Key Takeaways
- Retail saw a 42% increase in cyberattacks during the 2023 holiday season
- 71% of retail organizations were hit by ransomware in 2023
- 92% of retail breaches are financially motivated
- The average cost of a retail data breach reached $4.45 million in 2023
- Lost business represents 30% of the total cost of a retail breach
- Post-breach customer turnover in retail averages 3.9%
- 24% of all retail breaches involve the use of stolen credentials
- Social engineering accounts for 12% of retail data breaches
- Web application attacks account for 41% of breaches in the retail sector
- Credential stuffing attacks against retail sites increased by 155% year-over-year
- 43% of retail IT security managers report an increase in phishing attempts
- 50% of retail breaches involve basic web application attacks
- The average time to identify a breach in retail is 201 days
- 26% of retail breaches are contained within 30 days of discovery
- 37% of retail organizations lack a formal incident response plan
Retail data breaches are devastating and becoming more frequent and expensive.
Attack Vectors
Attack Vectors Interpretation
Detection & Response
Detection & Response Interpretation
Financial Impact
Financial Impact Interpretation
Incident Trends
Incident Trends Interpretation
Vulnerabilities
Vulnerabilities Interpretation
Sources & References
- Reference 1CHECKPOINTcheckpoint.comVisit source
- Reference 2IBMibm.comVisit source
- Reference 3VERIZONverizon.comVisit source
- Reference 4AKAMAIakamai.comVisit source
- Reference 5SOPHOSsophos.comVisit source
- Reference 6FORTINETfortinet.comVisit source
- Reference 7PONEMONponemon.orgVisit source
- Reference 8SANSsans.orgVisit source
- Reference 9PALOALTONETWORKSpaloaltonetworks.comVisit source
- Reference 10ZSCALERzscaler.comVisit source
- Reference 11CROWDSTRIKEcrowdstrike.comVisit source
- Reference 12TRUSTWAVEtrustwave.comVisit source
- Reference 13SBAsba.govVisit source
- Reference 14PROOFPOINTproofpoint.comVisit source
- Reference 15THALESGROUPthalesgroup.comVisit source
- Reference 16KNOWBE4knowbe4.comVisit source
- Reference 17FORRESTERforrester.comVisit source
- Reference 18ISACAisaca.orgVisit source
- Reference 19LOOKOUTlookout.comVisit source
- Reference 20F5f5.comVisit source
- Reference 21ENISAenisa.europa.euVisit source
- Reference 22IDTHEFTCENTERidtheftcenter.orgVisit source
- Reference 23GARTNERgartner.comVisit source
- Reference 24PCISECURITYSTANDARDSpcisecuritystandards.orgVisit source
- Reference 25MANDIANTmandiant.comVisit source
- Reference 26CYBINTSOLUTIONScybintsolutions.comVisit source
- Reference 27FIREEYEfireeye.comVisit source
- Reference 28ACCENTUREaccenture.comVisit source
- Reference 29MICROSOFTmicrosoft.comVisit source
- Reference 30VISAvisa.comVisit source
- Reference 31MARSHmarsh.comVisit source
- Reference 32IMPERVAimperva.comVisit source
- Reference 33IDCidc.comVisit source
- Reference 34TENABLEtenable.comVisit source
- Reference 35ISC2isc2.orgVisit source
- Reference 36LASTPASSlastpass.comVisit source
- Reference 37APWGapwg.orgVisit source
- Reference 38SALTsalt.securityVisit source
- Reference 39CLOUDFLAREcloudflare.comVisit source
- Reference 40FTCftc.govVisit source
- Reference 41RISKIQriskiq.comVisit source
- Reference 42TANIUMtanium.comVisit source
- Reference 43NETSCOUTnetscout.comVisit source
- Reference 44SONICWALLsonicwall.comVisit source
- Reference 45BITSIGHTbitsight.comVisit source
- Reference 46DELOITTEdeloitte.comVisit source
- Reference 47NETSKOPEnetskope.comVisit source
- Reference 48ARMISarmis.comVisit source
- Reference 49SPLUNKsplunk.comVisit source
- Reference 50JDSUPRAjdsupra.comVisit source
- Reference 51FBIfbi.govVisit source
- Reference 52DIGICERTdigicert.comVisit source
- Reference 53INCinc.comVisit source
- Reference 54WIZwiz.ioVisit source
- Reference 55AONaon.comVisit source
- Reference 56HONEYWELLhoneywell.comVisit source
- Reference 57DARKREADINGdarkreading.comVisit source
- Reference 58ZIMPERIUMzimperium.comVisit source
- Reference 59SHODANshodan.ioVisit source
- Reference 60LEXISNEXISlexisnexis.comVisit source
- Reference 61RAPID7rapid7.comVisit source
- Reference 62CLASSACTIONclassaction.orgVisit source
- Reference 63CYBEREASONcybereason.comVisit source
- Reference 64SECURITYSCORECARDsecurityscorecard.comVisit source
- Reference 65UPTIMEINSTITUTEuptimeinstitute.comVisit source
- Reference 66SIFTsift.comVisit source
- Reference 67BEYONDTRUSTbeyondtrust.comVisit source
- Reference 68COMPARITECHcomparitech.comVisit source
- Reference 69SYMANTECsymantec.comVisit source
- Reference 70SOLARWINDSsolarwinds.comVisit source
- Reference 71UPGUARDupguard.comVisit source
- Reference 72DIGITALSHADOWSdigitalshadows.comVisit source
- Reference 73SONATYPEsonatype.comVisit source
- Reference 74NOWSECUREnowsecure.comVisit source






