Shoppers facing major cybercrime risk this Black Friday

Cybersecurity
(Image credit: Altalex)

Research by cybersecurity firm Proofpoint looking into online retail has found that the vast majority of brands remain vulnerable to email fraud. With Black Friday upon us, just 11% of the primary corporate domains of the 159 members of the British Retail Consortium had the strongest level of Domain-based Message Authentication, Reporting & Conformance (DMARC) protection in place.

Many threat actors use domain spoofing to pose as well-known retailers, sending emails from fake addresses that are difficult to distinguish from legitimate ones. 

Implementing the strictest level of DMARC protection, however, means organizations can actively block fraudulent emails sent in their name.

Risky buy

The research also found that it wasn’t just UK retailers that were taking unnecessary risks. Looking at the top 20 online retailers across Europe, Proofpoint found that 80% also did not have the strictest DMARC policy in place.

As well as only shopping with sites that have a strong DMARC status in place, there are a few other steps that customers can take to protect their data from cybercriminals looking to impersonate a trusted domain over the shopping season.

Using strong passwords, avoiding unprotected Wi-Fi networks and remaining vigilant against lookalike sites will all help in the fight against fraud. In addition, avoiding suspicious links and watching out for phishing attacks is advised at all times.

“Organisations in all sectors should look to deploy authentication protocols, such as DMARC to shore up their email fraud defences,” Matt Cooke, cybersecurity strategist at Proofpoint, explained

"Cybercriminals will always leverage key events to drive targeted attacks using social engineering techniques such as impersonation and retailers are no exception to this. Ahead of Black Friday, consumers must be vigilant in checking the validity of all emails, especially on a day when guards are down, and attentions are focused on grabbing seasonal bargains.”

Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost