The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Retail Industry
Breach intelligence, attack campaigns, and threat reports targeting the Retail Industry sector.
Explore Other Sectors
Retail Industry Threat Reports
Over 250 Magento Stores Breached Overnight Through Critical Adobe Commerce Flaw
In October 2025, over 250 Magento and Adobe Commerce online stores were compromised in less than 24 hours after attackers exploited a newly disclosed critical vulnerability, CVE-2025-54236 (CVSS 9.1). The flaw, stemming from improper input validation, allowed threat actors to compromise e-commerce shops directly via their web applications, enabling unauthorized access, data exfiltration, and potential payment card theft. Security researchers observed an automated wave of exploitation attempts soon after public disclosure, underlining how rapidly threat actors weaponize emerging vulnerabilities for financial gain and to cause operational disruption. This incident highlights the urgent need for rapid patch management and layered web application defenses, as attackers increasingly leverage zero-day and recently disclosed vulnerabilities to target widely used commerce platforms, further increasing risks to consumer data and regulatory compliance for online retailers.
8 months ago
Kill Chain
Jingle Thief: How Hackers Exploited Cloud to Steal Millions in Retail Gift Cards (2025)
In October 2025, a cybercriminal group known as Jingle Thief orchestrated a sophisticated financial fraud campaign targeting retail and consumer services organizations operating in cloud environments. Leveraging phishing and smishing tactics to obtain employee credentials, the attackers gained access to cloud-based systems responsible for managing digital gift card issuance. Once inside, they exploited weak east-west traffic controls and lack of adequate segmentation to move laterally and automate gift card theft at scale, resulting in losses worth millions of dollars and significant operational disruption to affected businesses. This incident highlights an ongoing escalation in targeted cloud infrastructure attacks, especially towards retail functions involving financial assets like digital gift cards. The use of cloud-native attack vectors and credential phishing underscores the urgency for enhanced zero trust practices, robust detection controls, and strict policy enforcement to protect sensitive assets in distributed environments.
8 months ago
Kill Chain
Mideast & African Hackers Launch Multi-Vector Attacks on Governments, Banks, and Retailers in 2024
In early 2024, multiple threat groups originating from the Middle East and Africa executed a series of sophisticated, multi-vector cyber campaigns targeting government agencies, banks, and small to midsize retailers across the region. Attackers leveraged a blend of techniques including encrypted traffic evasion, lateral movement, cloud misconfiguration, and remote access tools. These campaigns exploited gaps in east-west security, egress controls, and cloud segmentation, resulting in data exfiltration, service disruptions, and operational downtime across multiple sectors. The tactics exposed critical weaknesses in hybrid cloud architectures, impacting regulatory compliance and eroding trust in public and financial institutions. This incident highlights the escalating trend of advanced regional threat actors targeting not just political or large economic entities, but also smaller businesses, using methods that combine traditional and cloud-native attack vectors. The frequency and sophistication of such attacks underscore the need for adaptive, zero trust security frameworks and heightened vigilance across both public and private sectors.
8 months ago
Kill Chain
Critical SessionReaper Flaw Exploited in Adobe Magento: 2025 Breach Analysis
In June 2025, a critical vulnerability known as SessionReaper (CVE-2025-54236) was exploited by cybercriminals targeting Adobe Magento (Adobe Commerce) platforms. Attackers leveraged the web application flaw to hijack user sessions and gain unauthorized access to sensitive online store environments. Hundreds of exploitation attempts were recorded within days of public disclosure, with threat actors using automated tools to scan, identify, and compromise unpatched Magento installations. The breaches exposed customer data, payment information, and threatened e-commerce operations for businesses relying on the affected platform. This incident stands out due to the speed of threat actor mobilization and highlights a broader trend of mass targeting critical web application bugs in widely used platforms. With compliance frameworks under increased scrutiny and evolving ransomware threats, rapid patch management has become a top priority for e-commerce and cloud-driven organizations.
8 months ago
Kill Chain
Jingle Thief: A 2024 Look at Cloud Gift Card Fraud in Retail
In early 2024, security researchers uncovered "Jingle Thief," a sophisticated cybercriminal campaign targeting major retail organizations through coordinated phishing and smishing attacks. The attackers leveraged credential harvesting to gain unauthorized, persistent access to enterprise cloud environments and exploited multicloud weaknesses to orchestrate large-scale, automated gift card fraud. This activity resulted in the theft of significant monetary value from targeted retailers and demonstrated the evolving tactics of financially motivated threat groups seeking to exploit cloud infrastructure and weak east-west security controls. Jingle Thief underscores an alarming trend: attackers increasingly exploit cloud misconfigurations and multifactor authentication gaps to maintain post-compromise access for extended periods. The campaign exemplifies the need for enterprises to adopt Zero Trust strategies and rigorous east-west segmentation as criminals shift focus toward cloud-native targets.
8 months ago
Kill Chain
Muji Halts Online Sales After Supply Chain Ransomware Hits Logistics Partner
In June 2024, Japanese retail giant Muji was forced to suspend its online sales after a logistics outage caused by a ransomware attack on Askul, its major delivery partner. The incident was triggered when attackers compromised Askul's systems, encrypting critical operational data and disrupting supply chain operations. As a result, Muji's ability to fulfill customer orders was severely impacted, highlighting the downstream risk associated with third-party vendors in an interconnected retail ecosystem. This breach not only halted Muji's core e-commerce activities but also underscored the vulnerability of global supply chains to cyber extortion. This event is particularly relevant as ransomware groups increasingly leverage supply chain attacks to maximize disruption and extort multiple victims. It reflects a rapid evolution in attacker tactics, where targeting essential providers amplifies business risk, and regulatory scrutiny on supply chain resilience continues to intensify.
8 months ago
Kill Chain
MANGO Data Breach 2024: Third-Party Vendor Incident Exposes Customer Data
In April 2024, Spanish fashion retailer MANGO reported that a data breach exposed customer personal information after one of its marketing vendors was compromised. The incident came to light when MANGO began notifying affected customers, stating that data such as names, contact details, and potentially other identifiers had been accessed without authorization. The intrusion was possible due to attackers breaching the marketing service provider’s environment, reflecting a concerning third-party risk. MANGO responded by collaborating with the vendor, investigating the incident, notifying authorities, and reinforcing security controls. This breach underscores a growing trend in supply-chain attacks where threat actors exploit weaker security in trusted partners. It highlights the urgent need for stringent vendor management, robust segmentation, and continuous monitoring, especially as regulatory focus intensifies on safeguarding consumer data throughout the supply chain.
8 months ago
Kill Chain
Bling Libra’s 2024 Extortion: Lessons from a Modern Ransomware Attack
In early 2024, a cybercriminal alliance known as Bling Libra—aligned with the notorious Scattered Spider and Lapsus$—launched coordinated extortion campaigns targeting retail and hospitality organizations worldwide. Using a mixture of credential theft, social engineering, and advanced lateral movement, attackers bypassed security controls to gain privileged access to sensitive systems, disrupted operations, and exfiltrated confidential data. Victims faced steep ransom demands and public threats of data disclosure if payments were not met, resulting in loss of business continuity, reputational harm, and regulatory scrutiny. This incident highlights the mounting prevalence of extortion-based tactics that leverage both data theft and operational disruption. Organizations across multiple industries are now seeing an increase in sophisticated, multi-stage attacks fueled by agile, loosely affiliated threat actor groups determined to exploit gaps in cyber defenses.
8 months ago
Kill Chain
FBI Disrupts BreachForums Data Extortion Portal Tied to Salesforce Attacks
In October 2025, the FBI, in collaboration with French authorities, seized the BreachForums portal used by the ShinyHunters and associated groups as a data leak extortion site in the wake of major Salesforce data theft attacks. The cybercriminals, operating as Scattered Lapsus$ Hunters, leveraged the platform to pressure prominent organizations—including FedEx, Disney, Google, and others—by threatening to leak over a billion customer records unless ransom demands were met. While the clearnet site is now under law enforcement control, the attackers continue extortion efforts via their dark web presence, asserting that Salesforce campaign leaks will proceed for non-compliance. This incident underscores evolving methods of data extortion and the resilience of threat actors despite law enforcement crackdowns. It highlights the growing trend of targeting SaaS providers, the strategic use of underground forums for large-scale data extortion, and the ongoing cat-and-mouse dynamic between cybercriminals and authorities.
8 months ago
Kill Chain
Storm-1175 Exploits GoAnywhere Zero-Day to Orchestrate Ransomware Attacks in 2024
In September 2024, Microsoft Threat Intelligence announced that Storm-1175, a financially motivated ransomware affiliate, exploited a critical zero-day vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT file transfer solution. Attackers gained remote code execution, established persistence via remote monitoring tools and web shells, performed lateral movement using legitimate Windows utilities, and exfiltrated data with Rclone before deploying Medusa ransomware in targeted organizations. Impacted sectors included transportation, education, retail, insurance, and manufacturing. The initial compromises began on September 11, days before the vulnerability was publicly disclosed or patched, giving attackers a significant advantage and facilitating stealthy, high-impact breaches due to delayed vendor transparency. This incident highlights the escalating sophistication of ransomware operations leveraging zero-day exploits and legitimate IT tools to evade detection, resulting in substantial business disruption and data loss. Growing regulatory scrutiny and industry concern underscore the urgent need for rapid threat intelligence sharing, proactive zero trust measures, and improved vendor communication in light of similar recent attacks.
8 months ago
Kill Chain
Salesforce 2025 Supply Chain Data Breach: An Executive Overview
In 2025, Salesforce and hundreds of its customers were targeted in two coordinated data theft campaigns by the threat group "Scattered Lapsus$ Hunters," leveraging both social engineering and stolen OAuth tokens. Attackers tricked employees into connecting malicious OAuth applications or exploited compromised Salesloft Drift tokens, gaining unauthorized access to sensitive CRM data, support tickets, credentials, and authentication tokens. The attackers subsequently attempted to extort 39 major organizations, threatening to leak up to 1.5 billion records via a dark web leak site unless sizable ransom demands were met. Salesforce publicly refused to negotiate or pay any ransom, and law enforcement actions appeared to subsequently seize the extortion domain. This incident underscores the growing sophistication of supply-chain attacks using identity-based and OAuth token compromise, highlighting the rising risk to SaaS ecosystems. The event triggered significant concerns across industries that increasingly rely on interconnected third-party platforms and further emphasizes urgent gaps in SaaS security, zero trust application governing, and lateral movement prevention.
8 months ago
Kill Chain
How Qilin Ransomware Disrupted Asahi’s Breweries in 2025
In late September 2025, Japanese beer giant Asahi fell victim to a major ransomware attack attributed to the Qilin cybercrime group. The attack began on September 29, disabling operations at six of Asahi's Japan-based breweries and resulting in the suspension of production for their flagship and other beer labels. Investigation confirmed that the attackers exfiltrated approximately 27GB of sensitive data, including internal financial documents, employee ID records, and confidential contracts. Qilin publicly claimed responsibility after failed ransom negotiations, leaking data and amplifying operational impacts. The incident forced Asahi to adopt manual processes, delaying product launches and potentially causing an estimated $335 million in financial losses. This breach underscores a persistent and rising trend of ransomware actors targeting large manufacturers by exploiting vulnerable edge devices and employing data theft for leverage. The Qilin group’s evolving tactics—linked to both organized cybercrime and nation-state affiliates—reflect the growing complexity of ransomware risks facing critical supply chain and manufacturing sectors in 2025.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports