Kaspersky has warned that the retail sector has become one of the most attractive targets for cybercriminals, with security incidents and data breaches increasing by more than 100% over the past three years. According to the cybersecurity company, attacks have evolved beyond data theft and now threaten payment systems, supply chains, employees, daily operations, and consumer trust.
Retail businesses process large volumes of sensitive information, including payment details, loyalty program records, and customer data. That information has become a valuable target for fraud, identity theft, and illegal sales on the dark web. Kaspersky says modern threats such as web-skimming, ransomware, Business Email Compromise (BEC), and refund fraud can quickly turn a single security breach into widespread operational disruption and significant financial losses.
Data Protection Has Become a Business Priority
The report identifies data security as one of the industry’s most urgent challenges. Retailers increasingly rely on customer information to support personalized marketing, dynamic pricing, artificial intelligence, and logistics automation. At the same time, the concentration of sensitive data across internal systems and third-party platforms expands the potential attack surface.
Kaspersky notes that the consequences of a major breach extend beyond technical recovery. Large retail organizations may face regulatory fines, legal expenses, contractual penalties, and recovery costs that can total as much as $91 million, while also damaging customer confidence in how personal information is handled.
Human Error Remains a Critical Weakness
The company estimates that between 64% and 86% of data breaches involve unintentional human error. Employees may unknowingly expose organizations by clicking phishing emails, using weak passwords, or mishandling access credentials.
Cybercriminals are also adopting increasingly sophisticated social engineering techniques. Recent attacks against retailers in the United Kingdom have included fake invoices, altered banking information, malicious API scripts, AI-generated deepfakes, voice cloning, and highly targeted phishing campaigns delivered through email, messaging applications, and workplace collaboration platforms such as Microsoft Teams.
Protecting Payment Systems and Supply Chains
The report highlights payment processing as one of the most sensitive stages of retail operations. Whether online or in physical stores, payment systems have become attractive targets because they process financial and personal information in real time. Successful attacks can lead to fraudulent transactions, stolen credentials, interrupted payment services, and significant revenue losses.
Kaspersky estimates that disruptions affecting online stores or payment systems can cost retailers up to $20,000 per hour. The company also warns that point-of-sale systems connected to customer databases, loyalty programs, or corporate networks can expose additional sensitive information if compromised.
Supply chain security has also become a growing concern. Retailers depend on technology vendors, logistics providers, cloud platforms, and other external partners, meaning vulnerabilities within third-party organizations can quickly spread throughout the business. According to the report, approximately 30% of attacks targeting the retail sector involve suppliers or business partners, although only a small percentage of executives currently consider third-party risk their primary cybersecurity concern.
Preparing for More Advanced Cyber Threats
Kaspersky says sophisticated attacks increasingly involve extended periods of reconnaissance before exploiting vulnerabilities. Between 2024 and 2025, several major retailers experienced incidents that disrupted operations, reduced productivity, increased recovery costs, and forced urgent infrastructure upgrades.
Claudio Martinelli, General Manager for the Americas at Kaspersky, said cybersecurity has become a fundamental business requirement rather than simply an IT function.
“Retail has reached a point where cybersecurity can no longer be viewed as technical support, but as a prerequisite for operating, selling, and maintaining consumer trust,” Martinelli said. He added that organizations should identify their most critical business processes and implement controls that help anticipate, reduce, and manage cyber risks before they disrupt operations.
Kaspersky’s Recommendations for Retailers
To strengthen cyber resilience, Kaspersky recommends that retailers identify their most critical systems and data, provide regular cybersecurity awareness training for employees, apply role-based access controls, deploy advanced detection and response technologies, and use threat intelligence and managed detection services to monitor evolving risks and improve incident response capabilities.

