
157 threat reports