Sony Pixel Power calrec Sony

AI-driven Attacks Targeting Retailers Ahead of the Holiday Shopping Season

21/10/2024

Facebook

Twitter

LinkedIn

Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, warns that as generative AI tools and Large Language Models (LLMs) continue to proliferate and advance, cybercriminals are increasingly using these technologies to enhance the scale and sophistication of their attacks on eCommerce platforms.

With sales beginning as early as October and extending through late December, the holiday shopping season represents a critical time for online retailers. The surge in activity not only drives substantial revenue but also attracts malicious actors targeting retailers at a time when they can least afford downtime or a security incident. As this crucial period approaches, retailers must prepare for a range of AI-driven threats, including bots, distributed denial of service (DDoS) attacks, API violations, and business logic abuse.

While cybersecurity threats are a concern year-round, they become even more pronounced during the holiday shopping season, when retailers often experience record-breaking sales, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. Cybercriminals recognize this and are using generative AI tools and LLMs to capitalize on the increased volume of digital transactions, limited-time promotions, and the gift cards and loyalty points stored in customer accounts.

In a recent 6-month analysis (April 2024 - September 2024), data from Imperva Threat Research reveals that, on average, retail sites collectively experience 569,884 AI-driven attacks each day. These attacks originate from AI tools like ChatGPT, Claude, and Gemini, alongside specialized bots that are designed to scrape websites for LLM training data. An analysis of these attacks shows that cybercriminals are primarily using the AI tools to carry out the following types of attacks.

Business Logic Abuse: The most common AI-driven attack (30.7%), business logic abuse involves exploiting the legitimate functionalities of an application or API to carry out malicious actions, such as manipulating prices, bypassing authentication, or abusing discount codes. AI enables attackers to automate these exploits at scale, making them harder to detect. To protect against these attacks, retailers should implement strict validation on all user inputs, employ anomaly detection systems to identify unusual activities, and regularly audit their business processes to identify functionalities that could be abused.

DDoS Attacks: Representing 30.6% of all AI-driven threats to retailers, DDoS attacks aim to overwhelm a website's resources, resulting in downtime that can lead to lost sales and reputational damage-especially during peak shopping periods. Cybercriminals are now leveraging AI to coordinate large botnets more efficiently, enhancing the effectiveness of these attacks. Retailers should invest in a DDoS protection solution that utilizes machine learning to identify and mitigate malicious traffic in real time, ensuring that legitimate customers are not impacted.

Bad Bot Attacks: Attacks from bad bots account for 20.8% of AI-driven threats targeting retailers. These automated threats engage in disruptive activities such as scraping pricing data, credential stuffing, and inventory hoarding (scalping). The infamous Grinch bot, in particular, is notorious for its inventory hoarding during the holiday shopping season, making it increasingly difficult for consumers to purchase high-demand items. With advancements in AI, operators can now create bots that convincingly mimic human behavior, allowing them to evade traditional security measures. To combat this threat, retailers should implement bot management solutions that utilize behavioral analytics to differentiate between genuine users and sophisticated bots.



API Violations: As eCommerce platforms increasingly expose APIs for mobile applications and third-party integrations, API violations are on the rise, accounting for 16.1% of AI-driven attacks on retailers. Cybercriminals exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or functionality. With the assistance of AI, attackers can quickly identify weak points in API implementations, making these threats particularly challenging to mitigate. To safeguard their APIs, retailers should enforce strict authentication and authorization protocols, implement rate limiting to prevent abuse, and regularly conduct comprehensive security assessments and penetration testing.

These AI-driven attacks pose significant risks not only for retailers but also for consumers. Cybercriminals are leveraging AI to conduct bot attacks, abuse business logic, and disrupt systems, putting sensitive personal information-including credit card details, addresses, and account information-at increased risk. Successful attacks can lead to identity theft, financial loss, and a loss of trust in eCommerce platforms, with fraudulent charges and unauthorized account access negatively affecting consumers shopping experiences.

In previous years, weve seen security threats like Grinch bots and DDoS attacks cause major disruptions during the holiday shopping season, affecting both retailers and consumers alike. Now, with the widespread availability of generative AI tools and LLMs, retailers are contending with a new wave of sophisticated cyberthreats, adds Singh. Without robust defenses, retailers risk facing a perfect storm of AI-driven attacks that could disrupt operations, compromise customer data, and tarnish their reputations during the most critical time of the year. To effectively mitigate these threats, retailers must adopt a comprehensive strategy that not only defends against these attacks but also allows them to respond swiftly without disrupting the shopping experience.

Additional Information:
LINK: https://www.thalesgroup.com/en/worldwide/digital-identity-and-security...
See more stories from thales

Most recent headlines

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

19/04/2025

SDVI Earns Both Product and Project of the Year Awards at...

SDVI, the leading platform provider for cloud-native media supply chains, today announced that the company earned multiple awards at the 2025 NAB Show, with two...

19/04/2025

Ateliere Announces CEO Transition

Ateliere Creative Technologies, a leading GenAI media software solutions company, today announced that Dan Goman has stepped down as CEO and David Bortis, Ateli...

19/04/2025

Marshall CV574 Miniature 4K UHD Camera Revolutionizes Off...

As Director of Media and Aerial Production at Terrible Herbst Motorsports, Bryan Moore is setting new standards in off-road racing media coverage thanks to his ...

19/04/2025

Lightware Launches Dual Screen Extended Desktop Taurus

A next-generation collaboration device that redefines connectivity for meeting environments Lightware, an industry-leading manufacturer of signal management so...

19/04/2025

Calrec Wins 2025 NAB Show Product of the Year Award for N...

Calrec is today announcing that its True Control 2.0 is a Remote Production winner in the 2025 NAB Show Product of the Year Awards. This official awards program...

19/04/2025

Appear and NBCUniversal Win Project of the Year at NAB Sh...

Appear, a global leader in live production technology, proudly announces it has been recognised alongside NBCUniversal with the prestigious NAB Show Delivery Pr...

19/04/2025

Deity Microphones Announces The Deity THEOS DIFB at NAB 2...

Deity Microphones, a leader in innovative audio equipment, is proud to announce the expected release of our Ultra-Wide Band IFB to the market. The THEOS DIFB wi...

19/04/2025

LiveU IQ Technology Delivers Breakthrough Network Perform...

A world renowned broadcaster and long-standing LiveU customer has successfully completed a series of live connectivity tests using LiveU's revolutionary, aw...

19/04/2025

BitFire Wins 2025 NAB Show Project of the Year and Produc...

BitFire (bitfire.tv), a longtime leader in live video transport, today announced dual NAB Show award wins at the 2025 NAB Show in Las Vegas. The company's M...

19/04/2025

BitFire Wins Three Top Awards at 2025 NAB Show

BitFire (bitfire.tv), a longtime leader in live video transport, today announced three major award wins at the 2025 NAB Show, April 5-9, in Las Vegas. The compa...

19/04/2025

Moments Lab and Satisfaction Group Form Unique Strategic...

AI video discovery company Moments Lab and Satisfaction Group, a leading independent unscripted television production company, are proud to announce a unique st...

19/04/2025

The Infrastructure of Creative Flow DigitalGlues creative...

As the media industry navigates the triple challenge of AI-driven production, distributed teams, and skyrocketing content demand, DigitalGlue s creative.space h...

19/04/2025

Miri Technologies Wins Two Prestigious Awards for X510 Bo...

Network technology startup Miri Technologies Inc. capped off its tremendously successful NAB Show debut by winning two prestigious industry awards for its cutti...

19/04/2025

Tablo Adds 45 New FAST Channels From Warner Bros. Discovery

CINCINNATI Scripp's Nuvyyo USA has concluded a deal with Warner Bros. Discovery to bring 45 FAST channels to Nuvyyo's Tablo TV device....

19/04/2025

Court Overrules FCC's $57 Million Fine Against AT&T

In a ruling that could have broader implications on the legality of regulatory agencies levying fines through administrative proceedings, the 5th U.S. Circuit C...

19/04/2025

FCC Chair Carr Blasts Comcast Over MSNBC Coverage

WASHINGTON Federal Communications Commission chair Brendan Carr has blasted Comcast over MSNBC's coverage of the deportation of Kilmar Abrego Garcia in a so...

19/04/2025

Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC

Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC This season features faculty member Arun Pandian as the new host and interviews ...

18/04/2025

Everyone Is Cordially Invited to Celebrate Queer Joy in The Wedding Banquet

Director Andrew Ahn, alongside actors Youn Yuh-jung and Joan Chen, takes a photo of the audience after the premiere of his film The Wedding Banquet at Eccles ...

18/04/2025

U.S. Judge Rules Google Illegally Monopolized Ad Technologies

In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...

18/04/2025

TV News Outlets See March Spike in Social Media Usage

Broadcast and cable TV news outlets saw strong social media growth in March, according to new data from the social video analytics company Tubular Labs ....

18/04/2025

Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist

Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist The drummer secured a spot among the elite winners in this years competition. By Maddie...

18/04/2025

Boston Conservatory Alums Bring Real Women Have Curves to Broadway

Boston Conservatory Alums Bring Real Women Have Curves to Broadway The Latin American immigrant community takes center stage in a new musical featuring Tatian...

18/04/2025

UPDATED: Broadcasters Urge FCC to Hit the Delete Button on Antiquated Regs

WASHINGTON The FCC's call for public comments and suggestions on outdated regulations that it should be eliminated, has prompted a slew of fillings from bro...

18/04/2025

Federal Judge Rules Google Illegally Monopolized Ad Technologies

In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...

18/04/2025

AMS, VideoAmp Collaborate on Cross-Channel Targeting and Measurement

PEARL RIVER, N.Y. Global media solutions company Active Media Services (AMS) has formed a new relationship with VideoAmp, a measurement company for linear TV, c...

18/04/2025

Netflix Reports Strong Q1 Revenue, Operating Income

Netflix reported generally positive results for first-quarter 2025, with revenue up 13% year-over-year to $10.543 billion and operating income growing by 27% to...

18/04/2025

NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile Units from NEP Group, Game Creek Video

NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile U...

18/04/2025

EVS's Sbastien Verlaine on U.S. Expansion, Next-Generation Products

EVSs S bastien Verlaine on U.S. Expansion, Next-Generation Products Beyond replay, offerings also target asset management and media infrastructure By Ken Kersc...

18/04/2025

ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC

ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC Men's championships to follow Saturday night on ESPN2 By Brandon Costa, Direct...

18/04/2025

Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports

Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports This panel discussion featured leaders from ESPN, CBS Sports, Warner Bros. Disc...

18/04/2025

NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remote-Production Models in U.S., Canada

NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remo...

17/04/2025

The Ugly Stepsister: A Cinderella Body Horror Story That Will Leave a Crowd in Shambles

Emilie Blichfeldt attends the 2025 Sundance Film Festival premiere of The Ugly ...

17/04/2025

Why Resilient GPS (R-GPS) Matters for US Military Superiority: We Must Address GPS Vulnerabilities

R-GPS gives warfighters a decisive battlefield advantage by punching through adv...

17/04/2025

What NAB told us about the future of media tech

This year's NAB Show in Las Vegas marked a noticeable shift in the priorities of media and broadcast organisations. Gone are the days of chasing flashy, or ...

17/04/2025

Changing Sustainable Production in Wales and Beyond

class=attachment-thumbnail size-thumbnail f-align-center alt= decoding=async data-lazy-srcset=https://www.antonbauer.com/wp-content/uploads/2024/12/Amy-Daniel-1...

17/04/2025

Roku to Collaborate with Adobe on Real-Time Customer Data

SAN JOSE, Calif. Roku and Adobe have announced that they are collaborating on a real time data platform made possible by a a new integration of the Roku Data C...

17/04/2025

IAB: Digital Ad Revenue Surges 14.9% YoY to $259 Billion in 2024

NEW YORK Internet advertising revenues demonstrated strong growth in 2024, increasing 14.9% year-over-year to $258.6 billion, according to the IAB Internet Adv...

17/04/2025

SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show

SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show Brie Clayton April 17, 2025 0 Comments Left to right, Geoff Stedman, CMO, SDVI...

17/04/2025

Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions with AJA

Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions ...

17/04/2025

Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0

Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0 Brie Clayton April 17, 2025 0 Comments Image: The Calrec True Control 2.o on ...

17/04/2025

In Return to Berklee, Lucius Looks Back and Moves Forward

In Return to Berklee, Lucius Looks Back and Moves Forward From mood boards to live demos, the alumni band gave students an exclusive look at the process behin...

17/04/2025

MyFree DirecTV Adds 8 NBCU Channels

DirecTV's free streaming service MyFree DirecTV has just added another eight channels from NBCUniversal....

17/04/2025

GameChanger Launches in the U.S.

LOS ANGELES The virtual production company GameChanger has announced that it is expanding its global footprint by bringing its virtual production technology to ...

17/04/2025

IBCAP Launches Automated VOD Monitoring and Takedown System

DENVER The International Broadcaster Coalition Against Piracy (IBCAP) has announced that it has developed a proprietary, automated software-based system to iden...

17/04/2025

Pixalate: Roku Continues to Dominate U.S. CTV Device Market

Pixalate's new CTV Device Market Share report for Q1 2025 shows that Roku has the highest open programmatic CTV device market share in the United States, wi...

17/04/2025

Edward J. Lewis III Named Senior Vice President of Institutional Advancement

Edward J. Lewis III Named Senior Vice President of Institutional Advancement Lewis has more than 20 years of industry experience, leading fundraising initiati...

17/04/2025

The Curling Group Puts On Inaugural Curling All-Star Game in Nashville

The Curling Group Puts On Inaugural Curling All-Star Game in Nashville The location in Music City is intended to broaden the sport's appeal By Dan Daley, ...

17/04/2025

Tribeca Festival 2025 Announces TV and NOW Lineup

April 17th, 2025 Press Materials Available Here Tribeca Festival 2025 Announces TV & NOW Lineup World Premieres and Exclusive Cast Panels with Apple TV '...

17/04/2025

SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clients, How Industry Trends Impact Workflows

SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clie...