Retail Cyberattacks Double in Three Years: Kaspersky
By Diego Valverde | Journalist & Industry Analyst -
Fri, 07/10/2026 - 11:40
Retail cybersecurity incidents have increased by more than 100% over the past three years, according to Kaspersky, as attackers increasingly target payment systems, customer data, employees, and supply chains. The company says retailers must prioritize data protection, workforce awareness, payment security, third-party risk management, and cyber resilience.
Cybersecurity incidents targeting the retail sector have more than doubled over the past three years. According to the latest Kaspersky’s cybersecurity in retail report, attacks are no longer limited to data theft but now threaten payment systems, business operations, supply chains and customer trust.
As retailers continue to rely on digital platforms, AI, connected ecosystems and personalized customer experiences, the amount of sensitive information they manage has grown significantly. Payment credentials, loyalty program data and customer profiles have become valuable assets for cybercriminals seeking financial fraud, identity theft and information that can be sold on the dark web.
"The retail sector has reached a stage where cybersecurity can no longer be viewed as technical support but as a condition for operating, selling and maintaining consumer trust," says Claudio Martinelli, General Manager for the Americas, Kaspersky.
Martinelli says digitalization has connected every part of retail operations, allowing a seemingly minor security breach to escalate into a large-scale commercial disruption. He notes that organizations should begin by identifying the business processes that cannot be interrupted and implementing the controls required to anticipate, reduce, and manage cyber risks before they affect operations or customer relationships.
Data and Payments Become Prime Targets
Kaspersky’s Cybersecurity as a Competitive Advantage in Retail report identifies data protection as one of the sector's most urgent priorities. Retailers increasingly depend on customer information to support personalized offers, dynamic pricing, artificial intelligence initiatives, and automated logistics. While these capabilities improve competitiveness, they also concentrate valuable data across connected platforms and third-party systems that present attractive targets for attackers.
Beyond the immediate operational impact, a major data breach can generate regulatory penalties, legal expenses, contractual liabilities and recovery costs that may reach as much as US$91 million for large retail organizations. Consumers demand both personalized experiences and stronger privacy protections, so companies face growing pressure to embed security and privacy into their data strategies from the outset.
Payment systems have also become a primary target because they represent the point where purchasing intent becomes revenue. The report warns that attackers increasingly seek to manipulate online transactions, steal credentials or intercept financial information during legitimate customer purchases.
Physical point-of-sale systems also remain vulnerable, particularly when integrated with customer platforms, loyalty programs, and broader corporate networks.
According to Kaspersky, cyberattacks capable of disrupting online stores or payment infrastructure can generate losses of up to US$20,000 per hour, making transaction security a business continuity issue rather than solely a fraud prevention measure.
Human Error and Supply Chains Expand the Attack Surface
Human error also remains one of the largest contributors to cybersecurity incidents. According to the report, between 64% and 86% of data breaches are linked to unintentional employee mistakes, including phishing attacks, weak passwords and improper credential management.
Kaspersky says social engineering campaigns have become increasingly sophisticated, with attackers using fake invoices, manipulated banking information, malicious API scripts and Business Email Compromise campaigns to deceive retail employees.
Recent attacks against retailers in the United Kingdom also demonstrate growing use of AI to strengthen psychological manipulation through deepfakes, voice cloning and highly personalized campaigns delivered through email, messaging applications, social media and collaboration platforms such as Microsoft Teams.
The report also highlights supply chain security as an area requiring greater attention. Modern retailers depend on a broad ecosystem of technology providers, logistics partners, cloud platforms and external vendors, meaning vulnerabilities affecting third parties can rapidly disrupt inventory management, product availability, payment processing, and customer service.
Kaspersky cites industry research showing that 30% of attacks targeting retailers involved business partners or suppliers. Despite this, only 9% of executives identify third-party risk as their primary cybersecurity concern, suggesting many organizations continue to underestimate supply chain exposure.
Cyber Resilience Becomes a Business Imperative
Kaspersky warns that sophisticated attacks have become more accessible as leaked source code, publicly available offensive tools and AI lower the barriers for cybercriminals.
Incidents affecting major retailers between 2024 and 2025 demonstrated how extended reconnaissance campaigns can ultimately result in operational downtime, productivity losses, costly remediation efforts, and risks to business continuity.
To strengthen resilience, Kaspersky recommends that retailers prioritize their most critical systems and business processes, improve employee cybersecurity awareness, implement advanced detection and response technologies, and leverage managed security and threat intelligence services to monitor evolving risks across increasingly complex digital environments.







