logo
Retail cyberattacks: AI making threats 'more advanced and personalised'

Retail cyberattacks: AI making threats 'more advanced and personalised'

Yahoo2 days ago

The use of artificial intelligence (AI) by perpetrators of cyberattacks is increasing the threat to retailers and their customers, according to a cybersecurity industry leader.
Speaking on an episode of GlobalData's Instant Insights podcast, Charlotte Wilson, head of enterprise sales at cybersecurity company Check Point Software, said that while the form that cyberattacks take has not changed a great deal, AI is being used to make them more effective.
This embedded content is not available in your region.
'I think they're getting far more advanced and highly personalised because of AI,' said Wilson. 'If you take this retail attack, any of the retailers right now, the primary attack is to get the money from the retailer to free up access back to their information, and that's the ransomware itself for the company, the retailer, to pay or not pay or negotiate.
'The secondary attack is all that information that has been gathered can then be sold to other people that then might do a secondary activity with it. And that's where some of the sophistication comes in. That's where social engineering comes in.'
Social engineering is the practice of deceiving and manipulating individuals into performing specific actions. It is a well-known tactic of email scammers who purport to be people or companies that they are not to trick victims into giving them personal information.
Of the role of retail cyberattacks in facilitating this, Wilson explained: 'There's the first attack, which is to the retailer. The secondary attack is to you and me, the mums and dads, brothers and sisters, the consumer – and AI is making them something you're more likely to click on because they're much more personalised.
'It could be so much as, 'I see that you bought this in the last time that you visited our store. We hope that was great for you. Here's some personalised offers for you based on what you like to shop for,' and if I've got access to you as a loyalty scheme customer, I probably know quite a bit about you.'
Wilson was speaking on the episode following the recent spate of cyberattack targeting UK retailers including Marks and Spencer, Co-op and Harrods. They are thought to have been perpetrated by a group known as Scattered Spider using a ransomware-as-a-service platform called DragonForce, of which Wilson says: 'There will be operators that design the ransomware attacks and the malware, and then there are affiliates that will go and use those and exploit it and hold people to ransom. They sometimes have a profit-share model, so it's a profitable way of doing cybercrime.'
Despite widespread coverage of the recent attacks, Check Point, which carries out its own cybersecurity research, finds retail to be only the fifth most hacked industry at present.
'It's way, way behind education, government and healthcare,' said Wilson. 'So, it's actually not the biggest attacked. We think they're dealing with about 300 attacks per week. It starts to get into the 1000s when you start to get into the other industries.
'However, obviously once you're in you can hold to ransom at a higher rate because it's so much more public, and you can see just the press at the moment is reporting the retail hacks pretty much every other day.'
Wilson went on to explain that retailers are at a particular disadvantage as they typically have a much larger potential attack surface than businesses in other industries.
'Retailers have an incredibly hard job because they're dealing with so many different suppliers of varying degrees,' said Wilson. 'The networks are dynamic. They have lots of things attached to them, so I think they have a really complex job, and, from a hacker's perspective, the path of least resistance is the one they'll choose.
'If you've got lots of things that you have to maintain, you have to make sure are patched, secured and controlled across many different interfaces, it's much easier for you to have something that isn't as up to date as it should be, or isn't as protected as it could be, they're much more susceptible to mistakes.'
Wilson gave two main recommendations for retailers to help keep their cybersecurity tight.
'One clear thing they can do is monitor the third-party access to their networks,' she said. 'One challenge that retailers have that is unique is that some of the suppliers to them might be quite small, and so may not hold the same level of security in their organisation as maybe the retailer is.'
In addition, she noted that collaboration between security and IT teams when patching vulnerabilities is required is not always adequate. Wilson is of the opinion that the handling of common vulnerability exploits (CVEs) – vulnerabilities that are identified and need to be patched – often fails as a result of miscommunication or misunderstanding between the two teams within a business.
'I just think the CVE part never really gets taken all that seriously,' she explained. 'That bit, for me, is a big thing. If it's being handled by your IT team as opposed to your security team, I think it's important that the security team stress the need for those certain CVEs that are critical to get patched and sorted, or to put those people outside of a blast zone.'
"Retail cyberattacks: AI making threats 'more advanced and personalised'" was originally created and published by Just Food, a GlobalData owned brand.
The information on this site has been included in good faith for general informational purposes only. It is not intended to amount to advice on which you should rely, and we give no representation, warranty or guarantee, whether express or implied as to its accuracy or completeness. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content on our site.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Classic Rock Band Has Instruments Stolen on Eve of Tour Launch
Classic Rock Band Has Instruments Stolen on Eve of Tour Launch

Yahoo

timean hour ago

  • Yahoo

Classic Rock Band Has Instruments Stolen on Eve of Tour Launch

Classic Rock Band Has Instruments Stolen on Eve of Tour Launch originally appeared on Parade. The classic rock band Heart had their tour plans marred when a thief took some of the band's precious gear as they prepared to kick off the latest leg of their tour on May 31 at the Hard Rock Live at Etess Arena in Atlantic City, N.J. Among the items missing is a custom-built, purple sparkle baritone Telecaster with a hand-painted headstock, made specifically for . Also stolen was a vintage 1966 Gibson EM-50 mandolin that band member has played for over 25 years. 🎬 SIGN UP for Parade's Daily newsletter to get the latest pop culture news & celebrity interviews delivered right to your inbox 🎬 'These instruments are more than just tools of our trade—they're extensions of our musical souls,' said Wilson in a statement. 'The baritone Tele was made uniquely for me, and Paul's mandolin has been with him for decades. We're heartbroken, and we're asking for their safe return—no questions asked. Their value to us is immeasurable.' Fans with information about the instruments are urged to come forward and contact the band's tour manager, Tony Moon at tonymoon@ with any leads. Despite the theft, Heart is continuing their Royal Flush Tour with special guest Tuesday, June 3 in Lexington, Ky. The band's current tour runs through Aug. 30 in Bethel, N.Y. Heart singer has been performing seated after she survived a battle with cancer last year. The singer took a fall in a parking lot earlier this year and broke her elbow in three places, prompting her to perform seated to avoid any further Rock Band Has Instruments Stolen on Eve of Tour Launch first appeared on Parade on Jun 3, 2025 This story was originally reported by Parade on Jun 3, 2025, where it first appeared.

Athletics' Wilson named AL Rookie of the Month after magnificent May
Athletics' Wilson named AL Rookie of the Month after magnificent May

Yahoo

time5 hours ago

  • Yahoo

Athletics' Wilson named AL Rookie of the Month after magnificent May

Athletics' Wilson named AL Rookie of the Month after magnificent May originally appeared on NBC Sports Bay Area A memorable May just got even better for Jacob Wilson. The Athletics' sterling young shortstop earned AL Rookie of the Month honors Tuesday after putting up stellar numbers over the last few weeks. Advertisement In May, Wilson posted .368/.437/.538 splits at the plate, along with four home runs, six doubles and 16 RBI. He also walked 11 times compared to just eight strikeouts over 27 games. Before Tuesday's game against the Minnesota Twins, Athletics manager Mark Kotsay praised Wilson's continuing development. 'The month was special,' Kotsay told reporters. 'He's been a big, big part of the offense and continues to just use his 'magic wand,' as we want to call it. The bat-to-ball skill is exceptional. 'He's beating all expectations. I think the growth from a shortstop that we saw from last year to this year is noticeable. I think he's making more plays than he did last season, and I think he'll continue to get better.' Advertisement In addition to his play overall, the No. 6 overall pick from the 2023 MLB Draft created some unforgettable moments over the past month as well. Wilson recorded the third walk-off hit of his young career on May 6 with an 11th-inning single to beat the Seattle Mariners. Needing only 62 career games, that made him the second-fastest player since at least 1969 to record three walk-off hits, per MLB's Sarah Langs. A week later, the Los Angeles native had a dominant homecoming to Dodger Stadium on May 13. In an 11-1 drubbing of the Dodgers, Wilson knocked out a pair of two-run home runs and finished with four hits. Wilson, who entered 2024 as the top prospect in the Athletics' organization, has vaulted himself into the frontrunner for the 2025 AL Rookie of the Year race. And though the Green and Gold have struggled lately, Wilson can continue to cement himself as a centerpiece of the team's young core if his May numbers continue throughout the summer.

Accused killer in Morrow County shootout with deputy receives $5 million bond
Accused killer in Morrow County shootout with deputy receives $5 million bond

Yahoo

time9 hours ago

  • Yahoo

Accused killer in Morrow County shootout with deputy receives $5 million bond

MOUNT GILEAD, Ohio (WCMH) – A man accused of murder appeared in court for the first time since a shootout that took the life of a Morrow County Sheriff deputy on Memorial Day. Brian Wilson, 53, was booked into Delaware County Jail after he was released from a hospital over the weekend, according to the sheriff's office. Wilson is charged with aggravated murder after an alleged shootout with deputy Daniel 'Weston' Sherrer at home on County Road 26, just south of Marengo. Sherrer was reportedly responding to a domestic violence call when Wilson confronted him on the porch of the home. Wilson allegedly told Sherrer, 'You better just f—— go if you want your family to see you tomorrow.' before shots were fired. Several gunshots were heard and Sherrer was hit during the exchange. More shots were fired, a court affidavit said, and two firearms were recovered, including a semiautomatic pistol and a revolver. Apply now: FBI offers teen academy for central Ohio students Wilson, charged with aggravated murder of a law enforcement officer, was also struck during the shootout and had been hospitalized for nearly a week before his release Saturday. On Tuesday, Wilson appeared virtually for his arraignment hearing in Morrow County court and received a $5 million cash surety bond with no possibility of paying 10%. The $5 million amount was issued after Morrow County prosecuting attorney Andrew Wick requested a $9 million bond. Wick told NBC4 that he knew Deputy Sherrer 'very well.' 'He was one of the good ones,' said Wick of Sherrer. 'Always willing to help and always curious about updates in the law.' If Wilson posts bond, he cannot leave Ohio, must refrain from consuming alcohol or drugs, must remove all firearms from his residence, and cannot contact members of Sherrer's family. If convicted of his aggravated murder charge, the court said Wilson could face life in prison or the death penalty. Sherrer was honored with a 120-mile procession last Wednesday and tomorrow he will be laid to rest at a private ceremony at Marion Cemetery. Visitation hours will be held Tuesday from 1-7 p.m. at Northmor High School. Gov. Mike DeWine has ordered flags flown at half staff until the completion of funeral services Copyright 2025 Nexstar Media, Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store