Retailers are facing more cyberattacks ahead of holiday shopping

Hands typing on a keyboard surrounded by security icons
(Image credit: Shutterstock)

Cybercriminals are out for blood as the holiday season approaches in the midst of an unprecedented global supply chain crisis. 

The stark warning comes as a part of a new report from cybersecurity experts Imperva, which states that for some businesses, the disruptions may cause delayed shipments and ultimately - empty shelves - which could force some firms to shut up shop altogether.

Retailers should be particularly wary of three types of attacks: those coming from automated bots, distributed denial of service attacks (DDoS), and website attacks.

Bad bots

Bots can do all kinds of nasties, from price and content scraping, to scalping, to denial of inventory. This year, the volume of monthly bot attacks against retail websites is up 13%, compared to the same period last year, Imperva said, adding that the majority (57%) of attacks recorded on e-commerce websites this year were carried out by bots. 

Retail seems to be a particularly popular target for crooks, as bad bots made up just a third (33%) of total attacks on websites, in all other industries, this year. 

To make matters even worse, the proportion of sophisticated bot attacks spiked 23.4% this year, as well.

DDoS spiking

DDoS attacks spiked 200% in September, compared to the same period last year, fueled mostly by the rising threat of the Meris botnet. Over the course of the last 12 months, retail suffered the highest volume of layer 7 DDoS incidents per month, of all industries.

Even though the intensity of the attacks was relatively low this year (averaging a maximum of 35,000 requests per second (RPS)), the frequency was high. That suggests, Imperva believes, that the criminals were trying to be disruptive, without being detected. Most of application-layer DDoS attacks for the year were targeted against US-based retailers (61.6%).

As for website attacks, in the first half of the year, these were "notably higher" in the retail industry, than any other, Imperva says. A key characteristic, the report states, are "sporadic peaks". 

“The 2021 holiday shopping season is shaping up to be a nightmare for both retailers and consumers,” says Peter Klimek, Director of Technology, Office of the CTO, Imperva. “With the global supply chain conditions worsening, retailers will not only struggle to get products to sell in Q4, but will face increased attacks from motivated cybercriminals who want to benefit from the chaos."

You might also want to check out our list of the best firewall tools out there

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Don’t let holidays be your cybersecurity downfall
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Closing the cybersecurity skills gap
The critical need for watertight security across the IT supply chain
An image of network security icons for a network encircling a digital blue earth.
Standing strong against hyper-volumetric DDoS attacks
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring