Holiday shoppers face rising risks as email fraud targets weak retailer security

Someone using an ecommerce website on their laptop.
(Image credit: 123RF)

  • Report claims 40% of retailers fail to meet email security standards
  • DMARC adoption gaps leave shoppers exposed to phishing attacks
  • Retailers’ weak protections heighten risks during sales

As shoppers prepare for another season of online deals, new research from Proofpoint reveals a concerning vulnerability among leading retailers.

The findings claim 40% of the UK’s top online retailers have yet to adopt stringent secure email measures, leaving customers exposed to phishing attacks and other email fraud risks.

With an estimated £800 million in increased spending anticipated this year, cybercriminals are ready to exploit the surge in digital transactions.

Weak email security exposes shoppers

Proofpoint’s analysis centers on the adoption of Domain-based Message Authentication, Reporting, and Conformance (DMARC) protocols among the top 30 UK retailers. DMARC authenticates the sender’s identity and helpts to prevent malicious emails from reaching consumers.

However, only 60% of these retailers have implemented the strictest level of DMARC protection, which actively blocks fraudulent messages. Alarmingly, 7% of retailers have no DMARC protection at all, leaving their domains wide open to impersonation and fraud.

While there has been some progress compared to 2023, when 47% of retailers lacked proactive measures, the current level of non-compliance remains a significant concern. The pre-festive shopping season, marked by Black Friday and Cyber Monday, is prime time for cybercriminals to launch attacks.

Fraudulent emails masquerading as legitimate offers from well-known brands are common tactics used to lure unsuspecting shoppers. These emails often contain malicious links, direct users to counterfeit websites, or request sensitive personal information under the guise of verifying purchases.

Proofpoint also warns against "smishing," or phishing via SMS, as well as social media scams which exploit shoppers’ eagerness to find bargains.

Proofpoint recommends that shoppers avoid reusing passwords across different platforms and use a password manager which simplifies password management while improving overall security. Adding multi-factor authentication to your accounts also provides an extra layer of defense.

Rather than clicking on links embedded in emails or messages, Proofpoint recommends that shoppers manually enter the retailer's official web address into a web browser, and to research unfamiliar sites by reading customer reviews and checking for complaints.

You might also like

TOPICS
Efosa Udinmwen
Freelance Journalist

Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity. Upon joining TechRadar Pro, in addition to privacy and technology policy, he is also focused on B2B security products. Efosa can be contacted at this email: udinmwenefosa@gmail.com

Read more
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Help! We're drowning in email spam, it's about to get worse and there's nothing we can do to stop it
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
A graphic showing someone on a tablet working through a supply chain.
How phishing attacks are hitting the supply chain – and how to fight back
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring