The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Retail Industry
Breach intelligence, attack campaigns, and threat reports targeting the Retail Industry sector.
Explore Other Sectors
Retail Industry Threat Reports
Zombie Card Attack Exposes Critical Flaw in Visa Contactless Payment Security
Researchers at the University of Massachusetts Amherst demonstrated a critical vulnerability in Visa contactless payment systems that allows attackers to revive expired credit cards for fraudulent transactions. The 'Zombie Card' attack exploits a cryptographic binding weakness in Visa's Kernel 3 EMV implementation, enabling attackers with physical access to expired cards and NFC relay equipment to modify expiration dates without breaking card cryptography. Testing across five major US banks showed one bank approved fraudulent transactions up to $500, while others either declined or failed the modification. The attack requires the original account to remain open and relies on issuers not independently verifying expiration dates during authorization, exposing fundamental flaws in contactless payment security architecture. This vulnerability highlights the growing sophistication of payment card fraud techniques as contactless transactions become mainstream, with researchers identifying similar NFC relay malware like WindRelay actively targeting victims across Europe, demonstrating that theoretical academic research quickly translates into real-world criminal exploitation.
1 month ago
Kill Chain
SafePal Data Exposure Incident: A Wake-Up Call for Crypto Security
In August 2026, SafePal, a hardware wallet manufacturer, disclosed a security incident where an authorization flaw in an order-tracking plug-in exposed personal information of approximately 39,798 customers. The compromised data included names, email addresses, shipping addresses, phone numbers, and purchase details. Importantly, wallet credentials and financial information remained secure. The vulnerability affected orders placed between March 2, 2025, and April 11, 2026. SafePal has since addressed the flaw, notified affected customers, and implemented additional security measures to prevent future incidents. This incident underscores the critical importance of securing customer data, especially in the cryptocurrency sector, where trust and security are paramount. It highlights the need for continuous monitoring and updating of third-party integrations to prevent unauthorized access and data breaches.
1 month ago
Kill Chain
WindRelay Malware: A New Threat to Contactless Payments
In August 2026, cybersecurity researchers identified 'WindRelay,' a novel Android malware that exploits Near Field Communication (NFC) technology to facilitate contactless payment fraud. The attack begins with social engineering tactics, where victims are deceived into installing a Remote Access Trojan (RAT) named SpyNote. This RAT enables attackers to remotely deploy the WindRelay malware onto the victim's device. Once installed, WindRelay transforms the compromised smartphone into an unauthorized NFC relay, capturing live card data when victims are manipulated into tapping their payment cards against their own infected devices. This data is then transmitted in real-time to fraudsters, who use it to perform unauthorized transactions at payment terminals. The campaign has primarily targeted individuals in Czechia, Slovakia, and Slovenia, with at least 23 samples of WindRelay identified between November 2025 and July 2026. This incident underscores a significant evolution in mobile payment fraud, combining advanced malware capabilities with sophisticated social engineering to exploit NFC technology. The emergence of WindRelay highlights the increasing sophistication of cybercriminals in leveraging mobile technologies for financial fraud. As NFC-based payment systems become more prevalent, the risk of similar attacks is likely to rise, emphasizing the need for enhanced security measures and user awareness to mitigate such threats.
1 month ago
Kill Chain
Immediate Action Required: SAP Commerce Cloud CVE-2026-58231 Exploited Days After Patch Release
In August 2026, SAP Commerce Cloud was found to have a critical vulnerability, CVE-2026-58231, rated 10.0 on the CVSS scale. This flaw allows unauthenticated attackers to exploit default authentication clients and submit specially crafted inputs to functions lacking sufficient validation, potentially leading to arbitrary code execution and compromising internal components. Exploitation attempts were detected just three days after the patch release, indicating rapid targeting by threat actors. The swift exploitation of CVE-2026-58231 underscores the increasing speed at which cyber adversaries are capitalizing on newly disclosed vulnerabilities. Organizations must prioritize timely patching and implement robust security measures to mitigate risks associated with such critical flaws.
1 month ago
Kill Chain
Critical Adobe Commerce Vulnerability CVE-2026-71362: Immediate Action Required
In August 2026, a critical vulnerability (CVE-2026-71362) was identified in Adobe's Commerce and Magento platforms, allowing unauthenticated attackers to hijack customer accounts. The flaw, stemming from improper handling of customer identity in session management, enabled unauthorized access to sensitive customer data. Security firm Sansec reported active exploitation attempts, emphasizing the urgency for immediate patching. This incident underscores the persistent threat posed by web application vulnerabilities, highlighting the necessity for robust session management and prompt application of security updates to protect customer information and maintain trust.
1 month ago
Kill Chain
Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231
In August 2026, SAP released patches to address a critical vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter. This flaw, rated 10.0 on the CVSS scale, allows unauthenticated attackers to exploit default authentication clients and submit specially crafted inputs to functions lacking sufficient validation. Successful exploitation could lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the application. This incident underscores the ongoing risks associated with insufficient authorization checks and input validation in enterprise applications. Organizations must prioritize timely patch management and implement robust security measures to mitigate such vulnerabilities.
1 month ago
Kill Chain
Levi Strauss 2026 Cyberattack: A Social Engineering Case Study
In August 2026, Levi Strauss & Co. disclosed a cybersecurity incident where attackers employed social engineering tactics to compromise three employees' computers, leading to the exfiltration of corporate data. The company acted swiftly to contain the breach, ensuring that consumer data remained unaffected and business operations continued without disruption. While no specific threat actor has claimed responsibility, some reports suggest a potential link to UNC6671, known for sophisticated voice phishing campaigns targeting corporate environments. This incident underscores the evolving threat landscape where social engineering attacks are becoming increasingly prevalent. Organizations must bolster their defenses against such tactics, emphasizing employee training and robust security protocols to mitigate risks associated with human-centric attack vectors.
1 month ago
Kill Chain
Critical Vulnerability in Watchfire Controller Software: CVE-2026-5846
In July 2026, a critical vulnerability (CVE-2026-5846) was identified in Watchfire Controller Software versions BC550 12.30, BC750 11.33 and 12.35, BC760 12.38 and 13.00, and BC760DC 12.39. This flaw involved the use of hard-coded RSA private keys and corresponding X.509 certificates embedded in the firmware, which could allow malicious actors to deliver unauthorized firmware updates and gain full control over the affected controllers. The vulnerability was reported by James Tillson to CISA, leading to the issuance of security patches by Watchfire to mitigate the risk. The incident underscores the ongoing challenges in securing embedded systems within critical infrastructure sectors such as Commercial Facilities, Critical Manufacturing, Healthcare, and Financial Services. It highlights the necessity for organizations to regularly update and audit their systems to prevent exploitation of such vulnerabilities.
1 month ago
Kill Chain
H96 TV Streaming Devices Exploited for Ad Fraud in 2026
In July 2026, security researchers uncovered that H96 TV streaming devices were being exploited to conduct large-scale ad fraud. These devices, manufactured by Zhejiang Fengwo IoT Technology Ltd, were found to spoof themselves as mobile phones, clicking on ads hosted on AI-generated websites operated by the Fengwo Group. This operation not only defrauded online merchants and advertising networks but also compromised user privacy by collecting hardware information and installed apps from tens of thousands of devices globally. This incident highlights the growing trend of cybercriminals leveraging Internet of Things (IoT) devices for fraudulent activities. As IoT adoption increases, the potential attack surface expands, necessitating enhanced security measures and consumer awareness to mitigate such threats.
1 month ago
Kill Chain
Fastjson CVE-2026-16723: Critical RCE Vulnerability Under Active Exploitation
In July 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-16723, was discovered in Alibaba's Fastjson library versions 1.2.68 through 1.2.83. This flaw allows unauthenticated attackers to execute arbitrary code in applications using the vulnerable library, particularly those deployed as Spring Boot executable fat-JARs. The vulnerability is exploitable under Fastjson's default configuration, without the need for enabling AutoType or the presence of specific gadget classes. Active exploitation has been observed, primarily targeting U.S.-based organizations across sectors such as Financial Services, Healthcare, Computing, and Retail. ([imperva.com](https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/?utm_source=openai)) The absence of a patch for Fastjson 1.x, which is no longer actively maintained, underscores the urgency for organizations to mitigate this risk. The exploitation of this vulnerability highlights the critical need for timely software updates and the adoption of secure coding practices to prevent similar attacks in the future.
1 month ago
Kill Chain
Europol's Crackdown on 'The Com' Network: 4,340 URLs Flagged for Removal
Between June and July 2026, Europol coordinated 'Referral Action Days' involving investigators from nine countries to target 'The Com,' a decentralized network of nihilistic violent extremist groups. This operation led to the identification and referral of 4,340 URLs containing content that promotes self-harm, child sexual exploitation, and violent attacks. The initiative aimed to disrupt The Com's online ecosystem and limit the dissemination of extremist propaganda. This crackdown underscores the persistent threat posed by decentralized extremist networks exploiting online platforms to radicalize and victimize individuals, particularly minors. The operation highlights the necessity for continuous international collaboration to monitor and mitigate the spread of such harmful content.
2 months ago
Kill Chain
Chick-fil-A Data Breach 2026: Credential Stuffing Attack Compromises Customer Accounts
In June 2026, Chick-fil-A experienced a credential stuffing attack targeting its website and mobile application. Between June 17 and June 19, unauthorized parties used previously compromised credentials to access Chick-fil-A One loyalty accounts. The breach exposed sensitive customer information, including names, email addresses, membership numbers, mobile pay numbers, partial payment card digits, and potentially birth dates, phone numbers, and addresses. In total, 13,322 individuals were affected across multiple states. Chick-fil-A responded by logging out impacted accounts, removing stored payment methods, restoring account balances, and issuing additional rewards to affected customers. This incident underscores the persistent threat of credential stuffing attacks, which exploit reused or compromised credentials to gain unauthorized access to user accounts. The recurrence of such attacks highlights the critical need for organizations to implement robust security measures, including mandatory multi-factor authentication and proactive monitoring, to protect customer data and maintain trust.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports