The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Retail Industry
Breach intelligence, attack campaigns, and threat reports targeting the Retail Industry sector.
Explore Other Sectors
Retail Industry Threat Reports
Superbox Android TV Botnet: The Silent Takeover of Consumer Home Networks
In June-November 2025, thousands of Superbox Android TV streaming devices sold through major U.S. retailers were discovered to be covertly enrolled in a global botnet and residential proxy service, relaying internet traffic for cybercriminals without explicit user consent. Forensic analysis revealed pre-installed or required third-party apps that hijacked consumers’ networks for malware distribution, ad fraud, and account takeover campaigns, while redirecting connections to Chinese servers and proxy aggregation services. The incident drew attention from cyber intelligence firms, Google, and law enforcement as a major example of pre-compromised consumer IoT supply chain risk, with impacts ranging from individual privacy invasions to the widescale abuse of residential IP addresses for criminal operations. This breach highlights the accelerating trend of consumer IoT and smart devices being targeted for botnet recruitment and criminal proxy operations, often by exploiting unofficial app ecosystems and distribution channels. The case underscores mounting regulatory scrutiny, the complexity of securing home networks, and the growing need for device supply chain and east-west traffic visibility in both enterprise and residential environments.
8 months ago
Kill Chain
Logitech Suffers 2024 Data Breach from Clop Extortion Attack
In July 2024, Logitech, a leading global hardware accessory manufacturer, confirmed a data breach following a cyberattack orchestrated by the Clop ransomware group. The attackers exploited vulnerabilities in Oracle E-Business Suite, part of a broader wave of Clop extortion operations targeting organizations using the MOVEit Transfer and Oracle solutions. Sensitive customer and internal information was reportedly exfiltrated, as Clop leveraged data theft and extortion—rather than encrypting files—pressuring Logitech to pay ransom under threat of data publication. The breach has prompted Logitech to review its security protocols and notify affected stakeholders, though the full extent of the compromised data remains under investigation. This incident highlights the accelerating trend of data extortion attacks, where criminals target trusted enterprise software platforms to access valuable data at scale. Regulatory scrutiny around third-party risk, heightened focus on data handling, and the rise in ransomware-free extortion tactics make such incidents not only high-profile but pivotal for all organizations dependent on interconnected ecosystems.
8 months ago
Kill Chain
2024 Uhale Android Photo Frame Breach: Supply Chain Malware Risk
In mid-2024, security researchers discovered that popular Uhale-branded Android-based digital photo frames were shipping with critical security flaws, including a supply chain compromise whereby the devices automatically downloaded and executed malware upon boot. The attack exploited insecure system components and unauthorized code injection, allowing threat actors to remotely install and run arbitrary malware. As a result, affected users faced risks ranging from credential theft and device hijacking to involuntary participation in botnets, with downstream exposure to broader enterprise or home networks if connected. This incident comes amid a broader surge in supply chain attacks targeting IoT and smart devices, with attackers leveraging manufacturer or third-party vulnerabilities to pre-install malware before devices reach consumers. The event highlights the growing regulatory and operational scrutiny of supply chain security, emphasizing the urgent need for enhanced vendor risk management and enterprise device segmentation.
8 months ago
Kill Chain
Google Targets Smishing Triad: 2025 Lawsuit Disrupts Phishing-as-a-Service Operations
In November 2025, Google filed a landmark lawsuit in the Southern District of New York targeting the so-called "Smishing Triad," a China-based phishing-as-a-service group responsible for operating the Lighthouse phishing kit. This kit empowers cybercriminals to impersonate over 400 brands and conduct high-volume SMS attacks, luring victims worldwide into divulging payment information and one-time passcodes. Attackers leveraged the compromised data to enroll payment cards in mobile wallets on Apple and Google devices, allowing them to transact and cash out at scale. Google identified over a million victims in 120 countries, with Smishing Triad operators rotating up to 25,000 phishing domains in an eight-day window. The case highlights an increasing sophistication and industrialization of mobile phishing schemes, where threat actors utilize automation, rapid domain turnover, and collaboration across specialized roles. Legal escalation by a major tech company reflects growing efforts to disrupt cross-border cybercrime ecosystems that evade technical and regulatory countermeasures.
8 months ago
Kill Chain
Global Credit Card Fraud Rings Dismantled in Europol-Led €300M Operation
In 2024, international law enforcement agencies, coordinated by Europol, dismantled three interconnected credit card fraud and money laundering rings responsible for more than €300 million in losses, impacting 4.3 million cardholders worldwide across 193 countries. The sophisticated criminal groups orchestrated large-scale thefts using stolen and counterfeit credit card data, leveraging advanced technology and vast dark web networks to execute fraudulent transactions on a global scale. Their activities spanned several years, with victims spread across multiple financial institutions, highlighting significant vulnerabilities in payment security and international collaboration. The bust resulted in arrests, asset seizures, and cut off a major underground economy impacting consumers and businesses. This case illustrates the increasing scale and complexity of financially motivated cybercrime, as threat actors use digital platforms and cross-border tactics to avoid detection. Ongoing regulatory and industry attention to payment fraud and anti-money-laundering measures underscores the need for improved threat detection and international cooperation.
8 months ago
Kill Chain
Europe Hit by Massive NFC Relay Malware Attacks Targeting Payment Cards in 2024
In early 2024, cybersecurity researchers uncovered a sweeping campaign across Eastern Europe involving over 760 malicious Android apps leveraging NFC (Near-Field Communication) relay malware. Threat actors distributed these apps through unofficial channels, targeting unsuspecting users to intercept and relay credit card information during contactless transactions. Once installed, the malware exploited device-level NFC permissions to steal payment credentials, enabling attackers to commit significant financial fraud and undermine consumer trust in mobile payments. The primary impact has been large-scale theft from compromised cards, increased banking fraud, regulatory concern, and widespread consumer exposure. This incident signals a sharp escalation in mobile payment threats and demonstrates how sophisticated cybercriminals now target embedded hardware features. Organizations face new challenges in defending against evolving mobile malware, with compliance and security standards coming under increased scrutiny.
8 months ago
Kill Chain
CISA Adds Adobe/Magento & WSUS Exploits to 2025 KEV Catalog
In October 2025, CISA added two newly discovered, actively exploited vulnerabilities—CVE-2025-54236 impacting Adobe Commerce and Magento, and CVE-2025-59287 impacting Microsoft Windows Server Update Services—to its Known Exploited Vulnerabilities (KEV) Catalog. Both vulnerabilities are believed to be leveraged by threat actors to gain unauthorized access and facilitate lateral movements within victim networks. Federal Civilian Executive Branch (FCEB) agencies are now required by BOD 22-01 to remediate these specific threats by the mandated due date, minimizing risk to critical government infrastructure and mission-critical digital assets. This inclusion highlights a rising trend of attackers weaponizing public-facing application and misconfigured update service vulnerabilities, reflecting an escalation in both attack sophistication and speed of exploitation. Organizations of all types face mounting regulatory and operational pressure to harden security posture and accelerate remediation response times.
8 months ago
Kill Chain
Morocco’s 'Jingle Thief' Heist Shows Retailers’ Holiday Cyber Weaknesses
In late 2024, the retail sector was targeted by a Morocco-based cybercriminal operation dubbed 'Jingle Thief.' The attackers orchestrated a large-scale gift card fraud campaign by exploiting weaknesses in payment and e-commerce systems. Through phishing and the abuse of unencrypted and east-west traffic within retail networks, the adversaries accessed internal gift card management tools. The stolen gift card data was quickly monetized, resulting in fraudulent transactions and direct financial losses to multiple retailers during the lucrative holiday season. This incident underscores the urgent need for advanced segmentation, strong encryption of data in transit, and continuous network threat detection in retail environments. It also highlights an emerging trend of financially motivated attackers focusing on high-impact, low-resilience periods such as holiday shopping surges.
8 months ago
Kill Chain
How Chinese Gangs Engineered a $1B+ US Credit Card Fraud Wave via Smishing in 2025
In 2025, large-scale social engineering attacks targeted US consumers through smishing campaigns that impersonated legitimate institutions such as highway toll authorities and the US Postal Service. Orchestrated by Chinese criminal organizations, these fraudulent text messages lured victims into divulging their credit card details, which were then monetized to purchase goods via an elaborate scheme. Attackers leveraged the stolen card data by installing it into Google and Apple Wallets in Asia and facilitating cross-border purchases, enabling smooth, large-scale fraud amounting to over $1 billion across a three-year period. This case underscores a recent surge in sophisticated financial fraud campaigns that combine social engineering with digital payment ecosystems, exploiting global tech infrastructure and multi-region collaboration. The landscape sees continued pressure on organizations to safeguard payment and customer data against rapidly evolving threats.
8 months ago
Kill Chain
Global Smishing Triad Campaign: 194,000 Malicious Domains Power Massive Phishing Surge
In 2024, security researchers attributed a global smishing campaign to a threat group known as the Smishing Triad, which registered more than 194,000 malicious domains since January 1. Utilizing infrastructure predominantly registered through Hong Kong-based providers with Chinese nameservers, the actors orchestrated widespread phishing via SMS attacks targeting banking, logistics, and other sectors. Victims received highly targeted text messages that redirected them to credential-harvesting sites, leading to financial fraud and data compromise. The campaign’s scale and global reach underline the adversaries’ operational sophistication and heavy use of automation. This incident reflects a broader surge in phishing tactics leveraging SMS and vast domain infrastructure, bypassing traditional email security. The growing adoption of QR and mobile-first communication further widens the threat surface, putting regulatory and compliance emphasis on new vectors.
8 months ago
Kill Chain
SessionReaper in the Wild: How a 2025 Adobe Commerce Flaw Fueled E-Commerce Breaches
In early 2025, a critical security vulnerability (CVE-2025-54236) was discovered in Adobe Commerce, formerly known as Magento. This flaw, actively exploited in the wild as 'SessionReaper,' enables remote attackers to hijack user sessions on e-commerce sites, bypassing authentication controls. Attackers leveraged this weakness to compromise sensitive customer data, manipulate transactions, and disrupt online sales operations for affected merchants. The exploitation led to significant financial and reputational risks, prompting rapid incident response and emergency patching. This incident highlights the growing trend of sophisticated web application attacks targeting popular e-commerce platforms. As threat actors increasingly weaponize session hijacking techniques and exploit critical flaws pre-patch, organizations must prioritize timely vulnerability management and layered defenses to protect customer trust and regulatory compliance.
8 months ago
Kill Chain
Toys "R" Us Canada Faces Customer Data Leak in 2024 Breach
In late April 2024, Toys "R" Us Canada disclosed a data breach after threat actors exfiltrated and subsequently leaked customer records from its systems. The breach was confirmed via direct customer notifications, revealing that sensitive customer data—including names and contact details—was stolen and made public on a hacker forum. The company identified the security incident after discovering that attackers had gained unauthorized access and were able to access certain internal systems, leading to the data leak. Following the discovery, Toys "R" Us Canada initiated an investigation and notified the affected individuals, emphasizing that payment information was not compromised. This incident highlights a continued trend of cybercriminals targeting retail and e-commerce sectors for customer data theft and exposure. The breach exemplifies the increasing frequency of attacks leveraging stolen credentials or vulnerable infrastructure, underlining the urgent need for robust data protection and threat monitoring strategies across all consumer-facing organizations.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports