Trends Are Shifting for Cyberattacks Targeting Retailers
Okta’s 2025 Customer Identity Trends Report shows nearly half (46%) of all digital registration attempts across the globe are classified as malicious identity attacks. “For retail and e-commerce, this battlefield is exponentially worse. Bad actors are not just trying to log in to existing accounts; they are deploying massive, automated botnets to create fraudulent new accounts at scale,” Kumbhat says. He explains that these accounts and compromised credentials act as the basis for multiple types of attacks, including:
Loyalty and promo abuse.
Fraudsters use automated credentials to mass-register and drain signup bonuses, gift card balances and promo rewards.
Inventory hoarding.
Attackers deploy shopping bots to buy up high-demand, limited-run inventory instantly using fake credentials, forcing physical retail shrinkage and massive digital cart abandonment losses.
Refund fraud.
Using credential stuffing to take over trusted customer accounts, bad actors fabricate virtual receipts and process fraudulent returns directly to clean bank cards or untraceable gift cards.
There’s also a disconnect between customer trust and perceived customer trust, further exacerbated when cyberattacks derail the trust that does exist. PwC’s 2024 Trust Survey reports that the majority (90%) of business executives think customers trust their companies, when only 30% of consumers actually do.
DIVE DEEPER: Read more about how retailers are modernizing their loss prevention strategies.
Zero-Trust Security Is Changing How Retail IT Leaders Combat Loss
IAM addresses a leading gap in security, helping with “systemic overprovisioning and fragmented, unmanaged nonhuman identities, which are the two most common gaps retailers are facing,” Kumbhat says. Overprovisioning often occurs as retailers hire seasonal employees, who may account for up to 50% of their staff, and as they deal with generally high employee turnover rates in the industry. This creates a “massive lingering attack surface,” Kumbhat says, as old accounts aren’t deprovisioned right away.
“And, when you factor in the nonhuman identities or AI agents, that attack surface multiplies. Nonhuman identities, such as API keys, third-party vendor integrations and emerging AI shopping or inventory agents, vastly outnumber humans,” he adds. “These are often overprovisioned with permanent, high-privilege service accounts that lack human oversight, creating massive backdoor vulnerabilities.”
Faster Solutions Must Maintain Security Without Holding Up Sales
There isn’t much a potential customer will tolerate by way of delays in the buying process, either in person or digitally. The entire session must be secured whether at a physical kiosk in a retail setting or online. IT leaders must consider the fastest and least prohibitive solutions to maintain security without slowing down the buyer.
“It requires a shift toward low-friction, passwordless, continuous trust models. Forcing a frontline retail worker to type in passwords or wait for SMS one-time passcodes every time they step away from a terminal completely stalls checkout lines,” says Kumbhat. To replace such high-friction MFA, biometrics and passwordless standards can help.
“This involves using secure physical badges paired with biometrics, such as FastPass or passkeys, to verify identity in milliseconds, combined with continuous session evaluation that automatically locks the terminal the second anomalies like geographic or behavioral mismatches are detected,” he says.
