The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Retail Industry

Breach intelligence, attack campaigns, and threat reports targeting the Retail Industry sector.

156 threat reports
Page 1 of 13

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Retail Industry Threat Reports

Showing 1–12 / 156 reports
Ghost Service Accounts: The Hidden Threat in Your M365 Environment
Impact· HIGH

Ghost Service Accounts: The Hidden Threat in Your M365 Environment

In July 2026, threat actor UNK_CondorFiltration successfully compromised a major Chilean retailer's Microsoft 365 environment using the open-source TeamFiltration toolkit. After failing to breach employee accounts at multiple Chilean financial institutions, the attacker pivoted to exploit forgotten service accounts with default credentials and no multi-factor authentication. Within seven minutes, six of seven targeted service accounts were compromised, enabling the exfiltration of emails, chat conversations, and files from Outlook, Teams, and OneDrive. The attacker also probed the company's VPN and accessed both M365 and Azure management portals. This incident highlights the growing threat of identity-based attacks targeting non-human accounts in cloud environments. As organizations strengthen human account security, attackers increasingly focus on overlooked service accounts that lack proper lifecycle management, creating critical security gaps in zero trust implementations.

6 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
TeamFiltration Campaign Exploits Forgotten Service Accounts in Chilean Organizations
Impact· HIGH

TeamFiltration Campaign Exploits Forgotten Service Accounts in Chilean Organizations

In July-August 2026, the UNK_CondorFiltration campaign leveraged the TeamFiltration framework to target over 5,700 Microsoft 365 accounts across 28 tenants, primarily focusing on Chilean retail and financial institutions. Operating from 1,487 unique AWS EC2 IP addresses, attackers successfully compromised 7 unmanaged service accounts using default passwords and no multi-factor authentication. The campaign unfolded in three waves, with threat actors gaining access to Microsoft Office, OneDrive, and Teams within minutes of compromise, then pivoting through German VPN nodes to access corporate infrastructure and initiate data exfiltration activities. This incident highlights the growing trend of attackers targeting forgotten service accounts and leveraging legitimate penetration testing tools for malicious purposes, reflecting broader shifts toward identity-based attacks that exploit basic hygiene gaps rather than sophisticated exploits.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Psychedelic Stealer Targets Ukraine Through Fake Cloudflare ClickFix Campaign
Impact· HIGH

Psychedelic Stealer Targets Ukraine Through Fake Cloudflare ClickFix Campaign

In September 2026, threat actors compromised legitimate Ukrainian business websites to inject fake Cloudflare verification pages as part of a ClickFix campaign distributing Psychedelic Stealer malware. The attack targeted various Ukrainian businesses including healthcare facilities, retailers, and manufacturers, using social engineering to trick victims into executing malicious MSI installers that harvested browser credentials, cryptocurrency wallets, and account tokens. Arctic Wolf Labs documented 557 views with 426 clicks across the campaign, primarily targeting Ukrainian users but also affecting victims in the US, Poland, Germany, Canada, and the Netherlands. This incident highlights the growing sophistication of information stealer campaigns that exploit trusted brand impersonation and legitimate website compromise to bypass security controls. The emergence of new stealer families like Psychedelic, combined with advanced evasion techniques and modular malware ecosystems, represents an escalating threat to credential security and highlights the urgent need for enhanced egress filtering and behavioral monitoring capabilities.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Autonomous AI Agents Execute Massive Credit Card Theft Campaign
Impact· CRITICAL

Autonomous AI Agents Execute Massive Credit Card Theft Campaign

A Chinese threat actor deployed autonomous AI agents to orchestrate a massive payment card theft operation, compromising over 119 websites and stealing more than 600,000 credit card records. The campaign, active since July 2026, utilized three AI frameworks - Strix for vulnerability scanning, Cairn for exploitation, and Hermes for orchestration - to systematically target online retailers. Major victims included Fortune 500 companies across hospitality, aviation, and retail sectors. The attackers deployed payment skimmers through various injection methods and implemented destructive cleanup procedures that wiped source data after exfiltration, causing operational disruptions. This incident represents a paradigm shift toward AI-powered cybercrime, demonstrating how autonomous systems can execute complex attack chains at unprecedented scale and speed. The low operational cost of $25 per target and minimal human oversight signal a new era where sophisticated attacks become accessible to less skilled threat actors, fundamentally changing the threat landscape.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Entertainment Turned Weapon: How Cybercriminals Hide Advanced Malware in Popular Film Torrents
Impact· HIGH

Entertainment Turned Weapon: How Cybercriminals Hide Advanced Malware in Popular Film Torrents

In September 2026, Kaspersky's Global Research and Analysis Team uncovered a sophisticated multi-stage malware campaign targeting individuals and organizations through compromised torrent files disguised as popular films including The Odyssey. Active since mid-August 2026, the attack affected hundreds of victims across Russia, Turkey, Japan, Kenya, Uganda, Colombia, and several European countries. The malware employs advanced evasion techniques including sandbox detection, UAC bypass, and uses the Solana blockchain for command-and-control infrastructure resilience, ultimately providing attackers with persistent remote access to compromised systems. This incident highlights the evolving sophistication of malware distribution campaigns that exploit legitimate entertainment content as attack vectors. The combination of social engineering through popular media, advanced technical evasion capabilities, and blockchain-based infrastructure represents a concerning trend in cybercrime operations that traditional security measures may struggle to detect and mitigate effectively.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
BigCommerce Ribon App Breach: How Third-Party Integrations Became the New Attack Vector
Impact· MEDIUM

BigCommerce Ribon App Breach: How Third-Party Integrations Became the New Attack Vector

In September 2026, attackers compromised credentials for Ribon third-party applications on the BigCommerce platform, operated by Be A Part Of (a Fastr company). Between September 13-17, the threat actors used stolen API keys to inject malicious scripts into merchant storefronts and access customer data including names, email addresses, phone numbers, and shipping addresses. BigCommerce immediately removed the compromised applications and notified affected merchants, with companies like Master of Malt confirming exposure of shopper information. While BigCommerce's core platform remained secure, the incident demonstrates the expanding attack surface created by third-party integrations in e-commerce ecosystems. This supply chain compromise highlights the growing trend of attackers targeting less-secured vendor applications to reach high-value customer databases, particularly as organizations increasingly rely on SaaS integrations for enhanced functionality.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Abandoned CDN Domain Hijack Exposes Supply Chain Blind Spot in Thousands of Websites
Impact· HIGH

Abandoned CDN Domain Hijack Exposes Supply Chain Blind Spot in Thousands of Websites

In July 2025, an abandoned Content Delivery Network (CDN) domain was re-registered by an unknown actor, creating a massive supply chain vulnerability affecting thousands of websites. The original CDN service had been discontinued years earlier, but its domain was allowed to expire while thousands of sites maintained hardcoded references to resources hosted under that domain. The new domain owner gained wildcard DNS control, enabling them to serve arbitrary content to any website still calling the abandoned hostnames. This incident mirrors the June 2024 polyfill.io compromise, where over 110,000 websites were affected when that JavaScript library domain changed ownership and began serving malicious redirects to mobile visitors. This incident highlights the growing threat of supply chain attacks targeting client-side dependencies and third-party resources. As organizations increasingly rely on external CDNs and JavaScript libraries, abandoned domains represent a significant blind spot in traditional security scanning and dependency management approaches.

6 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical WordPress Plugin Flaw Enables Mass Web Shell Deployment Campaign
Impact· CRITICAL

Critical WordPress Plugin Flaw Enables Mass Web Shell Deployment Campaign

Threat actors are actively exploiting CVE-2026-27540, a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin with over 6,000 installations. The flaw allows unauthenticated attackers to upload arbitrary PHP files through missing file type validation in the wwlc_file_upload_handler AJAX action. Wordfence has blocked over 100,000 exploit attempts since June 2026, with attackers successfully deploying web shells that enable remote code execution and complete site takeover. The vulnerability affects all plugin versions up to 2.0.3.1 and demonstrates how supply chain weaknesses in popular plugins can create widespread attack surfaces. This incident reflects the growing threat to WordPress ecosystems as attackers increasingly target plugin vulnerabilities to achieve mass compromise across thousands of websites simultaneously, highlighting the urgent need for better third-party component security.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WordPress Under Fire: CVE-2026-27540 Plugin Flaw Enables Mass Webshell Attacks
Impact· CRITICAL

WordPress Under Fire: CVE-2026-27540 Plugin Flaw Enables Mass Webshell Attacks

In September 2026, security researchers identified active exploitation of CVE-2026-27540, a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin. The flaw allows unauthenticated attackers to upload PHP webshells through an exposed AJAX action, enabling complete site compromise. Wordfence reported blocking over 100,000 exploitation attempts, with attack spikes occurring between June and August 2026. The vulnerability affects versions 2.0.3.1 and older of the premium plugin, which was patched in version 2.0.3.2 released in February 2026. This incident highlights the ongoing threat landscape targeting WordPress ecosystems, where third-party plugin vulnerabilities continue to provide attack vectors for cybercriminals seeking to establish persistent access to websites for malicious purposes including data theft and further payload deployment.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Account Recovery Becomes the New Attack Path as MFA Strengthens Defenses
Impact· CRITICAL

Account Recovery Becomes the New Attack Path as MFA Strengthens Defenses

Multi-factor authentication has significantly raised the cost of account takeover attacks, forcing threat actors to pivot toward alternative attack vectors. Cybercriminal groups like Scattered Spider are increasingly targeting account recovery processes, using social engineering to manipulate help desk staff into resetting passwords and transferring MFA tokens to attacker-controlled devices. High-profile incidents include the 2025 Marks & Spencer breach, where attackers impersonated an employee to trick a third-party contractor into resetting credentials, ultimately deploying ransomware and causing an estimated £300 million in damages. This trend represents a fundamental shift in attack methodology, where the security of accounts depends less on MFA technology and more on the processes used to reset authentication factors. The emergence of account recovery as a primary attack vector reflects the evolving threat landscape where traditional credential theft methods are becoming less effective. As organizations strengthen their authentication mechanisms with phishing-resistant factors and conditional access controls, attackers are adapting by targeting the human elements of identity management processes.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA's September 2026 KEV Update: Four Critical Vulnerabilities Under New Federal Mandate
Impact· CRITICAL

CISA's September 2026 KEV Update: Four Critical Vulnerabilities Under New Federal Mandate

On September 8, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including critical flaws in Adobe Commerce/Magento (CVE-2026-75650), Microsoft Windows (CVE-2026-81963, CVE-2026-85880), and N-able N-central (CVE-2026-86218). These vulnerabilities enable template injection attacks, privilege escalation through link following, heap-based buffer overflow exploitation, and static code injection in management platforms. The additions coincide with the new Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize remediation of high-risk vulnerabilities that grant total system control post-exploitation. This incident reflects the ongoing evolution of vulnerability management from traditional patch-all approaches to risk-based prioritization, driven by increasingly sophisticated threat actors who rapidly weaponize disclosed vulnerabilities against internet-exposed infrastructure and enterprise management platforms.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
StyleSmuggler Attack: How CVE-2026-75650 Exposes Critical E-Commerce Security Gaps
Impact· CRITICAL

StyleSmuggler Attack: How CVE-2026-75650 Exposes Critical E-Commerce Security Gaps

In September 2026, Adobe disclosed CVE-2026-75650, dubbed 'StyleSmuggler,' a critical remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source platforms. The vulnerability, scoring a maximum CVSS of 10.0, allows unauthenticated attackers to inject PHP code through Magento's email template engine and execute arbitrary commands by triggering payment failure reminder emails. Active exploitation began on September 4, 2026, with threat actors deploying Rust-based Linux backdoors and PHP web shells on compromised e-commerce storefronts worldwide. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog within 24 hours of disclosure, emphasizing the severity and widespread targeting of unpatched Magento installations. This incident highlights the critical security risks facing e-commerce platforms as attackers increasingly target template injection vulnerabilities in widely-deployed content management systems. With millions of online stores running vulnerable Magento versions and the rise of automated exploitation frameworks, organizations must prioritize rapid patching and comprehensive security monitoring for their web applications.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports