AI-driven Attacks Targeting Retailers Ahead of the Holiday Shopping Season
21/10/2024
Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, warns that as generative AI tools and Large Language Models (LLMs) continue to proliferate and advance, cybercriminals are increasingly using these technologies to enhance the scale and sophistication of their attacks on eCommerce platforms.
With sales beginning as early as October and extending through late December, the holiday shopping season represents a critical time for online retailers. The surge in activity not only drives substantial revenue but also attracts malicious actors targeting retailers at a time when they can least afford downtime or a security incident. As this crucial period approaches, retailers must prepare for a range of AI-driven threats, including bots, distributed denial of service (DDoS) attacks, API violations, and business logic abuse.
While cybersecurity threats are a concern year-round, they become even more pronounced during the holiday shopping season, when retailers often experience record-breaking sales, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. Cybercriminals recognize this and are using generative AI tools and LLMs to capitalize on the increased volume of digital transactions, limited-time promotions, and the gift cards and loyalty points stored in customer accounts.
In a recent 6-month analysis (April 2024 - September 2024), data from Imperva Threat Research reveals that, on average, retail sites collectively experience 569,884 AI-driven attacks each day. These attacks originate from AI tools like ChatGPT, Claude, and Gemini, alongside specialized bots that are designed to scrape websites for LLM training data. An analysis of these attacks shows that cybercriminals are primarily using the AI tools to carry out the following types of attacks.
Business Logic Abuse: The most common AI-driven attack (30.7%), business logic abuse involves exploiting the legitimate functionalities of an application or API to carry out malicious actions, such as manipulating prices, bypassing authentication, or abusing discount codes. AI enables attackers to automate these exploits at scale, making them harder to detect. To protect against these attacks, retailers should implement strict validation on all user inputs, employ anomaly detection systems to identify unusual activities, and regularly audit their business processes to identify functionalities that could be abused.
DDoS Attacks: Representing 30.6% of all AI-driven threats to retailers, DDoS attacks aim to overwhelm a website's resources, resulting in downtime that can lead to lost sales and reputational damage-especially during peak shopping periods. Cybercriminals are now leveraging AI to coordinate large botnets more efficiently, enhancing the effectiveness of these attacks. Retailers should invest in a DDoS protection solution that utilizes machine learning to identify and mitigate malicious traffic in real time, ensuring that legitimate customers are not impacted.
Bad Bot Attacks: Attacks from bad bots account for 20.8% of AI-driven threats targeting retailers. These automated threats engage in disruptive activities such as scraping pricing data, credential stuffing, and inventory hoarding (scalping). The infamous Grinch bot, in particular, is notorious for its inventory hoarding during the holiday shopping season, making it increasingly difficult for consumers to purchase high-demand items. With advancements in AI, operators can now create bots that convincingly mimic human behavior, allowing them to evade traditional security measures. To combat this threat, retailers should implement bot management solutions that utilize behavioral analytics to differentiate between genuine users and sophisticated bots.
API Violations: As eCommerce platforms increasingly expose APIs for mobile applications and third-party integrations, API violations are on the rise, accounting for 16.1% of AI-driven attacks on retailers. Cybercriminals exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or functionality. With the assistance of AI, attackers can quickly identify weak points in API implementations, making these threats particularly challenging to mitigate. To safeguard their APIs, retailers should enforce strict authentication and authorization protocols, implement rate limiting to prevent abuse, and regularly conduct comprehensive security assessments and penetration testing.
These AI-driven attacks pose significant risks not only for retailers but also for consumers. Cybercriminals are leveraging AI to conduct bot attacks, abuse business logic, and disrupt systems, putting sensitive personal information-including credit card details, addresses, and account information-at increased risk. Successful attacks can lead to identity theft, financial loss, and a loss of trust in eCommerce platforms, with fraudulent charges and unauthorized account access negatively affecting consumers shopping experiences.
In previous years, weve seen security threats like Grinch bots and DDoS attacks cause major disruptions during the holiday shopping season, affecting both retailers and consumers alike. Now, with the widespread availability of generative AI tools and LLMs, retailers are contending with a new wave of sophisticated cyberthreats, adds Singh. Without robust defenses, retailers risk facing a perfect storm of AI-driven attacks that could disrupt operations, compromise customer data, and tarnish their reputations during the most critical time of the year. To effectively mitigate these threats, retailers must adopt a comprehensive strategy that not only defends against these attacks but also allows them to respond swiftly without disrupting the shopping experience.
Additional Information:
LINK: | https://www.thalesgroup.com/en/worldwide/digital-identity-and-security... |
See more stories from thales |
Most recent headlines
04/02/2025
Spotify Reports Fourth Quarter 2024 Earnings
Today, we announced our fourth quarter 2024 earnings, closing Q4 stronger than ever by outperforming across key metrics and celebrating our first full year of p...
04/02/2025
Spotify rapporterar intkter fr fjrde kvartalet 2024
Idag rapporterar vi int kter f r fj rde kvartalet 2024. Vi avslutade Q4 starkare n n gonsin genom att vertr ffa f rv ntningarna p v ra nyckeltal och kan d rm...
04/02/2025
SGL Carbon opts for green electricity at its German sites
As a technology-based company and one of the worlds leading companies in the development and production of carbon-based solutions, SGL Carbon opts for innovativ...
04/02/2025
ST Engineering iDirect Names Sridhar Kuppanna as Chief Technology Officer
Ground segment technology innovator appoints new CTO to execute bold technological vision Herndon, Va., February 4, 2025 ST Engineering iDirect, global leade...
04/02/2025
L3Harris Signs Multi-Year Pilot Training Agreement With Thai Airways
L3Harris has signed a two-year agreement with Thai Airways International to provide training service on its A320 Full Flight Simulator (FFS). This significant a...
04/02/2025
US Air Force Completes First Flight of L3Harris Viper Shield Electronic Warfare System
L3Harris' all-digital electronic warfare suite, Viper Shield , completed its...
04/02/2025
Radio Botswana chooses Calrec's IP-native Type R mixing system
The shift from analogue to IP was driven by a desire for greater flexibility in our operations. IP simplifies connectivity, reduces the physical footprint of th...
04/02/2025
Simplifying Gray Media News Operations with Calrec's Type R
Streamline, standardise and save: how Gray Media has simplified news operations At TVNewsCheck's News Tech Forum 2024, Gray Media's Peter Gogas and Calr...
04/02/2025
Bending Spoons closes $233 million acquisition of Brightcove
Boston, MA-February 4, 2025 | Bending Spoons, the Italy-based technology company, completed its previously announced acquisition of US-based streaming technolog...
04/02/2025
PARAMOUNT AND NIELSEN SIGN MULTI-YEAR MEASUREMENT AND ANALYTICS DEAL ACROSS PARAMOUNT'S LEADING BROADCAST, CABLE AND STREAMING PLATFORMS
Nielsen Reports Major Recent Ratings Milestones for CBS and Paramount Series N...
04/02/2025
Grup Mediapro to Collaborate with Google Cloud on Gen AI
BARCELONA Grup Mediapro and Google Cloud have expanded their collaboration to create an innovation lab focused on generative AI to develop solutions for the med...
04/02/2025
EditShare Receives SOCE 2 Type II Certification
WATERTOWN, Mass. EditShare this week said it has received SOC 2 Type II certification, an independently audited evaluation of an organization's information ...
04/02/2025
Executive Creative Director Halle Petro Named Partner of Sonic Union
Executive Creative Director Halle Petro Named Partner of Sonic Union Brie Clayton February 4, 2025 0 Comments Sonic Union is excited to announce Execu...
04/02/2025
Blackmagic Design Announces Blackmagic Camera for Android 2.0 Update
Blackmagic Design Announces Blackmagic Camera for Android 2.0 Update Brie Clayton February 4, 2025 0 Comments New update adds support for Xiaomi Pad 6...
04/02/2025
CETA Software Launches Artist Access: The Time-Tracking Tool for Creative Teams
CETA Software Launches Artist Access: The Time-Tracking Tool for Creative Teams Brie Clayton February 4, 2025 0 Comments CETA Software, creators of p...
04/02/2025
OWC Announces General Availability Launch of OWC Dock Ejector 2.0
OWC Announces General Availability Launch of OWC Dock Ejector 2.0 Brie Clayton February 4, 2025 0 Comments The Ultimate Tool for Efficiently and Safel...
04/02/2025
Colourist Claudio Del Bravo on grading Queer
Explaining the process to TVBEurope, Del Bravo said the films look was inspired by the Technicolor three-strip' process, evoking the rich colours of early ...
04/02/2025
Paramount, Nielsen Sign Multiyear Measurement and Analytics Deal
NEW YORK Paramount Global and Nielsen have inked a new, multiyear deal that will provide measurement for all of the company's platforms, including national ...
04/02/2025
2d Animated Short Concerning a Project for Schools
2d Animated Short Concerning a Project for Schools Brie Clayton February 3, 2025 0 Comments 2d animated short concerning a project for schools Febru...
04/02/2025
Step by step guide to using 3D Models in After Effects
Step by step guide to using 3D Models in After Effects Graham Quince February 3, 2025 0 Comments Since 2024, Adobe After Effects has had native suppor...
04/02/2025
Powerful Premiere Automation with new Excalibur Update
Powerful Premiere Automation with new Excalibur Update Colin Smith February 3, 2025 0 Comments This tutorial takes you through the new update for auto...
04/02/2025
Cinematography of A Complete Unknown: Shooting 12,800 iso Sony Venice 2 to create a 1960's era film
Cinematography of A Complete Unknown: Shooting 12,800 iso Sony Venice 2 to creat...
04/02/2025
DIY to DA: Ela Minus Breaks Through
DIY to D A: Ela Minus Breaks Through The electronic artist and producer tells Rolling Stone about her new album, D A, and how shes forged a career outside the...
04/02/2025
The Future of Football? Technology and Entertainment Merge in the Kings World Cup Nations
The future of football? Technology and entertainment merge in the Kings World Cu...
04/02/2025
Virtual Production and AR Graphics: Demystifying the Tools, Technologies, and Trends
Virtual Production and AR Graphics: Demystifying the Tools, Technologies, and Tr...
04/02/2025
SVG All-Stars: Russell Fink, Senior Director, Programming and Content Analytics, SNY
SVG All-Stars: Russell Fink, Senior Director, Programming and Content Analytics,...
04/02/2025
SVG New Sponsor Spotlight: farmerswife's Jodi Clifford on Organizing Your Productions Like a Professional
SVG New Sponsor Spotlight: farmerswife's Jodi Clifford on Organizing Your Pr...
04/02/2025
EA Acquires TRACAB Technologies as It Looks to Move Beyond Games
EA Acquires TRACAB Technologies as It Looks to Move Beyond Games EA believes TRACABs sports tracking/analysis technology will help to make the EA SPORTS App the...
04/02/2025
Kingdom Come: Alamiya Media on Bringing the Supercoppa Italiana and Supercopa de Espaa to Saudi Arabia
Kingdom come: Alamiya Media on bringing the Supercoppa Italiana and Supercopa de...
04/02/2025
Alamiya Media at 50: Preparing for Rapid Change, an International Broadcast Center and the FIFA World Cup
Alamiya Media at 50: Preparing for rapid change, an international broadcast cent...
04/02/2025
An update on our TV and broadband prices
An update on our TV and broadband pricesTuesday 4 February 2025 An update on our TV and broadband prices Devesh Raj, Chief Operating Officer, Sky This April,...
04/02/2025
Sky extends partnership with the PDC to remain the home of darts until 2030
Sky extends partnership with the PDC to remain the home of darts until 2030Tuesday 4 February 2025 Following another record-breaking PDC World Darts Championsh...
04/02/2025
Frankfurt is the world's first airport to regularly use walk-through scanners from Rohde & Schwarz for passengers
Frankfurt is the world's first airport to regularly use walk-through scanner...
04/02/2025
Riedel Unveils Next Generation of StageLink Edge Devices
Wuppertal February 4, 2025 Riedel Unveils Next Generation of StageLink Edge DevicesRiedel Communications today announced the launch of its StageLink family of...
04/02/2025
Clara Galle, Claudia Salas and Paula Usero Star in 'That Night,' the New Netflix Series Based on the Bestselling Novel by Gillian McAllister
Back to All News Clara Galle, Claudia Salas and Paula Usero Star in That Night,...
04/02/2025
Fox Corporation Reports Second Quarter Fiscal 2025 Financial Results
Fox Corporation Reports Second Quarter Fiscal 2025 Financial Results NEW YORK, NY, February 4, 2025 - Fox Corporation (Nasdaq: FOXA, FOX; FOX or the Compan...
04/02/2025
Introducing our fully digital, true diversity wideband wireless mic solution
DPA Microphones is moving into the wireless market with the release of its new N-Series Digital Wireless System at ISE 2025 (Stand 7P600). A fully digital, true...
04/02/2025
2025-02-04
CUPERTINO, CALIFORNIA Apple today introduced Apple Invites, a new app for iPhone that helps users create custom invitations to gather friends and family for any...
04/02/2025
ABS appoints Sameer Karimbhai as New General Counsel
ABS appoints Sameer Karimbhai as New General Counsel...
04/02/2025
Thales Alenia Space signs a contract with Mohammed Bin Rashid Space Centre to develop the Emirates Airlock Module, a critical element of Lunar Gateway
Facebook Twitter LinkedIn Thales Alenia Space strengthens its cooperation with the UAE as a key partner in future space missions Cannes, February 4th, 20...
04/02/2025
RT Internship Programme 2025 - Applications Now Open
We're thrilled to announce that applications for the 2025 RT Internship Programme are now open....
04/02/2025
Jack Woolley tops the Dancing with the Stars leaderboard in Dedicated Dance Week
Jack Woolley topped the leaderboard in what was an emotional night on Dancing with the Stars, as the remaining nine couples took to the floor for Dedicated Danc...
03/02/2025
Spotify's This Is Taylor Swift' Immersive Experience Connects Swifties Across Asia to Their Favorite Anthem
If you're one of the many Swifties living in Asia, you're in for a treat...
03/02/2025
5 Spotify Hacks Every Free User Needs To Know
Whether you're discovering your new favorite song or queuing up the latest episode of the hottest podcasts, Spotify is always innovating to deliver the best...
03/02/2025
SBS boosts commitment to Indigenous leadership and innovation with Executive team update
SBS boosts commitment to Indigenous leadership and innovation with Executive tea...
03/02/2025
L3Harris Technology Enhances US Torpedo Capability
The L3Harris IPLCS is a fiber-optic tether connecting a torpedo to the origin vessel, providing data in real time. Credit: L3Harris...
03/02/2025
VidTrans 2025 to Focus on Security, Dynamic Media Production
BOTHELL, Wash. Video Services Forum (VSF) today announced that the VidTrans 2025 conference and exposition will take place Feb. 25-27 at the Marina del Rey Marr...
03/02/2025
Legislation Proposed to Require Refunds During TV Blackouts
WASHINGTON Last week Rep. Pat Ryan (D-N.Y.) and Sen. Chris Murphy (D-Conn.) introduced the Stop Sports Blackouts Act to make cable and satellite companies ref...
03/02/2025
New Vendors Gain Amazon Prime Video Preferred Certification
Amazon Prime Video has added more companies to its Preferred Vendor Services Program....
03/02/2025
Grand Slam Track Inks Media Rights Deal with The CW, NBC Sports
BURBANK, Calif. The CW, NBC Sports and Grand Slam Track, a new global track competition, have announced a media rights deal that makes The CW the exclusive U.S....