
Facebook
Twitter
LinkedIn
Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, warns that as generative AI tools and Large Language Models (LLMs) continue to proliferate and advance, cybercriminals are increasingly using these technologies to enhance the scale and sophistication of their attacks on eCommerce platforms.
With sales beginning as early as October and extending through late December, the holiday shopping season represents a critical time for online retailers. The surge in activity not only drives substantial revenue but also attracts malicious actors targeting retailers at a time when they can least afford downtime or a security incident. As this crucial period approaches, retailers must prepare for a range of AI-driven threats, including bots, distributed denial of service (DDoS) attacks, API violations, and business logic abuse.
While cybersecurity threats are a concern year-round, they become even more pronounced during the holiday shopping season, when retailers often experience record-breaking sales, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. Cybercriminals recognize this and are using generative AI tools and LLMs to capitalize on the increased volume of digital transactions, limited-time promotions, and the gift cards and loyalty points stored in customer accounts.
In a recent 6-month analysis (April 2024 - September 2024), data from Imperva Threat Research reveals that, on average, retail sites collectively experience 569,884 AI-driven attacks each day. These attacks originate from AI tools like ChatGPT, Claude, and Gemini, alongside specialized bots that are designed to scrape websites for LLM training data. An analysis of these attacks shows that cybercriminals are primarily using the AI tools to carry out the following types of attacks.
Business Logic Abuse: The most common AI-driven attack (30.7%), business logic abuse involves exploiting the legitimate functionalities of an application or API to carry out malicious actions, such as manipulating prices, bypassing authentication, or abusing discount codes. AI enables attackers to automate these exploits at scale, making them harder to detect. To protect against these attacks, retailers should implement strict validation on all user inputs, employ anomaly detection systems to identify unusual activities, and regularly audit their business processes to identify functionalities that could be abused.
DDoS Attacks: Representing 30.6% of all AI-driven threats to retailers, DDoS attacks aim to overwhelm a website's resources, resulting in downtime that can lead to lost sales and reputational damage-especially during peak shopping periods. Cybercriminals are now leveraging AI to coordinate large botnets more efficiently, enhancing the effectiveness of these attacks. Retailers should invest in a DDoS protection solution that utilizes machine learning to identify and mitigate malicious traffic in real time, ensuring that legitimate customers are not impacted.
Bad Bot Attacks: Attacks from bad bots account for 20.8% of AI-driven threats targeting retailers. These automated threats engage in disruptive activities such as scraping pricing data, credential stuffing, and inventory hoarding (scalping). The infamous Grinch bot, in particular, is notorious for its inventory hoarding during the holiday shopping season, making it increasingly difficult for consumers to purchase high-demand items. With advancements in AI, operators can now create bots that convincingly mimic human behavior, allowing them to evade traditional security measures. To combat this threat, retailers should implement bot management solutions that utilize behavioral analytics to differentiate between genuine users and sophisticated bots.
API Violations: As eCommerce platforms increasingly expose APIs for mobile applications and third-party integrations, API violations are on the rise, accounting for 16.1% of AI-driven attacks on retailers. Cybercriminals exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or functionality. With the assistance of AI, attackers can quickly identify weak points in API implementations, making these threats particularly challenging to mitigate. To safeguard their APIs, retailers should enforce strict authentication and authorization protocols, implement rate limiting to prevent abuse, and regularly conduct comprehensive security assessments and penetration testing.
These AI-driven attacks pose significant risks not only for retailers but also for consumers. Cybercriminals are leveraging AI to conduct bot attacks, abuse business logic, and disrupt systems, putting sensitive personal information-including credit card details, addresses, and account information-at increased risk. Successful attacks can lead to identity theft, financial loss, and a loss of trust in eCommerce platforms, with fraudulent charges and unauthorized account access negatively affecting consumers shopping experiences.
In previous years, weve seen security threats like Grinch bots and DDoS attacks cause major disruptions during the holiday shopping season, affecting both retailers and consumers alike. Now, with the widespread availability of generative AI tools and LLMs, retailers are contending with a new wave of sophisticated cyberthreats, adds Singh. Without robust defenses, retailers risk facing a perfect storm of AI-driven attacks that could disrupt operations, compromise customer data, and tarnish their reputations during the most critical time of the year. To effectively mitigate these threats, retailers must adopt a comprehensive strategy that not only defends against these attacks but also allows them to respond swiftly without disrupting the shopping experience.
Additional Information:
Most recent headlines
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
19/04/2025
SDVI, the leading platform provider for cloud-native media supply chains, today announced that the company earned multiple awards at the 2025 NAB Show, with two...
19/04/2025
Ateliere Creative Technologies, a leading GenAI media software solutions company, today announced that Dan Goman has stepped down as CEO and David Bortis, Ateli...
19/04/2025
As Director of Media and Aerial Production at Terrible Herbst Motorsports, Bryan Moore is setting new standards in off-road racing media coverage thanks to his ...
19/04/2025
A next-generation collaboration device that redefines connectivity for meeting environments
Lightware, an industry-leading manufacturer of signal management so...
19/04/2025
Calrec is today announcing that its True Control 2.0 is a Remote Production winner in the 2025 NAB Show Product of the Year Awards. This official awards program...
19/04/2025
Appear, a global leader in live production technology, proudly announces it has been recognised alongside NBCUniversal with the prestigious NAB Show Delivery Pr...
19/04/2025
Deity Microphones, a leader in innovative audio equipment, is proud to announce the expected release of our Ultra-Wide Band IFB to the market. The THEOS DIFB wi...
19/04/2025
A world renowned broadcaster and long-standing LiveU customer has successfully completed a series of live connectivity tests using LiveU's revolutionary, aw...
19/04/2025
BitFire (bitfire.tv), a longtime leader in live video transport, today announced dual NAB Show award wins at the 2025 NAB Show in Las Vegas. The company's M...
19/04/2025
BitFire (bitfire.tv), a longtime leader in live video transport, today announced three major award wins at the 2025 NAB Show, April 5-9, in Las Vegas. The compa...
19/04/2025
AI video discovery company Moments Lab and Satisfaction Group, a leading independent unscripted television production company, are proud to announce a unique st...
19/04/2025
As the media industry navigates the triple challenge of AI-driven production, distributed teams, and skyrocketing content demand, DigitalGlue s creative.space h...
19/04/2025
Network technology startup Miri Technologies Inc. capped off its tremendously successful NAB Show debut by winning two prestigious industry awards for its cutti...
19/04/2025
CINCINNATI Scripp's Nuvyyo USA has concluded a deal with Warner Bros. Discovery to bring 45 FAST channels to Nuvyyo's Tablo TV device....
19/04/2025
In a ruling that could have broader implications on the legality of regulatory agencies levying fines through administrative proceedings, the 5th U.S. Circuit C...
19/04/2025
WASHINGTON Federal Communications Commission chair Brendan Carr has blasted Comcast over MSNBC's coverage of the deportation of Kilmar Abrego Garcia in a so...
19/04/2025
Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC This season features faculty member Arun Pandian as the new host and interviews ...
18/04/2025
Director Andrew Ahn, alongside actors Youn Yuh-jung and Joan Chen, takes a photo of the audience after the premiere of his film The Wedding Banquet at Eccles ...
18/04/2025
In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...
18/04/2025
Broadcast and cable TV news outlets saw strong social media growth in March, according to new data from the social video analytics company Tubular Labs ....
18/04/2025
Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist The drummer secured a spot among the elite winners in this years competition.
By
Maddie...
18/04/2025
Boston Conservatory Alums Bring Real Women Have Curves to Broadway The Latin American immigrant community takes center stage in a new musical featuring Tatian...
18/04/2025
WASHINGTON The FCC's call for public comments and suggestions on outdated regulations that it should be eliminated, has prompted a slew of fillings from bro...
18/04/2025
In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...
18/04/2025
PEARL RIVER, N.Y. Global media solutions company Active Media Services (AMS) has formed a new relationship with VideoAmp, a measurement company for linear TV, c...
18/04/2025
Netflix reported generally positive results for first-quarter 2025, with revenue up 13% year-over-year to $10.543 billion and operating income growing by 27% to...
18/04/2025
NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile U...
18/04/2025
EVSs S bastien Verlaine on U.S. Expansion, Next-Generation Products Beyond replay, offerings also target asset management and media infrastructure By Ken Kersc...
18/04/2025
ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC Men's championships to follow Saturday night on ESPN2 By Brandon Costa, Direct...
18/04/2025
Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports This panel discussion featured leaders from ESPN, CBS Sports, Warner Bros. Disc...
18/04/2025
NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remo...
17/04/2025
Emilie Blichfeldt attends the 2025 Sundance Film Festival premiere of The Ugly ...
17/04/2025
R-GPS gives warfighters a decisive battlefield advantage by punching through adv...
17/04/2025
This year's NAB Show in Las Vegas marked a noticeable shift in the priorities of media and broadcast organisations. Gone are the days of chasing flashy, or ...
17/04/2025
class=attachment-thumbnail size-thumbnail f-align-center alt= decoding=async data-lazy-srcset=https://www.antonbauer.com/wp-content/uploads/2024/12/Amy-Daniel-1...
17/04/2025
SAN JOSE, Calif. Roku and Adobe have announced that they are collaborating on a real time data platform made possible by a a new integration of the Roku Data C...
17/04/2025
NEW YORK Internet advertising revenues demonstrated strong growth in 2024, increasing 14.9% year-over-year to $258.6 billion, according to the IAB Internet Adv...
17/04/2025
SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show
Brie Clayton April 17, 2025
0 Comments
Left to right, Geoff Stedman, CMO, SDVI...
17/04/2025
Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions ...
17/04/2025
Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0
Brie Clayton April 17, 2025
0 Comments
Image: The Calrec True Control 2.o on ...
17/04/2025
In Return to Berklee, Lucius Looks Back and Moves Forward From mood boards to live demos, the alumni band gave students an exclusive look at the process behin...
17/04/2025
DirecTV's free streaming service MyFree DirecTV has just added another eight channels from NBCUniversal....
17/04/2025
LOS ANGELES The virtual production company GameChanger has announced that it is expanding its global footprint by bringing its virtual production technology to ...
17/04/2025
DENVER The International Broadcaster Coalition Against Piracy (IBCAP) has announced that it has developed a proprietary, automated software-based system to iden...
17/04/2025
Pixalate's new CTV Device Market Share report for Q1 2025 shows that Roku has the highest open programmatic CTV device market share in the United States, wi...
17/04/2025
Edward J. Lewis III Named Senior Vice President of Institutional Advancement Lewis has more than 20 years of industry experience, leading fundraising initiati...
17/04/2025
The Curling Group Puts On Inaugural Curling All-Star Game in Nashville The location in Music City is intended to broaden the sport's appeal By Dan Daley, ...
17/04/2025
April 17th, 2025 Press Materials Available Here
Tribeca Festival 2025 Announces TV & NOW Lineup
World Premieres and Exclusive Cast Panels with Apple TV '...
17/04/2025
SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clie...