Protect Your 零售 Business: 3 Common Cyber Attack Methods to Watch Out for in 2023

What were the most common cyber attack patterns in the retail industry in 2023?

支持… 网络安全意识月在美国,我们正在审查各行业报告的事故. 本文的重点将是零售业.

With a wealth of payment data and countless entry points from e-commerce shops, 第三方供应商和实体商店位置, the retail industry is teeming with opportunities for threat actors to capitalize on for financial gain.

事实上,没有人会感到意外 Verizon 2023数据泄露调查报告 (Verizon DBIR) found that 100% of the reported incidents were financially motivated, 37%的人专门针对支付卡数据.

So, what were the most common cybersecurity attack methods in the retail industry in 2023?

根据Verizon 2023年的DBIR, nearly 90% of all reported incidents in the retail industry were from social engineering, 系统入侵或基本web应用程序攻击.

社会工程与零售业

这是网络安全领域最常见的疑点之一, 社会工程是常见的, 但是非常有效, 策略. Threat actors prey on human nature to manipulate individuals into exposing sensitive information. 在零售业的背景下, this can include manipulating someone into providing access to customer databases with payment card data, 公司网络信息或客户凭证.

系统入侵与零售业

系统入侵似乎是一个直截了当的概念, but it’s still a commonly reported attack pattern that many retailers aren’t completely protected from. System intrusions involve cases in which a threat actor uses technological means to gain unauthorized access to a system or database. 大多被报道为黑客攻击或部署恶意软件, 这种攻击方法还包括勒索软件, 对零售商来说,这是一个日益严重的问题. 最近的一份报告显示,有一个 增加75% in the rate of ransomware attacks on the retail sector in 2022.

基本的Web应用程序攻击和零售行业

一个非常简单的攻击方法, basic web application attacks are akin to a smash-and-grab in the cybersecurity world – get in, 拿上货物,离开这里. 在零售业, web applications commonly take the form of an e-commerce website or app, 还有第三方网站, 插件, 供应商和供应链, 这一切都能hold住一个宝藏的支付, 个人及专有资料.

The good news is the risk of basic web application attacks can be mitigated with automated security tools, 多因素身份验证, best-practice controls and proactive incident response planning. While protective measures aren’t error-proof, they do offer some peace of mind.

This article is part of a series highlighting the most common cybersecurity incidents by industry and is based on data from the 2023 Verizon DBIR. 其他条款包括:

It is important to note that the data referenced is from organizations that chose to disclose incidents and data breaches.

关于网络安全意识月

自2004年以来, the United States and Congress have recognized October as 网络安全意识月 to raise awareness about the importance of cybersecurity in the public and private sectors and tribal communities. 今年是20周年th year anniversary of 网络安全意识月 and this year's campaign, 保护我们的世界, focuses on four ways to protect yourself, your family and your business from online threats.

相关资源

关于施耐德唐斯网络安全

The Schneider Downs cybersecurity practice consists of experts offering a comprehensive set of information technology security services, 包括渗透测试, 入侵防御/检测审查, ransomware安全, vulnerability assessments and a robust digital forensics and incident response team. 此外,我们的 数字取证和事件响应 teams are available 24x7x365 at 1-800-993-8937 if you suspect or are experiencing a network incident of any kind.

要了解更多信息,请访问我们专门的 网络安全 呼叫或联系团队 (电子邮件保护)

想要了解情况? 订阅我们的双周通讯, 关注网络安全.

你们已经听到了我们的想法,我们也想听听你们的想法

The Schneider Downs 我们对 blog exists to create a dialogue on issues that are important to organizations and individuals. 虽然我们喜欢分享我们的想法和见解, 我们对你要说的特别感兴趣. If you have a question or a comment about this article – or any article from the 我们对 blog – we hope you’ll share it with us. After all, a dialogue is an exchange of ideas, and we’d like to hear from you. 电邮至 (电子邮件保护).

所讨论的材料仅供参考, 而且这不能被理解为投资, 税, 或法律建议. 请注意,个别情况可能有所不同. 因此, this information should be relied upon when coordinated with individual professional advice.

©2024施耐德唐斯. 版权所有. All content on this site is property of Schneider Downs unless otherwise noted and should not be used without 书面许可.

我们对
8审查用户访问时的关键考虑事项
Allegheny County Marriage License Data Leak May Affect Recent Newlyweds
$1 Billion a Day: Unpacking the 金融 Aftershock of the Change 医疗保健 Cyber-Attack
Get the Low Down Before You Download: Exploring the Temu App’s Security Risks
宾夕法尼亚州华盛顿县遭遇六位数勒索软件攻击
浪漫骗局:保护你的心和钱包
Register to receive our weekly newsletter with our 最近的 columns and insights.
有问题吗?? 问我们!

我们很乐意听到你的消息. Drop us a note, and we’ll respond to you as quickly as possible.

问我们
bet9平台游戏

This site uses cookies to ensure that we give you the best user experience. Cookies assist in navigation, analyzing traffic and in our marketing efforts as described in our 隐私政策.

×