
ARMONK, N.Y. - 05 Jan 2015: According to findings released today by IBM (NYSE: IBM), despite an 50 percent decline in the number of cyber attacks against U.S. retailers, the number of records stolen from them remains at near record highs. IBM Security researchers report that in 2014, cyber attackers still managed to steal more than 61 million records from retailers despite the decline in attacks, demonstrating cyber criminal's increasing sophistication and efficiency.
Contrary to what most would expect, the majority of cyber attackers scaled back their hacking efforts around Black Friday and Cyber Monday in 2014 rather than capitalize from the massive spike in retail spending. The 2014 Retail Research and Intelligence Report and the Holiday Trends: Black Friday/Cyber Monday Research and Intelligence Report were created by IBM's Managed Security Services team of analysts, who monitor more than 20 billion security incidents every day.
According to the research, cyber attackers are becoming increasingly more sophisticated, using new techniques to obtain massive amounts of confidential records with increased efficiency. Since 2012, the number of breaches reported by retailers dropped by 50 percent. Despite this decline, the perpetrators were able to impact a far greater number of victims with each incident.
The threat from organized cyber crime rings remains the largest security challenge for retailers, said Kris Lovejoy, General Manager, IBM Security Services. It is imperative that security leaders and CISOs in particular, use their growing influence to ensure they have the right people, processes and technology in place to take on these growing threats.
Black Friday and Cyber Monday
Identified as the two biggest shopping days of the year by IBM's Digital Analytics Benchmark, cyber attackers reduced their activity across all industries on Black Friday and Cyber Monday, rather than taking action. When looking at the two week period (Nov 24 - Dec 5) around these days, the data shows the following activity across all industries:
The number of daily cyber attacks was 3,043, nearly one third less than the 4,200 average over this period in 2013.
From 2013 and 2014, the number of breaches dropped by more than 50 percent for Black Friday and Cyber Monday.
In 2013, there were more than 20 breaches disclosed including several large breaches that caused the number of records compromised to rise drastically, reaching close to 4 million.
Over the same period in 2014, 10 breaches were disclosed which resulted in just over 72,000 records getting compromised
Despite this cyber threat slow down, the retail and wholesale industries emerged as the top industry target for attackers in 2014, a potential result of the wave of high profile incidents impacting name brand retailers. In the two years prior, manufacturing ranked first amongst the top five attacked industries while the retail and wholesale industry ranked last. This past year, the primary mode of attack was unauthorized access via Secure Shell Brute Force attacks, which surpassed malicious code, the top choice in 2012 and 2013.
Top Breaches Overshadow Growing Trend
Attackers secured more than 61 million records in 2014, down from almost 73 million in 2013. However, when the data was narrowed down to only incidents involving less than 10 million records (which excludes the top two attacks over this timeframe, Target Corporation and The Home Depot), the data shows a different story--the number of retail records compromised in 2014 increased by more than 43 percent over 2013.
Sophisticated Methods of Attack
While there has been a rise in the number of Point of Sale (POS) malware attacks, the vast majority of incidents targeting the retail sector involved Command Injection or SQL injection. The complexity of SQL deployments and the lack of data validation performed by security administrators made retail databases a primary target. Over 2014, this Command Injection method was used in nearly 6,000 attacks against retailers. Additional methods include Shellshock as well as POS malware such as BlackPOS, Dexter, vSkimmer, Alina and Citadel.
The data for the number of records compromised and breaches disclosed was analyzed by IBM security experts and was made publically available by Privacy Rights Clearinghouse. The remaining data came from IBM's Managed Security services team.
About IBM Security
IBM's security platform provides the security intelligence to help organizations holistically protect their people, data, applications and infrastructure. IBM offers solutions for identity and access management, security information and event management, database security, application development, risk management, endpoint management, next-generation intrusion protection and more. IBM operates one of the world's broadest security research and development, and delivery organizations.
For more information, please visit www.ibm.com/security, follow @IBMSecurity on Twitter or visit the IBM Security Intelligence blog.
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
06/09/2026
June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
20/06/2026
New add-on creates doubles & vocal stacks
IK Multimedia's latest ReSing add-on kits the innovative software out with the ability to automatically genera...
20/06/2026
What exactly is Apogee Control V3?
Control V3 is a new mixer application that controls Apogee interfaces. The new hit feature is that V3 finally allows for...
19/06/2026
Split compound eases operational challenges at Shinnecock Hills Golf Club...
19/06/2026
North Carolina, Oklahoma meet in the best-of-three Finals as ESPN leans into spe...
19/06/2026
Company launch comprehensive mix-comparison tool
The Him DSP are a plug-in company founded by The Him, an EDM DJ and producer who has amassed over half a bi...
19/06/2026
Major Sampler upgrades introduced
The latest version of Bitwig's DAW software has just entered public beta testing, and is available now for all users w...
19/06/2026
Four times the power of their predecessors
Akai Pro have just introduced upgraded versions of two of their popular standalone MPC systems, kitting them out ...
19/06/2026
Data from May shows seasonal outdoor trends triggers lower viewing
Warsaw, Pola...
19/06/2026
Buttons is best control system in the rAVe Best of Infocomm Awards 2026...
19/06/2026
Mavis Studio Makes iPad Production More Powerful
Brie Clayton June 19, 2026
0 Comments
InfoComm update brings new NDI Preview, PTZ control, USB audio ...
19/06/2026
Immersive Studio Metaverse Stage Tackles Post with Blackmagic Design
Brie Clayton June 19, 2026
0 Comments
New narrative projects rely on DaVinci Reso...
19/06/2026
How to Run the Original 1993 After Effects
Graham Quince June 19, 2026
0 Comments
How to the original After Effects v1 in an emulator, and you don'...
19/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
19/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
19/06/2026
SMPTE , the home of media professionals, technologists and engineers, has announced that its entire Standards catalog is now freely available to the global medi...
19/06/2026
nsign, the digital signage SaaS platform built around its core principle of Simplify Complexity, has announced a partnership with BrightSign , expanding the dep...
19/06/2026
Visual Productions announces the availability of its new RdmRelay2 at InfoComm 2026 (ACT Entertainment, Booth N6813). A networked, four-channel DMX relay, it is...
19/06/2026
Adobe Unveils Major Expansion of Creative Agent Across Firefly and Creative Clou...
19/06/2026
Immersive Studio Metaverse Stage Innovates Storytelling with URSA Cine Immersive
Brie Clayton June 18, 2026
0 Comments
Two new narrative short films c...
19/06/2026
Friday 19 June 2026
How to watch the 2026/27 Premier League season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Premier League opening we...
19/06/2026
Catch up on the latest developments across Baselight and Daylight v7, Nara and FilmLight API Wednesday 8 July, 5pm onwards
Firehouse: DCTV, 87 Lafayette St, Ne...
19/06/2026
Lab studies explain how new cancer drug works as it enters patient testing Immunologists at Scripps Research show how a new, experimental drug revives immune ce...
18/06/2026
Ratings Roundup is a rundown of recent rating news and is derived from press rel...
18/06/2026
PTZOptics has unveiled new Visual Reasoning demonstrations at InfoComm 2026 (Boo...
18/06/2026
IBC2026 will take place at the RAI Amsterdam from September 11-14, bringing toge...
18/06/2026
InfoComm 2026 held its first-ever Media Day on June 17, providing journalists an...
18/06/2026
FOR-A America has announced a Trade Agreements Act (TAA)-compliant LED display solution combining Alfalite's Litepix LED displays and Brompton Technology...
18/06/2026
In-venue and creative video staffers at the professional and collegiate level have one major thing in common: the intensity and attention to detail ramps up dur...
18/06/2026
The International Federation of American Football (IFAF) and TMRW Sports have an...
18/06/2026
AJA Video Systems has unveiled Io Xpand, a Thunderbolt 5-enabled PCIe expansion ...
18/06/2026
ESPN has announced its coverage plans for the 30th anniversary of the WNBA's...
18/06/2026
FOX Sports' Big Noon Kickoff will broadcast live from Wembley Stadium in Lon...
18/06/2026
InfoComm 2026 opened on Wednesday at the Las Vegas Convention Center, bringing t...
18/06/2026
As media companies look to deliver more live, VOD, and snackable sports content ...
18/06/2026
Top L-R: Take Me Home, The Lake
Bottom L-R: TheyDream, Union County
Free Summer Screening Series Announced
Screenings for the Local Utah Community at...
18/06/2026
Improvements & new IR content
iamReverb Audio have just launched a free update that kits their convolution reverb plug-in out with some new features and int...
18/06/2026
Modelling suite gains improved captures, iOS support & more
Two notes Audio Engineering have just announced the launch of Genome 2.0, a significant update t...
18/06/2026
New AI assistance feature, video overhaul & more
VSL have just announced the launch of Vienna Ensemble Pro 8.1 and 8.1V, a pair of major updates to their ev...
18/06/2026
The average daily TV screen time in May was 3 hours and 36 minutes, marking a clear decrease of 15 minutes compared to April. This trend proved to be much stron...
18/06/2026
Integration embeds Gracenote content intelligence, including contextual segments...
18/06/2026
AJA Video Systems unveiled Io Xpand, a high-performance Thunderbolt 5-enabled PCIe expansion chassis for AJA KONA and Corvid video and audio I/O cards. As dema...
18/06/2026
New NVRT-driven workflow enables on-demand traffic mirroring and guided troubleshooting for AV teams, integrators, and support organizations ahead of InfoComm 2...
18/06/2026
At InfoComm 2026, Mavis announced a major update to Mavis Studio, its live production app for the iPad, with new features designed to make professional AV produ...
18/06/2026
Transaction Positions Harmonic as a Pure-Play Broadband Company
Harmonic Inc. (NASDAQ: HLIT), the worldwide leader in virtualized broadband solutions, today a...
18/06/2026
ACT Entertainment and NETGEAR have announced a strategic partnership that establishes verified interoperability between NETGEAR Switches and key technologies fr...
18/06/2026
IBC2026 is set to bring the global media, entertainment and technology community together at the RAI Amsterdam from 11 14 September, enabling industry players f...