Sony Pixel Power calrec Sony

AI-driven Attacks Targeting Retailers Ahead of the Holiday Shopping Season

21/10/2024

Facebook

Twitter

LinkedIn

Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, warns that as generative AI tools and Large Language Models (LLMs) continue to proliferate and advance, cybercriminals are increasingly using these technologies to enhance the scale and sophistication of their attacks on eCommerce platforms.

With sales beginning as early as October and extending through late December, the holiday shopping season represents a critical time for online retailers. The surge in activity not only drives substantial revenue but also attracts malicious actors targeting retailers at a time when they can least afford downtime or a security incident. As this crucial period approaches, retailers must prepare for a range of AI-driven threats, including bots, distributed denial of service (DDoS) attacks, API violations, and business logic abuse.

While cybersecurity threats are a concern year-round, they become even more pronounced during the holiday shopping season, when retailers often experience record-breaking sales, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. Cybercriminals recognize this and are using generative AI tools and LLMs to capitalize on the increased volume of digital transactions, limited-time promotions, and the gift cards and loyalty points stored in customer accounts.

In a recent 6-month analysis (April 2024 - September 2024), data from Imperva Threat Research reveals that, on average, retail sites collectively experience 569,884 AI-driven attacks each day. These attacks originate from AI tools like ChatGPT, Claude, and Gemini, alongside specialized bots that are designed to scrape websites for LLM training data. An analysis of these attacks shows that cybercriminals are primarily using the AI tools to carry out the following types of attacks.

Business Logic Abuse: The most common AI-driven attack (30.7%), business logic abuse involves exploiting the legitimate functionalities of an application or API to carry out malicious actions, such as manipulating prices, bypassing authentication, or abusing discount codes. AI enables attackers to automate these exploits at scale, making them harder to detect. To protect against these attacks, retailers should implement strict validation on all user inputs, employ anomaly detection systems to identify unusual activities, and regularly audit their business processes to identify functionalities that could be abused.

DDoS Attacks: Representing 30.6% of all AI-driven threats to retailers, DDoS attacks aim to overwhelm a website's resources, resulting in downtime that can lead to lost sales and reputational damage-especially during peak shopping periods. Cybercriminals are now leveraging AI to coordinate large botnets more efficiently, enhancing the effectiveness of these attacks. Retailers should invest in a DDoS protection solution that utilizes machine learning to identify and mitigate malicious traffic in real time, ensuring that legitimate customers are not impacted.

Bad Bot Attacks: Attacks from bad bots account for 20.8% of AI-driven threats targeting retailers. These automated threats engage in disruptive activities such as scraping pricing data, credential stuffing, and inventory hoarding (scalping). The infamous Grinch bot, in particular, is notorious for its inventory hoarding during the holiday shopping season, making it increasingly difficult for consumers to purchase high-demand items. With advancements in AI, operators can now create bots that convincingly mimic human behavior, allowing them to evade traditional security measures. To combat this threat, retailers should implement bot management solutions that utilize behavioral analytics to differentiate between genuine users and sophisticated bots.



API Violations: As eCommerce platforms increasingly expose APIs for mobile applications and third-party integrations, API violations are on the rise, accounting for 16.1% of AI-driven attacks on retailers. Cybercriminals exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or functionality. With the assistance of AI, attackers can quickly identify weak points in API implementations, making these threats particularly challenging to mitigate. To safeguard their APIs, retailers should enforce strict authentication and authorization protocols, implement rate limiting to prevent abuse, and regularly conduct comprehensive security assessments and penetration testing.

These AI-driven attacks pose significant risks not only for retailers but also for consumers. Cybercriminals are leveraging AI to conduct bot attacks, abuse business logic, and disrupt systems, putting sensitive personal information-including credit card details, addresses, and account information-at increased risk. Successful attacks can lead to identity theft, financial loss, and a loss of trust in eCommerce platforms, with fraudulent charges and unauthorized account access negatively affecting consumers shopping experiences.

In previous years, weve seen security threats like Grinch bots and DDoS attacks cause major disruptions during the holiday shopping season, affecting both retailers and consumers alike. Now, with the widespread availability of generative AI tools and LLMs, retailers are contending with a new wave of sophisticated cyberthreats, adds Singh. Without robust defenses, retailers risk facing a perfect storm of AI-driven attacks that could disrupt operations, compromise customer data, and tarnish their reputations during the most critical time of the year. To effectively mitigate these threats, retailers must adopt a comprehensive strategy that not only defends against these attacks but also allows them to respond swiftly without disrupting the shopping experience.

Additional Information:
LINK: https://www.thalesgroup.com/en/worldwide/digital-identity-and-security...
See more stories from thales

More from Thales

30/06/2025

Thales 2025 Global Cloud Security Study Reveals Organizations Struggle to Secure Expanding, AI-Driven Cloud Environments

Facebook Twitter LinkedIn 52% report AI security spending is displacing tr...

30/06/2025

Thales Alenia Space to develop SOLiS very-high-throughput laser communications demonstrator

Facebook Twitter LinkedIn Cannes, June 30th, 2025 - Thales Alenia Space, t...

27/06/2025

Thales and KONGSBERG to establish new major Defence communications joint venture in Norway

Facebook Twitter LinkedIn Thales, a global high-tech leader, and Kongsberg...

26/06/2025

The European Space Agency awards Thales Alenia Space the study of the SIRIUS mission to monitor Urban Heat Islands from space

Facebook Twitter LinkedIn Madrid, June 26, 2025 - The European Space Agenc...

24/06/2025

Thales Launches File Activity Monitoring (FAM) to Strengthen Real-Time Visibility and Control Over Unstructured Data

Facebook Twitter LinkedIn New capability gives instant visibility to detec...

24/06/2025

Imperva Application Security Integrates API Detection and Response, Setting A New Standard in API Security

Facebook Twitter LinkedIn First unified, single-pane-of-glass platform to ...

24/06/2025

Thales celebrates American Airlines 1st 787-9 aircraft flying with AVANT Up Inflight Entertainment System

Facebook Twitter LinkedIn The American Airlines 787-9 takes flight with Th...

20/06/2025

Thales supports airspace sovereignty in Albania with Ground Master 400 Alpha surveillance radar

Facebook Twitter LinkedIn At the Paris Air Show, in the presence of the Fr...

19/06/2025

Thales and Terma sign a Memorandum of Understanding to expand cooperation in the Air, Naval and Space domains

Facebook Twitter LinkedIn Thales, a global technology leader for the Defen...

12/06/2025

Thales ranked No.1 most attractive employer among engineering students in France in 2025

Facebook Twitter LinkedIn Thales has secured the top spot in the 2025 rank...

12/06/2025

Thales invests 55 million euros to anchor next-generation resilient navigation in France

Facebook Twitter LinkedIn Thales strengthens its European leadership in re...

11/06/2025

Software Rpublique unveils "vision 4rescue", an integrated technological ecosystem for the next-gen of Emergency Services

Facebook Twitter LinkedIn In response to the increasing frequency and inte...

05/06/2025

Vietnam Space Committee, OSB Group and Thales Partner to Promote Education and Innovation in Space Technologies

Facebook Twitter LinkedIn Vietnam has been building a national framework t...

04/06/2025

Thales Unveils State-of-the-Art Inflight Entertainment & Services Lab at its Engineering Competence Centre in Bengaluru

Facebook Twitter LinkedIn The new lab, dedicated to development of Infligh...

03/06/2025

Thales reinvents secure payment systems for a data-driven future, showcasing leadership at Money20/20 Europe

Facebook Twitter LinkedIn Payment systems must evolve beyond traditional c...

02/06/2025

cortAIx SG: Thales Accelerates Trusted AI Innovation in Singapore with Strategic Partnerships

Facebook Twitter LinkedIn Thales's global acceleration in trusted AI e...

02/06/2025

Cyshield uses Thales technology to launch Egypt's first connectivity service for eSIM devices

Facebook Twitter LinkedIn Cyshield, a leading digital solutions company, s...

22/05/2025

Thales Reinforces Commitment to Malaysia at LIMA 2025 with New Leadership and Contracts Awarded

Facebook Twitter LinkedIn As a strategic partner in helping Malaysia achie...

21/05/2025

Tawazun Council and Thales Sign Agreement to Establish Ground Master Air Surveillance Radar Production Facility in UAE

Facebook Twitter LinkedIn As part of the Tawazun Economic Program, Thales ...

19/05/2025

Thales to provide a cyber-secured and AI-powered autonomous mine countermeasures system to the Republic of Singapore Navy

Facebook Twitter LinkedIn The unique, sea-proven Pathmaster solution will ...

19/05/2025

Thales, Radiall and FoxConn have initiated preliminary discussions on semiconductor production

Facebook Twitter LinkedIn Thales, Radiall and FoxConn announce they have i...

15/05/2025

Thales powers one million digital payment experiences with Vipps mobile wallet in Norway

Facebook Twitter LinkedIn Thales fully supports the success of Vipps, Norw...

15/05/2025

Thales boosts Air Traffic Management System for Serbia and Montenegro Air Traffic Services SMATSA

Facebook Twitter LinkedIn Serbia and Montenegro Air Traffic Services SMATS...

15/05/2025

Thales inaugurates GenF, a first step towards nuclear fusion energy

Facebook Twitter LinkedIn Thales, a global leader in high-power lasers, will inaugurate GenF on Thursday 15 May 2025 in Le Barp (Bordeaux). GenF aims to t...

13/05/2025

Thales celebrates 50 years in Greece

Facebook Twitter LinkedIn On the occasion of DEFEA, Greece's premier defence exhibition, Thales, a global leader in advanced technologies for the Defe...

13/05/2025

Thales launches TRAC SIGMA - an innovative multi-mission Primary Surveillance Radar for Approach and Long-Range Air Surveillance

Facebook Twitter LinkedIn Thales unveils its new multi-mission Primary Sur...

30/04/2025

Thales modernises the world-class TACTIS armoured vehicle training centre for the Royal Netherlands Army

Facebook Twitter LinkedIn Thales has secured a major contract to modernise...

29/04/2025

One out of three secure civil IDs delivered each year is powered by Thales

Facebook Twitter LinkedIn In a world where identity fraud represents a critical vulnerability for citizens and societies, Thales is leading the transforma...

25/04/2025

Thales and Deloitte form Strategic Alliance to Help Enhance Data Protection and Governance Services

Facebook Twitter LinkedIn Enhancing Data Protection and Governance Service...

24/04/2025

Thales reports its order intake and sales for the first quarter of 2025

Facebook Twitter LinkedIn Order intake: 3.8 billion, down -25% (-27% on an organic basis1) Sales: 5.0 billion, up 12.2% ( 9.9% on an organic basis) A...

23/04/2025

Thales and Michelin drive software revenue growth with innovative simulation software

Facebook Twitter LinkedIn Enables Michelin to focus on development of its ...

17/04/2025

MGCS Project Company GmbH (MPC) established in Cologne

Facebook Twitter LinkedIn Thursday, 17 April 2025 - The next step has now been taken in the Franco-German armaments project Main Ground Combat System (MGC...

14/04/2025

Thales to supply NATO with latest-generation situational awareness solution to ensure decision superiority

Facebook Twitter LinkedIn Thales has been selected by NATO to deliver phas...

08/04/2025

U.S. Air Force awards NSPA F-16 Helmet Mounted Display contract for Thales Scorpion HMD

Facebook Twitter LinkedIn Thales Thales subsidiary, Thales Defense &...

08/04/2025

Thales revolutionizes Inflight Entertainment (IFE) with 360Stream Live TV and innovative Near-Live highlights

Facebook Twitter LinkedIn Thales revolutionizes inflight TV with 360Stream...

07/04/2025

Thales signs a contract to deliver the Ground Master 200 MM/C Multi Mission Compact radar to Sweden

Facebook Twitter LinkedIn The Swedish Defence Materiel Administration (F r...

07/04/2025

Thales announces next-generation Inertial Measurement Unit (IMU) for resilient navigation

Facebook Twitter LinkedIn Thales is a global leader in inertial navigation...

03/04/2025

Thales to recruit 8,000 people in 2025 and accelerate its 'Learning company' programme

Facebook Twitter LinkedIn Thales, a global leader in advanced technologies...

02/04/2025

Thales Alenia Space wins 51 million contract to extend EGNOS service life

Facebook Twitter LinkedIn Strengthening Europe's critical navigation infrastructure thanks to EGNOS satellite-based augmentation system Cannes, April ...

01/04/2025

DSTA and Thales Announce AI-Driven Co-Lab to Strengthen Singapore's Defence Systems

Facebook Twitter LinkedIn Defence Science and Technology Agency (DSTA) and...

31/03/2025

Thales unveils its PANORAMIC quad-tube night vision goggle

Facebook Twitter LinkedIn Presented for the first time at SOFINS1, PANORAMIC is a lightweight, compact night vision goggle equipped with four light intens...