Sony Pixel Power calrec Sony

AI-driven Attacks Targeting Retailers Ahead of the Holiday Shopping Season

21/10/2024

Facebook

Twitter

LinkedIn

Imperva, a Thales company, the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, warns that as generative AI tools and Large Language Models (LLMs) continue to proliferate and advance, cybercriminals are increasingly using these technologies to enhance the scale and sophistication of their attacks on eCommerce platforms.

With sales beginning as early as October and extending through late December, the holiday shopping season represents a critical time for online retailers. The surge in activity not only drives substantial revenue but also attracts malicious actors targeting retailers at a time when they can least afford downtime or a security incident. As this crucial period approaches, retailers must prepare for a range of AI-driven threats, including bots, distributed denial of service (DDoS) attacks, API violations, and business logic abuse.

While cybersecurity threats are a concern year-round, they become even more pronounced during the holiday shopping season, when retailers often experience record-breaking sales, says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. Cybercriminals recognize this and are using generative AI tools and LLMs to capitalize on the increased volume of digital transactions, limited-time promotions, and the gift cards and loyalty points stored in customer accounts.

In a recent 6-month analysis (April 2024 - September 2024), data from Imperva Threat Research reveals that, on average, retail sites collectively experience 569,884 AI-driven attacks each day. These attacks originate from AI tools like ChatGPT, Claude, and Gemini, alongside specialized bots that are designed to scrape websites for LLM training data. An analysis of these attacks shows that cybercriminals are primarily using the AI tools to carry out the following types of attacks.

Business Logic Abuse: The most common AI-driven attack (30.7%), business logic abuse involves exploiting the legitimate functionalities of an application or API to carry out malicious actions, such as manipulating prices, bypassing authentication, or abusing discount codes. AI enables attackers to automate these exploits at scale, making them harder to detect. To protect against these attacks, retailers should implement strict validation on all user inputs, employ anomaly detection systems to identify unusual activities, and regularly audit their business processes to identify functionalities that could be abused.

DDoS Attacks: Representing 30.6% of all AI-driven threats to retailers, DDoS attacks aim to overwhelm a website's resources, resulting in downtime that can lead to lost sales and reputational damage-especially during peak shopping periods. Cybercriminals are now leveraging AI to coordinate large botnets more efficiently, enhancing the effectiveness of these attacks. Retailers should invest in a DDoS protection solution that utilizes machine learning to identify and mitigate malicious traffic in real time, ensuring that legitimate customers are not impacted.

Bad Bot Attacks: Attacks from bad bots account for 20.8% of AI-driven threats targeting retailers. These automated threats engage in disruptive activities such as scraping pricing data, credential stuffing, and inventory hoarding (scalping). The infamous Grinch bot, in particular, is notorious for its inventory hoarding during the holiday shopping season, making it increasingly difficult for consumers to purchase high-demand items. With advancements in AI, operators can now create bots that convincingly mimic human behavior, allowing them to evade traditional security measures. To combat this threat, retailers should implement bot management solutions that utilize behavioral analytics to differentiate between genuine users and sophisticated bots.



API Violations: As eCommerce platforms increasingly expose APIs for mobile applications and third-party integrations, API violations are on the rise, accounting for 16.1% of AI-driven attacks on retailers. Cybercriminals exploit vulnerabilities in APIs to gain unauthorized access to sensitive data or functionality. With the assistance of AI, attackers can quickly identify weak points in API implementations, making these threats particularly challenging to mitigate. To safeguard their APIs, retailers should enforce strict authentication and authorization protocols, implement rate limiting to prevent abuse, and regularly conduct comprehensive security assessments and penetration testing.

These AI-driven attacks pose significant risks not only for retailers but also for consumers. Cybercriminals are leveraging AI to conduct bot attacks, abuse business logic, and disrupt systems, putting sensitive personal information-including credit card details, addresses, and account information-at increased risk. Successful attacks can lead to identity theft, financial loss, and a loss of trust in eCommerce platforms, with fraudulent charges and unauthorized account access negatively affecting consumers shopping experiences.

In previous years, weve seen security threats like Grinch bots and DDoS attacks cause major disruptions during the holiday shopping season, affecting both retailers and consumers alike. Now, with the widespread availability of generative AI tools and LLMs, retailers are contending with a new wave of sophisticated cyberthreats, adds Singh. Without robust defenses, retailers risk facing a perfect storm of AI-driven attacks that could disrupt operations, compromise customer data, and tarnish their reputations during the most critical time of the year. To effectively mitigate these threats, retailers must adopt a comprehensive strategy that not only defends against these attacks but also allows them to respond swiftly without disrupting the shopping experience.

Additional Information:
LINK: https://www.thalesgroup.com/en/worldwide/digital-identity-and-security...
See more stories from thales

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

14/03/2026

Study: Applied AI Moving Into Core Media Workflows

Share Copy link Facebook X Linkedin Bluesky Email...

14/03/2026

GlobalM to Showcase Live IP Media Transport at 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

14/03/2026

Milano Cortina 2026 - Yospace helps ad-funded rights-hold...

Yospace, the trusted leader in Dynamic Ad Insertion (DAI), stitched 5.4 billion one-to-one addressable OTT advertisements across the 17 days of Milano Cortina 2...

14/03/2026

Telestream Advances Production-Ready AI Across Its Product Portfolio

Telestream Advances Production-Ready AI Across Its Product Portfolio Brie Clayton March 13, 2026 0 Comments New AI capabilities drive smarter automati...

14/03/2026

Kraken Graded in DaVinci Resolve Studio

Kraken Graded in DaVinci Resolve Studio Brie Clayton March 13, 2026 0 Comments Senior Colorist Dylan Hopkin delivers the first Scandinavian feature in...

14/03/2026

Tedial Powers the Future of Media Operations at NAB Show 2026

Tedial Powers the Future of Media Operations at NAB Show 2026 Brie Clayton March 13, 2026 0 Comments Transforming Media Through Intelligence, Flexibil...

13/03/2026

SVG Sit-Down: Net Insight's Andreas Eriksson on Scalable, Predictable Live-Media Infrastructure

Recently named CEO Andreas Eriksson has taken the helm at Net Insight at a pivot...

13/03/2026

Scripps Sports To Broadcast First PWHL Game on National TV in U.S.

Scripps Sports and Ally Financial are partnering with the Professional Women's Hockey League (PWHL) to broadcast its first game on national linear televisio...

13/03/2026

Disney+ Follows in ESPN's Footsteps With Launch of Verts Vertical Video Feed on Mobile

Disney+ has launched Verts, a vertical video feed on its U.S. mobile app, markin...

13/03/2026

LTN and Appear Announce Integrated Solution for Live Event Video Transport and Distribution

LTN, a managed IP video transport company, and Appear, a live production technol...

13/03/2026

PFL Signs Betting Data and Streaming Agreement With Sportradar

The Professional Fighters League (PFL) has announced an agreement with Sportradar for global betting data and streaming rights. Under the deal, Sportradar becom...

13/03/2026

SVG GameDay, Ep. 7: Milwaukee Brewers' Jami Patton - Game Pres with the Brew Crew

In-venue and creative video staffers at the professional and collegiate level ha...

13/03/2026

Peacock To Add Vertical Video Option for Live NBA Games

The streamer will be the first entertainment platform to offer AI-enabled vertical video for live games, starting with the NBA...

13/03/2026

Ease Live Deploys Interactive Overlay Platform on Red Bull TV for Premier Padel

Ease Live, an Evertz company specializing in interactive graphical overlays, has deployed its platform on Red Bull TV for Premier Padel coverage. The deployment...

13/03/2026

ESPN's Andy Jacobson on Pushing the Envelope to Debut MNF Playbook'

Monday Night Football, ESPN's premiere NFL property, has continued to be improved and upgraded from a production perspective. Alternative broadcasts are aug...

13/03/2026

NAB 2026: Net Insight Introduces Nimbra 520 Media Processing Node

At NAB Show 2026, Net Insight (booth W1653) is introducing the Nimbra 520, a high-density media processing node for live contribution and distribution across ma...

13/03/2026

NAB 2026: Harmonic Takes Wraps Off Spectrum X Plus Media Server

Harmonic (booth W2831) has announced Spectrum X Plus, the newest generation of its Spectrum X media server, offering double the channel density of previous gene...

13/03/2026

Riedel Communications Appoints Jan Schaffner as VP of Managed Technology Americas

Riedel Communications has announced the expansion of its Managed Technology Divi...

13/03/2026

NAB 2026: Telestream Launches UP, a Cloud-Native Ingest and Monitoring Solution

Telestream (booth W1503) has announced the expansion of Telestream Cloud Services with the introduction of UP, a cloud-native solution for ingest, orchestration...

13/03/2026

It's Showtime! Production Pros Bring Awards Shows, Festivals, and Other Events to Life

From awards ceremonies and sports honors shows to festivals and fan conventions,...

13/03/2026

Overtime Partners with Metro by T-Mobile for OTE and Overtime Select Basketball Leagues

Overtime has announced a partnership with Metro by T-Mobile, naming Metro the Of...

13/03/2026

NAB 2026: Calrec to Showcase IP Ecosystem and Plethora of New Products

At NAB 2026, Calrec (booth C6907) will IP Ecosystem powered by True Control 2.0, integrating the company's IP-native Argo consoles - including the U.S. debu...

13/03/2026

Ratings Roundup: FOX Smashes WBC Records, ESPN Nets Best College Hoops Audience in 10+ Years

Ratings Roundup is a rundown of recent ratings news derived from press releases ...

13/03/2026

A New Era of Personalization: Shape Your Taste Profile on Spotify

Spotify has always been built around your taste. More than 80% of listeners say personalization is what they love most about us. Now we're taking that even ...

13/03/2026

Spotify Debuts Legends Club for Popular German-Language Podcasts With Kaulitz Hills'

The new Spotify Legends Club has opened its doors. Its members: select German-sp...

13/03/2026

Klevgrand release OneShot2

Pushing drum sampler technology into new territories The latest version of Klevgrand's software drum sampler has just arrived, boasting a newly designe...

13/03/2026

IK Multimedia update ARC On-Ear

Expanded headphone support & engine improvements IK Multimedia's recently introduced ARC On-Ear system brings the power of their monitoring-correction s...

13/03/2026

UVI introduce Mosaiq 26

Extra sound collections, more presets & new Keys category UVI's rhythm and pattern instrument has just received a major update that introduces four new ...

13/03/2026

Missionized Business Jets: Fielded and Flying

Over a year ago, L3Harris delivered the first missionized Bombardier Global 6500 aircraft for U.S. Indo-Pacific Command. Two ATHENA-R platforms now average 400+...

13/03/2026

GFiber and Stonepeak's Astound Broadband to Merge

Share Copy link Facebook X Linkedin Bluesky Email...

13/03/2026

Harmonic Redefines the Economics of Video Playout with Ne...

Harmonic (NASDAQ: HLIT) today announced Spectrum X Plus, the newest generation of its Spectrum X media server, offering double the channel density of previous ...

13/03/2026

Historic Ewing Covenant Church Revitalizes Worship Experi...

When Ewing Covenant Church made the decision to return to its original, historic building, affectionately called 1867 Sanctuary for weekly worship, the congre...

13/03/2026

Marshall Electronics Launches CV574 WP its First 4K All I...

Marshall Electronics introduces its first all-IP 4K POV camera, the CV574-WP, at NAB 2026 (Booth C8339). The CV574-WP supports NDI |HX, providing ultra-efficien...

13/03/2026

Net Insight launches Nimbra 520 - Predictable Live Media...

At NAB Show 2026, Net Insight introduces Nimbra 520, a high-density media processing node designed to simplify live contribution and distribution across both ma...

13/03/2026

Abandon Editorial Signs With Michal Dimitri for West Coast Representation

Abandon Editorial Signs With Micha l Dimitri for West Coast Representation Brie Clayton March 12, 2026 0 Comments Abandon Editorial is excited to part...

13/03/2026

Documentary The Bulldogs Shot and Edited with Blackmagic Design

Documentary The Bulldogs Shot and Edited with Blackmagic Design Brie Clayton March 12, 2026 0 Comments Editorial tools helped shape film in real time,...

13/03/2026

AE Captions as Fast as CapCut - No Plugins

AE Captions as Fast as CapCut - No Plugins Graham Quince March 12, 2026 0 Comments Stop wasting hours clicking through nested compositions and manuall...

13/03/2026

New Music USA and Berklee Institute of Jazz and Gender Justice Announce 2026 Next Jazz Legacy Cohort

New Music USA and Berklee Institute of Jazz and Gender Justice Announce 2026 Nex...

13/03/2026

VEON Delivers Record Digital Growth: 4Q25 Digital Revenues Grow 84% to 20.1% of Total, Driving 17% Revenue and 29% EBITDA Growth in 4Q25

13 Mar 2026 VEON Delivers Record Digital Growth: 4Q25 Digital Revenues Grow 84%...

13/03/2026

Sky Adds Blood on Snow to Original Film Slate in Acquisition Headlined by Benedict Cumberbatch and Aaron TaylorJohnson

Friday 13 March 2026 Sky Adds Blood on Snow to Original Film Slate in Acquisiti...

13/03/2026

RT announces Rick O'Shea as new presenter on RT Radio 1's Arena

RT has announced today that Rick O'Shea is the new presenter of Arena RT Radio 1's flagship weeknight arts and culture programme. Rick has been pres...

13/03/2026

Lights! Camera! Action! The 98th Oscars set to air live as RT backs the Irish nominees

Lights! Camera! Action! The 98th Oscars set to air live as RT backs the Irish n...

12/03/2026

Milano Cortina 2026: Yospace helps ad-funded rights-holders claim advertising gold

Staines-upon-Thames, UK, 11th March, 2026 - Yospace, the trusted leader in Dyna...

12/03/2026

Utah Scientific Expands Technology Partner Program With Integrations From Audinate, Bitfocus, and Skaarhoj

Utah Scientific Expands Technology Partner Program With Integrations From Audina...

12/03/2026

Techex Hires Matt McKee as Senior Director, Sales, Americas

Techex, a global expert in live video solutions over IP and cloud, announces the appointment of Matt McKee as Senior Director, Sales, Americas, further strength...