The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Retail Industry
Breach intelligence, attack campaigns, and threat reports targeting the Retail Industry sector.
Explore Other Sectors
Retail Industry Threat Reports
BlackFile's Vishing Attacks: A Wake-Up Call for Retail and Hospitality Sectors
In early 2026, the BlackFile extortion group initiated a series of data theft and extortion attacks targeting retail and hospitality organizations. Employing voice phishing (vishing) tactics, they impersonated IT support staff to deceive employees into divulging credentials and one-time passcodes. With these credentials, BlackFile registered their own devices to bypass multi-factor authentication, escalated access to executive accounts, and exfiltrated sensitive data from platforms like Salesforce and SharePoint. The stolen data was then used to pressure victims into paying seven-figure ransoms, with threats of public disclosure on their dark web leak site. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai)) This incident underscores a significant shift in cybercriminal tactics, highlighting the increasing prevalence of vishing attacks that exploit human vulnerabilities rather than technical system flaws. The success of such social engineering methods emphasizes the need for organizations to enhance employee training and implement robust verification protocols to mitigate similar threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/?utm_source=openai))
5 months ago
Kill Chain
Scattered Spider Hacker Arrested in Finland Faces U.S. Charges
In April 2026, a 19-year-old dual U.S. and Estonian citizen, known online as "Bouquet," was arrested at Helsinki Airport in Finland while attempting to board a flight to Japan. U.S. federal prosecutors have charged him with wire fraud, conspiracy, and computer intrusion, alleging his involvement in at least four cyberattacks orchestrated by the Scattered Spider hacking group. These attacks, dating back to March 2023, targeted multiple large corporations, resulting in millions of dollars in ransom payments and significant operational disruptions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-reportedly-charges-scattered-spider-hacker-arrested-in-finland/?utm_source=openai)) This arrest underscores the persistent threat posed by cybercriminal groups like Scattered Spider, which employ sophisticated social engineering tactics to infiltrate organizations. The incident highlights the critical need for robust cybersecurity measures, including advanced threat detection and employee training, to mitigate the risks associated with such attacks.
4 months ago
Kill Chain
Rituals Data Breach 2026: Safeguarding Customer Information
In April 2026, Dutch cosmetics company Rituals experienced a data breach affecting its 'My Rituals' membership database. Unauthorized parties accessed and downloaded personal information, including full names, email addresses, phone numbers, dates of birth, gender, and home addresses. Notably, no passwords or payment information were compromised. The company promptly contained the breach, notified affected customers, and initiated a forensic investigation to prevent future incidents. This incident underscores the growing trend of cyberattacks targeting customer loyalty programs, which often house extensive personal data. Organizations must prioritize the security of such databases to mitigate risks associated with unauthorized access and potential misuse of personal information.
5 months ago
Kill Chain
NGate Malware Exploits HandyPay App to Steal NFC Payment Data
In April 2026, ESET researchers identified a new variant of the NGate malware targeting Android users in Brazil. This malware is embedded within a trojanized version of HandyPay, a legitimate NFC payment application. Once installed, the malicious app prompts users to set it as the default NFC payment application, requests their card PIN, and instructs them to tap their card on the device. The malware then captures and transmits the NFC payment data and PIN to attackers, enabling unauthorized transactions and ATM withdrawals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit trusted applications to distribute malware, highlighting the need for heightened vigilance among Android users regarding app sources and permissions. The use of generative AI in developing such malware indicates a concerning trend towards more sophisticated and accessible cyber threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data/?utm_source=openai))
5 months ago
Kill Chain
NGate Malware Exploits HandyPay App to Steal NFC Data in Brazil
In April 2026, ESET researchers identified a new variant of the NGate Android malware targeting users in Brazil. This malware abuses a legitimate application called HandyPay by injecting malicious code, likely generated with AI assistance. The campaign, active since November 2025, distributes the trojanized app through fake lottery websites and counterfeit Google Play pages. Once installed, the app prompts users to set it as the default NFC payment application, enter their payment card PIN, and tap their card against the device. The malware then relays the NFC data and PIN to attacker-controlled devices, enabling unauthorized contactless transactions and ATM withdrawals. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/21/3277653/0/en/eset-research-new-ngate-hides-in-nfc-payment-app-possibly-built-with-ai.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals, who are now leveraging AI-generated code to enhance malware capabilities and employing sophisticated social engineering techniques to distribute malicious applications. The focus on NFC payment data highlights the increasing targeting of mobile payment systems, necessitating heightened vigilance and security measures for both users and financial institutions. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/21/3277653/0/en/eset-research-new-ngate-hides-in-nfc-payment-app-possibly-built-with-ai.html?utm_source=openai))
5 months ago
Kill Chain
Seiko USA Website Defaced: Hackers Claim Customer Data Theft
In April 2026, Seiko USA's website was defaced by attackers who claimed to have breached the company's Shopify backend, exfiltrating sensitive customer data including names, email addresses, phone numbers, order histories, and shipping information. The attackers demanded a ransom, threatening to publicly release the stolen data if their demands were not met. Seiko USA has not publicly confirmed the breach, and the defaced content has since been removed from the website. This incident underscores the growing trend of cybercriminals targeting e-commerce platforms to access customer data, highlighting the critical need for robust security measures and prompt incident response strategies to protect sensitive information and maintain customer trust.
5 months ago
Kill Chain
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
In April 2026, cybersecurity analysts uncovered an underground guide titled 'The Underground Guide to Legit CC Shops: Cutting Through the Bullshit,' which provides insight into how cybercriminals evaluate and select stolen credit card marketplaces. The guide emphasizes a structured approach to vetting suppliers, focusing on factors such as operational longevity, data quality, transparency, and community validation to mitigate risks associated with scams and law enforcement infiltration. This discovery highlights the increasing sophistication and discipline within the cybercriminal ecosystem, as threat actors adopt more methodical strategies to ensure the reliability and security of their illicit operations. Understanding these evolving tactics is crucial for developing effective countermeasures and disrupting fraudulent activities in the digital landscape.
5 months ago
Kill Chain
JanaWare Ransomware: A Persistent Threat to Turkish Homes and SMBs
Since at least 2020, a localized ransomware campaign has been targeting individuals and small to medium-sized businesses (SMBs) in Turkey. The attackers employ phishing emails containing malicious Java archive files that, when executed, deploy a customized variant of the Adwind Remote Access Trojan (RAT). This malware disables security defenses and delivers a ransomware payload known as 'JanaWare,' which encrypts files and demands ransoms between $200 and $400. ([acronis.com](https://www.acronis.com/en/tru/posts/new-janaware-ransomware-targets-turkey-via-adwind-rat/?utm_source=openai)) The campaign's longevity and focus on smaller targets highlight a growing trend where cybercriminals opt for low-value, high-volume attacks. Such operations often evade detection and persist longer due to the limited cybersecurity resources of SMBs and the underreporting of smaller incidents. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/6-year-ransomware-campaign-turkish-homes-smbs/?utm_source=openai))
5 months ago
Kill Chain
Magento 2026: PolyShell Vulnerability Exploited in Credit Card Skimming Attacks
In April 2026, a significant cybersecurity incident targeted nearly 100 online stores utilizing the Magento e-commerce platform. Attackers exploited the 'PolyShell' vulnerability, a critical flaw in Magento's REST API, allowing unauthenticated remote code execution. By injecting malicious code into a 1x1-pixel SVG image within the websites' HTML, they deployed a sophisticated credit card skimmer. This skimmer intercepted checkout processes, presenting a fake 'Secure Checkout' overlay to customers, capturing their payment information, and exfiltrating it through encrypted channels. The campaign's stealthy nature and the widespread use of Magento made this attack particularly impactful. This incident underscores a growing trend of attackers leveraging zero-day vulnerabilities in widely used platforms to conduct large-scale data theft. The use of obfuscated code within seemingly benign elements like SVG images highlights the evolving sophistication of threat actors. Organizations must remain vigilant, ensuring timely patching and employing advanced detection mechanisms to mitigate such risks.
5 months ago
Kill Chain
Hasbro's 2026 Cyberattack: A Wake-Up Call for Corporate Cybersecurity
In late March 2026, Hasbro, Inc., a leading American toy and entertainment company, detected unauthorized access to its network. Upon discovery on March 28, the company promptly activated its security incident response protocols, implemented containment measures—including taking certain systems offline—and engaged third-party cybersecurity experts to investigate the breach. While essential business operations such as order processing and product shipping continued through business continuity plans, Hasbro cautioned that interim measures might persist for several weeks, potentially causing delays. The full scope of the incident, including whether sensitive data was compromised, remains under investigation. ([techcrunch.com](https://techcrunch.com/2026/04/01/hasbro-hacked-may-take-several-weeks-to-recover/?utm_source=openai)) This incident underscores the escalating threat landscape facing large corporations, particularly those with complex digital infrastructures. The attack on Hasbro highlights the critical importance of robust cybersecurity measures and incident response strategies to mitigate operational disruptions and protect sensitive information.
5 months ago
Kill Chain
Magecart E-Skimmer Infections Reach Record Highs in 2025
In 2025, Magecart e-skimming attacks surged, compromising over 23 million online transactions across more than 10,500 unique infections. These attacks involved injecting malicious JavaScript into e-commerce checkout pages to steal payment data. The proliferation of full-stack e-skimmer kits and Malware-as-a-Service offerings enabled less technically skilled threat actors to execute large-scale compromises, significantly impacting the security of online merchants and consumers. ([recordedfuture.com](https://www.recordedfuture.com/resources/guides/annual-payment-fraud-intelligence-report-2025?utm_source=openai)) The industrialization of the fraud ecosystem, characterized by standardized attack tools and services, has lowered the barrier to entry for cybercriminals. This trend underscores the urgent need for financial institutions and e-commerce platforms to adopt proactive, intelligence-driven defenses to mitigate the escalating threat of payment fraud. ([recordedfuture.com](https://www.recordedfuture.com/resources/guides/annual-payment-fraud-intelligence-report-2025?utm_source=openai))
5 months ago
Kill Chain
Venom Stealer: The New Frontier in Automated ClickFix Attacks
In April 2026, a new malware-as-a-service (MaaS) platform named Venom Stealer emerged, automating the creation of persistent information-stealing attacks through ClickFix social engineering techniques. Developed by an individual known as 'VenomStealer,' this platform enables attackers to establish a continuous exfiltration pipeline, harvesting credentials, session cookies, and cryptocurrency wallets from victims. Unlike traditional infostealers, Venom Stealer remains active post-infection, continuously monitoring and exfiltrating new data, thereby undermining standard incident response measures. The commoditization of such advanced attack methods signifies a concerning evolution in cyber threats, making sophisticated social engineering tactics more accessible to a broader range of cybercriminals. Organizations must enhance their security awareness training and implement robust monitoring of outbound traffic to detect and prevent data exfiltration activities associated with these attacks.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports