✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Retail Industry
Breach intelligence, attack campaigns, and threat reports targeting the Retail Industry sector.
Explore Other Sectors
Retail Industry Threat Reports
Cordial and Snarky Spider's Rapid Data Theft and Extortion Attacks
In October 2025, two financially motivated threat groups, Cordial Spider and Snarky Spider, affiliated with The Com, initiated a series of rapid data theft and extortion attacks targeting U.S.-based organizations across sectors such as academia, aviation, retail, hospitality, automotive, financial services, legal, and technology. Utilizing voice-phishing and social engineering tactics, these groups directed employees to fraudulent single sign-on (SSO) pages to capture credentials, enabling them to infiltrate identity platforms and traverse SaaS environments. Once inside, they removed existing multi-factor authentication (MFA) devices, established their own, and deleted alerts to conceal their activities, leading to significant data exfiltration and extortion demands, often in the seven-figure range. This incident underscores a growing trend of cybercriminals leveraging sophisticated social engineering techniques to exploit identity systems, highlighting the urgent need for organizations to enhance their security measures against such evolving threats.
2 months ago
Kill Chain
BlackFile Extortion Group's Vishing Attacks on Retail and Hospitality
In February 2026, the BlackFile extortion group initiated a series of data theft and extortion attacks targeting retail and hospitality organizations. Employing voice phishing (vishing) tactics, they impersonated corporate IT helpdesk staff to deceive employees into divulging credentials. With these credentials, the attackers accessed systems like Salesforce and SharePoint, exfiltrated sensitive data, and demanded seven-figure ransoms. The group also engaged in swatting to pressure victims further. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai)) This incident underscores the evolving sophistication of social engineering attacks, particularly vishing, in the retail and hospitality sectors. The BlackFile group's methods highlight the critical need for organizations to enhance their security awareness training and implement robust authentication measures to mitigate such threats.
3 months ago
Kill Chain
BlackFile's Vishing Attacks: A Wake-Up Call for Retail and Hospitality Sectors
In early 2026, the BlackFile extortion group initiated a series of data theft and extortion attacks targeting retail and hospitality organizations. Employing voice phishing (vishing) tactics, they impersonated IT support staff to deceive employees into divulging credentials and one-time passcodes. With these credentials, BlackFile registered their own devices to bypass multi-factor authentication, escalated access to executive accounts, and exfiltrated sensitive data from platforms like Salesforce and SharePoint. The stolen data was then used to pressure victims into paying seven-figure ransoms, with threats of public disclosure on their dark web leak site. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai)) This incident underscores a significant shift in cybercriminal tactics, highlighting the increasing prevalence of vishing attacks that exploit human vulnerabilities rather than technical system flaws. The success of such social engineering methods emphasizes the need for organizations to enhance employee training and implement robust verification protocols to mitigate similar threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai))
3 months ago
Kill Chain
Scattered Spider Hacker Arrested in Finland Faces U.S. Charges
In April 2026, a 19-year-old dual U.S. and Estonian citizen, known online as "Bouquet," was arrested at Helsinki Airport in Finland while attempting to board a flight to Japan. U.S. federal prosecutors have charged him with wire fraud, conspiracy, and computer intrusion, alleging his involvement in at least four cyberattacks orchestrated by the Scattered Spider hacking group. These attacks, dating back to March 2023, targeted multiple large corporations, resulting in millions of dollars in ransom payments and significant operational disruptions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-reportedly-charges-scattered-spider-hacker-arrested-in-finland/?utm_source=openai)) This arrest underscores the persistent threat posed by cybercriminal groups like Scattered Spider, which employ sophisticated social engineering tactics to infiltrate organizations. The incident highlights the critical need for robust cybersecurity measures, including advanced threat detection and employee training, to mitigate the risks associated with such attacks.
2 months ago
Kill Chain
Rituals Data Breach 2026: Safeguarding Customer Information
In April 2026, Dutch cosmetics company Rituals experienced a data breach affecting its 'My Rituals' membership database. Unauthorized parties accessed and downloaded personal information, including full names, email addresses, phone numbers, dates of birth, gender, and home addresses. Notably, no passwords or payment information were compromised. The company promptly contained the breach, notified affected customers, and initiated a forensic investigation to prevent future incidents. This incident underscores the growing trend of cyberattacks targeting customer loyalty programs, which often house extensive personal data. Organizations must prioritize the security of such databases to mitigate risks associated with unauthorized access and potential misuse of personal information.
3 months ago
Kill Chain
NGate Malware Exploits HandyPay App to Steal NFC Payment Data
In April 2026, ESET researchers identified a new variant of the NGate malware targeting Android users in Brazil. This malware is embedded within a trojanized version of HandyPay, a legitimate NFC payment application. Once installed, the malicious app prompts users to set it as the default NFC payment application, requests their card PIN, and instructs them to tap their card on the device. The malware then captures and transmits the NFC payment data and PIN to attackers, enabling unauthorized transactions and ATM withdrawals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit trusted applications to distribute malware, highlighting the need for heightened vigilance among Android users regarding app sources and permissions. The use of generative AI in developing such malware indicates a concerning trend towards more sophisticated and accessible cyber threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data/?utm_source=openai))
3 months ago
Kill Chain
NGate Malware Exploits HandyPay App to Steal NFC Data in Brazil
In April 2026, ESET researchers identified a new variant of the NGate Android malware targeting users in Brazil. This malware abuses a legitimate application called HandyPay by injecting malicious code, likely generated with AI assistance. The campaign, active since November 2025, distributes the trojanized app through fake lottery websites and counterfeit Google Play pages. Once installed, the app prompts users to set it as the default NFC payment application, enter their payment card PIN, and tap their card against the device. The malware then relays the NFC data and PIN to attacker-controlled devices, enabling unauthorized contactless transactions and ATM withdrawals. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/21/3277653/0/en/eset-research-new-ngate-hides-in-nfc-payment-app-possibly-built-with-ai.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals, who are now leveraging AI-generated code to enhance malware capabilities and employing sophisticated social engineering techniques to distribute malicious applications. The focus on NFC payment data highlights the increasing targeting of mobile payment systems, necessitating heightened vigilance and security measures for both users and financial institutions. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/21/3277653/0/en/eset-research-new-ngate-hides-in-nfc-payment-app-possibly-built-with-ai.html?utm_source=openai))
3 months ago
Kill Chain
Seiko USA Website Defaced: Hackers Claim Customer Data Theft
In April 2026, Seiko USA's website was defaced by attackers who claimed to have breached the company's Shopify backend, exfiltrating sensitive customer data including names, email addresses, phone numbers, order histories, and shipping information. The attackers demanded a ransom, threatening to publicly release the stolen data if their demands were not met. Seiko USA has not publicly confirmed the breach, and the defaced content has since been removed from the website. This incident underscores the growing trend of cybercriminals targeting e-commerce platforms to access customer data, highlighting the critical need for robust security measures and prompt incident response strategies to protect sensitive information and maintain customer trust.
3 months ago
Kill Chain
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
In April 2026, cybersecurity analysts uncovered an underground guide titled 'The Underground Guide to Legit CC Shops: Cutting Through the Bullshit,' which provides insight into how cybercriminals evaluate and select stolen credit card marketplaces. The guide emphasizes a structured approach to vetting suppliers, focusing on factors such as operational longevity, data quality, transparency, and community validation to mitigate risks associated with scams and law enforcement infiltration. This discovery highlights the increasing sophistication and discipline within the cybercriminal ecosystem, as threat actors adopt more methodical strategies to ensure the reliability and security of their illicit operations. Understanding these evolving tactics is crucial for developing effective countermeasures and disrupting fraudulent activities in the digital landscape.
3 months ago
Kill Chain
JanaWare Ransomware: A Persistent Threat to Turkish Homes and SMBs
Since at least 2020, a localized ransomware campaign has been targeting individuals and small to medium-sized businesses (SMBs) in Turkey. The attackers employ phishing emails containing malicious Java archive files that, when executed, deploy a customized variant of the Adwind Remote Access Trojan (RAT). This malware disables security defenses and delivers a ransomware payload known as 'JanaWare,' which encrypts files and demands ransoms between $200 and $400. ([acronis.com](https://www.acronis.com/en/tru/posts/new-janaware-ransomware-targets-turkey-via-adwind-rat/?utm_source=openai)) The campaign's longevity and focus on smaller targets highlight a growing trend where cybercriminals opt for low-value, high-volume attacks. Such operations often evade detection and persist longer due to the limited cybersecurity resources of SMBs and the underreporting of smaller incidents. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/6-year-ransomware-campaign-turkish-homes-smbs/?utm_source=openai))
3 months ago
Kill Chain
Magento 2026: PolyShell Vulnerability Exploited in Credit Card Skimming Attacks
In April 2026, a significant cybersecurity incident targeted nearly 100 online stores utilizing the Magento e-commerce platform. Attackers exploited the 'PolyShell' vulnerability, a critical flaw in Magento's REST API, allowing unauthenticated remote code execution. By injecting malicious code into a 1x1-pixel SVG image within the websites' HTML, they deployed a sophisticated credit card skimmer. This skimmer intercepted checkout processes, presenting a fake 'Secure Checkout' overlay to customers, capturing their payment information, and exfiltrating it through encrypted channels. The campaign's stealthy nature and the widespread use of Magento made this attack particularly impactful. This incident underscores a growing trend of attackers leveraging zero-day vulnerabilities in widely used platforms to conduct large-scale data theft. The use of obfuscated code within seemingly benign elements like SVG images highlights the evolving sophistication of threat actors. Organizations must remain vigilant, ensuring timely patching and employing advanced detection mechanisms to mitigate such risks.
3 months ago
Kill Chain
Hasbro's 2026 Cyberattack: A Wake-Up Call for Corporate Cybersecurity
In late March 2026, Hasbro, Inc., a leading American toy and entertainment company, detected unauthorized access to its network. Upon discovery on March 28, the company promptly activated its security incident response protocols, implemented containment measures—including taking certain systems offline—and engaged third-party cybersecurity experts to investigate the breach. While essential business operations such as order processing and product shipping continued through business continuity plans, Hasbro cautioned that interim measures might persist for several weeks, potentially causing delays. The full scope of the incident, including whether sensitive data was compromised, remains under investigation. ([techcrunch.com](https://techcrunch.com/2026/04/01/hasbro-hacked-may-take-several-weeks-to-recover/?utm_source=openai)) This incident underscores the escalating threat landscape facing large corporations, particularly those with complex digital infrastructures. The attack on Hasbro highlights the critical importance of robust cybersecurity measures and incident response strategies to mitigate operational disruptions and protect sensitive information.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports