Almost one-fifth of retailers suffer permanent data loss from cyber attacks: Kaspersky survey

  • 87% of retailers faced cyber incidents over the past 12 months. Kaspersky’s survey among retail and wholesale experts unveil insights into risks and challenges the industry faces and suggested ways to address them.

    Retail is moving into an AI‑driven and personalized landscape, where every digital touchpoint creates both convenience and risk. A new global study* conducted by Kaspersky’s Internal Research Center surveyed IT security specialists working in the retail sector across 18 countries and revealed key target areas, the most relevant threats, and the potential damage to business.

    Cyber incidents and the goals behind the attacks

    The retail sector, encompassing e-commerce, loyalty programs, and personalized offerings, spans the entire transaction process from initial browsing to final payment, thereby accumulating massive volumes of personal data. With only 13% of the sector escaping cyber incidents over the past year, it is clear that this environment is highly vulnerable to cyber threats and appealing for cybercriminals. 

    As for the nature of the recently experienced incidents, phishing appeared to be the prevalent threat, reported by more than one-fifth of retailers (21%). Other social engineering-related attacks on retailers featured deepfakes (13%), invoice or payment fraud (13%), business email compromise (9%), and vishing (voice phishing) (8%). The top 3 most frequently experienced incidents in retail organizations also comprised cyber espionage (19%) and web application exploits (18%).

    During attacks, adversaries’ primary aims were stealing clients’ and employees’ personal data (34% and 28% respectively). Taken together, this diversity of threats shows that retailers are exposed not only to manipulation of employees and partners, but also to technically complex attacks against their online infrastructure.

    Actual losses and measures taken

    The most common actual results of the recent attacks on retailers included clients' personal data theft (28%), financial loss (25%), and disruption of both business and operational processes (25%). In some cases, an attack could lead to very serious consequences that might threaten the existence of a business: irrecoverable data loss (19%) and irreversible damage to corporate assets or systems (16%).

    Among the most popular protection measures taken after the most harmful incident organizations had experienced, were the implementation of Zero Trust or the Principle of Least Privilege for employees, partners and contractors (31%), strengthening cloud security controls (30%), and installation of monitoring IT security solutions (30%).

    Internal incident risk factors

    The survey also raised the question of internal factors which increase the likelihood of successful cyberattacks on retailers. According to the poll, human actions tend to be the primary concern, with insufficient expertise among IT and security staff (27%) and a lack of security awareness (27%) topping the list. Technical shortcomings also had a strong impact: outdated software or hardware and the absence of centralized control over IT infrastructure are equally prevalent, at 23% each.

    A lack of security awareness may be the reason behind risky workplace behaviors and associated losses. When asked about most typical digital misbehavior of their colleagues, more than third of respondents (34%) stated the use of personal devices for work‑related activities and the storage of corporate data. Almost equally widespread, in 33% of companies, employees practice irresponsible password habits, including weak or reused passwords, and also connected corporate devices to public Wi‑Fi networks without using a secure connection.

    Budget changes and plans for future

    Willing to enhance their IT security function, 82% of retailers increased their IT security budget this year. Unlike the general trend across other sectors, where organizations are largely planning to expand their internal IT teams, the retail industry is increasingly turning to third-party IT security providers. Almost half of these companies (41%) have allocated new funding to outsource specific IT security functions, including employee education, MSSP, MDR, and the deployment of data protection technologies.

    AI is set to play a key role in the future of retail

    More companies are implementing AI tools in their infrastructure: 12% of retailers already have a working LLM-based tool, while 83% are currently in the discussion, design, or pilot phases. Although it speeds up the operations, Interestingly, 33% of retail companies claim they don’t see any risks in AI, which is significantly more than all industries’ indices (18%).

    “Retail is a highly dynamic industry: business priorities, workloads, infrastructure requirements, and economic conditions change rapidly. To ensure that cybersecurity keeps pace with these changes, retailers choose to turn to external security service providers, gaining access to the required expertise and technologies without having to continuously expand their in-house teams,” says Elizaveta Komarova, Solution Architect, Finance & Retail at Kaspersky. “By outsourcing part of their cybersecurity functions, retailers effectively entrust an external partner with the resilience of their business processes and the financial risks associated with security incidents. This makes it essential to have confidence in the provider’s experience, including a proven track record with retailers of different sizes, and to eliminate potential security blind spots through 24/7/365 protection. This is especially critical during peak periods, such as seasonal sales, periods of increased consumer demand, and holidays, when the cost of any disruption is particularly high and in-house teams may have limited availability”.

    Enhancing protection: recommendations for retail safety

    To prevent it or at least minimize its disruptive consequences of cyber incidents, Kaspersky recommends retail companies implement the following measures:

    ·      Elevate the organization’s overall cyber culture by implementing a continuous awareness program that regularly educates all employees about cybersecurity, stays up‑to‑date and includes the newest threat intelligence. This measure will foster a stronger security mindset and improve defensive behaviors.

    ·      Update or introduce the organization’s AI usage policies. These should explicitly address the risk of inadvertent data exposure. Define clear guidelines for how employees may interact with AI‑driven tools and specify what types of data can be entered, how to anonymize sensitive information, and which AI services are approved for use.

    ·      Identify the most valuable assets and essential business processes. Customer data, intellectual property, core applications, and supply‑chain workflows should stay entirely protected. This enables the organization to understand the most critical parts of the business and, therefore, to implement a more suitable defense system.

    ·      Regularly monitor the current state of cybersecurity in your industry. Conduct threat assessments and examine the most likely adversaries and vulnerabilities that could have the highest impact on operations. Retail Cybersecurity Solutions will allow to build a customized security control that maximizes effectiveness and stays up-to-date. They combine all the necessary features for stable growth and reliable protection from emerging threats.

    ·      Strengthen the capabilities of your digital environment: deploy advanced endpoint protection solutions on workstations, laptops, and mobile devices to detect and prevent cyber incidents. Ensure continuous updates of all security solutions so they stay aligned with emerging threats.

    More insights, best practices and recommendations for retailers are available by the link: https://www.kaspersky.com/enterprise-security/retail-cybersecurity

    *The study, conducted by Kaspersky Internal Research Center in 2026, surveyed IT security experts from 18 countries, targeting companies with 100+ employees across diverse industries. 1800 specialists and management representatives were interviewed, all of them working or being in charge of IT security functions. Retail sector is represented with a total of 120 respondents.

    حمّل تطبيق Alamrakamy| عالم رقمي الآن