Company News • 14.01.2015

Number of cyber attacks on retailers drops by half

Despite an 50 percent decline in the number of cyber attacks against U.S. retailers, the number of records stolen from them remains at near record highs. IBM Security researchers report that in 2014, cyber attackers still managed to steal more than 61 million records from retailers despite the decline in attacks, demonstrating cyber criminal's increasing sophistication and efficiency.

Contrary to what most would expect, the majority of cyber attackers scaled back their hacking efforts around Black Friday and Cyber Monday in 2014 rather than capitalize from the massive spike in retail spending. The 2014 Retail Research and Intelligence Report and the Holiday Trends: Black Friday/Cyber Monday Research and Intelligence Report were created by IBM's Managed Security Services team of analysts, who monitor more than 20 billion security incidents every day.

According to the research, cyber attackers are becoming increasingly more sophisticated, using new techniques to obtain massive amounts of confidential records with increased efficiency. Since 2012, the number of breaches reported by retailers dropped by 50 percent. Despite this decline, the perpetrators were able to impact a far greater number of victims with each incident.

"The threat from organized cyber crime rings remains the largest security challenge for retailers," said Kris Lovejoy, General Manager, IBM Security Services. "It is imperative that security leaders and CISOs in particular, use their growing influence to ensure they have the right people, processes and technology in place to take on these growing threats."

Black Friday and Cyber Monday

Identified as the two biggest shopping days of the year by IBM's Digital Analytics Benchmark, cyber attackers reduced their activity across all industries on Black Friday and Cyber Monday, rather than taking action. When looking at the two week period (Nov 24 - Dec 5) around these days, the data shows the following activity across all industries:

  • The number of daily cyber attacks was 3,043, nearly one third less than the 4,200 average over this period in 2013.
  • From 2013 and 2014, the number of breaches dropped by more than 50 percent for Black Friday and Cyber Monday.
  • In 2013, there were more than 20 breaches disclosed including several large breaches that caused the number of records compromised to rise drastically, reaching close to 4 million.
  • Over the same period in 2014, 10 breaches were disclosed which resulted in just over 72,000 records getting compromised

Despite this "cyber threat slow down," the retail and wholesale industries emerged as the top industry target for attackers in 2014, a potential result of the wave of high profile incidents impacting name brand retailers. In the two years prior, manufacturing ranked first amongst the top five attacked industries while the retail and wholesale industry ranked last. This past year, the primary mode of attack was unauthorized access via Secure Shell Brute Force attacks, which surpassed malicious code, the top choice in 2012 and 2013.

Top breaches overshadow growing trend

Attackers secured more than 61 million records in 2014, down from almost 73 million in 2013. However, when the data was narrowed down to only incidents involving less than 10 million records (which excludes the top two attacks over this timeframe, Target Corporation and The Home Depot), the data shows a different story--the number of retail records compromised in 2014 increased by more than 43 percent over 2013.

Sophisticated methods of attack

While there has been a rise in the number of Point of Sale (POS) malware attacks, the vast majority of incidents targeting the retail sector involved Command Injection or SQL injection. The complexity of SQL deployments and the lack of data validation performed by security administrators made retail databases a primary target. Over 2014, this Command Injection method was used in nearly 6,000 attacks against retailers. Additional methods include Shellshock as well as POS malware such as BlackPOS, Dexter, vSkimmer, Alina and Citadel.

The data for the number of records compromised and breaches disclosed was analyzed by IBM security experts and was made publically available by Privacy Rights Clearinghouse. The remaining data came from IBM's Managed Security services team.

Source: IBM Security

related articles:

popular articles:

Thumbnail-Photo: Wayfair Announces Decorify App for Apple Vision Pro...
15.02.2024   #Tech in Retail #virtual reality

Wayfair Announces Decorify App for Apple Vision Pro

Wayfair's virtual room styler and 3D imaging tools enable Apple Vision Pro users to reimagine their living spaces and experience the future of shopping in their home

With the Wayfair Decorify app on Apple Vision Pro, users have a variety of options to see their spaces redesigned. They can upload a photo of their space ...

Thumbnail-Photo: ‘Problem-solving mission’ with updated Modern Store Framework...
16.02.2024   #Tech in Retail #personnel management

‘Problem-solving mission’ with updated Modern Store Framework

Zebra Technologies will be looking to address challenges with expertise and new solutions at EuroCIS

Zebra Technologies Corporation (NASDAQ: ZBRA), a leading digital solution provider enabling businesses to intelligently connect data, assets, and people, today announced it’s taking the newly enhanced Modern Store framework on a ‘problem ...

Thumbnail-Photo: SES-imagotag becomes VusionGroup
29.01.2024   #software applications #artificial intelligence

SES-imagotag becomes VusionGroup

A new identity highlighting the broader portfolio of innovative solutions
developed by the Group to solve the major challenges of physical commerce

SES-imagotag (Euronext: SESL, FR0010282822), the global leader in digital solutions for physical commerce, today announced that it has changed its name to VusionGroup. This new name embodies the various product lines and solutions that have enhanced ...

Thumbnail-Photo: MPREIS Transforms Operations with Zebra Workcloud Task Management™...
06.11.2023   #customer experience #software developement

MPREIS Transforms Operations with Zebra Workcloud Task Management™ Software Solution

Austrian food retailer to streamline communication in around 300 stores to improve staff engagement, inventory optimisation, and customer satisfaction

MPREIS has around 300 Austrian stores in regions across Tyrol...

Thumbnail-Photo: Trigo and Netto Announce Autonomous Supermarket with Real-Time Receipt...
24.01.2024   #Tech in Retail #artificial intelligence

Trigo and Netto Announce Autonomous Supermarket with Real-Time Receipt Capability.

‘Final step’ in frictionless shopping drives trust by enabling consumers to view their receipts BEFORE leaving the store
Full size 800m2 grocery supermarket powered by computer vision AI is Europe’s largest retrofitted frictionless store

Trigo, a leading provider of AI computer vision technology that transforms traditional brick-and-mortar retail outlets into digital smart stores, and discount supermarket chain Netto Marken-Discount (also known as Netto), have partnered to launch ...

Thumbnail-Photo: Ask the Bot: generative AI in retail
02.01.2024   #Tech in Retail #food retail

Ask the Bot: generative AI in retail

Revolution in retail: the era of generative AI and AI bots

They are able to analyse data, write product descriptions, answer shoppers’ questions or write codes...

Thumbnail-Photo: Out of Stock in Retail and innovative solutions to avoid them...
07.11.2023   #brick and mortar retail #customer satisfaction

Out of Stock in Retail and innovative solutions to avoid them

Due to various events, the availability of goods in retail will be increasingly restricted from 2022, with the result that customers cannot find in food retail the products they wish to buy, because those products are sold out, are temporarily ...

Thumbnail-Photo: Unified Commerce Platform in focus
24.10.2023   #omnichannel #software developement

Unified Commerce Platform in focus

Handover at REMIRA: Dirk Bingler supersedes Stephan Unser as CEO

REMIRA is setting the course for future development of the company: On November 1, Dirk Bingler (48) will become the new CEO of the supply chain and omnichannel software expert headquartered in Dortmund. The previous CEO Stephan Unser (62) moves to ...

Thumbnail-Photo: EuroCIS 2024 - technology special
11.12.2023   #online trading #e-commerce

EuroCIS 2024 - technology special

The latest technology solutions and trends for you and the retail sector

At EuroCIS 2022 from February 27 to 29, 2024, the Leading Trade Fair for Retail Technology, we will be looking at all the important and current topics relating to technology in retail: AI and Machine Learning, Payment, Connected Retail, Seamless Store and Smart Energy Management and many more.

Thumbnail-Photo: The global state of autonomous stores
18.12.2023   #Tech in Retail #self-checkout systems

The global state of autonomous stores

The stores are located in various retail segments such as food retail, fashion, electronics, convenience stores and fast food.

In a highly competitive global retail landscape, autonomous stores are an emerging force that addresses changing consumer behaviors, reduces operational costs, improves profitability, and powers revenue growth strategies. Advancements in autonomous ...

Supplier

Zebra Technologies Germany GmbH
Zebra Technologies Germany GmbH
Ernst-Dietrich-Platz 2
40882 Ratingen
SALTO Systems GmbH
SALTO Systems GmbH
Schwelmer Str. 245
42389 Wuppertal
Innovative Technology Ltd.
Innovative Technology Ltd.
Innovative Business Park
OL1 4EQ Oldham
VusionGroup SA
VusionGroup SA
55 place Nelson Mandela
90000 Nanterre
Captana GmbH
Captana GmbH
Bundesstraße 16
77955 Ettenheim
REMIRA Group GmbH
REMIRA Group GmbH
Phoenixplatz 2
44263 Dortmund