Retail Under Siege: Evolving Cyber Threats and What We Must Do Next

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Retail Tech Insights Advisory Board.

Academy Sports + Outdoors

Retail Under Siege: Evolving Cyber Threats and What We Must Do Next

Mark Alvarado

Mark Alvarado

After 21 years in Information Technology, spanning hands-on engineering, cybersecurity leadership and regulatory compliance, I can confidently say: few industries face the same relentless digital assault as retail.

Retail businesses are high-value targets. We collect personal and financial data, operate on interconnected platforms and work under tight margins with demanding customer expectations. This perfect storm of data-rich environments and rapid digital transformation has made retail a frontline battlefield in the modern cyber landscape.

A Familiar Playbook, Newer Tactics

The fundamental motives behind attacks on retail remain unchanged: data theft, financial gain and disruption. What has changed is the attackers’ sophistication. In early 2024, VF Corporation, the parent company of major brands like Vans, Supreme and The North Face, suffered a ransomware attack that severely disrupted operations, compromising internal systems and causing significant delays in order fulfillment. Attackers didn’t just exfiltrate data; they paralyzed business continuity.

This isn’t an isolated case. It’s a stark reminder that retail breaches go far beyond PCI compliance failures or phishing emails. Cybercriminals now leverage AI-driven tools to automate reconnaissance, deepfake social engineering, and exploit complex supply chain weaknesses.

Common Threat Vectors in Retail

1. Point-of-Sale (POS) Attacks: POS systems, often distributed across thousands of locations, are a prime target. Threat actors seek to inject malware that silently siphons cardholder data.

2. Third-Party Vendor Risks: Retail is notorious for heavy vendor reliance, be it logistics, cloud services or in-store kiosks. Without rigorous third-party risk assessments, a breach in one system can compromise the entire ecosystem.

3. Account Takeover (ATO): Credential stuffing and phishing continue to enable attackers to hijack consumer and employee accounts.

Loyalty programs and gift card systems are especially attractive targets.

4. Ransomware & Extortion: Beyond data encryption, we now see data being exfiltrated and weaponized through double-extortion campaigns. Attackers demand payment not just to unlock systems, but to prevent leaks of sensitive business or customer data.

Retail’s Unique Challenge: Speed vs. Security

Retail moves fast. Promotional campaigns, website changes and backend integrations happen weekly, sometimes daily. Security, on the other hand, is methodical by necessity. Balancing agility and risk is the hardest part of my job as a CISO.

“As a certified ethical hacker and data privacy advocate, i’ve seen that the answer isn’t to slow retail innovation, it’s to embed cybersecurity at the decision-making level. That means including security in project kickoffs, procurement evaluations and board-level discussions, not just audits or incident responses.”

As a certified Ethical Hacker and data privacy advocate, I’ve seen that the answer isn’t to slow retail innovation, it’s to embed cybersecurity at the decision-making level. That means including security in project kickoffs, procurement evaluations and board-level discussions, not just audits or incident responses.

Five Recommendations for Today’s Retail Cyber Landscape

1. Identity is the New Perimeter – Move beyond traditional firewalls. Implement robust identity and access management with multi-factor authentication (MFA) across customer and employee platforms.

2. Zero Trust Architecture – Assume breach. Build segmented, policy-driven environments that don’t implicitly trust internal traffic.

3. Third-Party Risk Programs – Require vendor security questionnaires, audit results and contractual obligations around breach notification and incident management.

4. Security Awareness at All Levels – Employees in stores, warehouses and corporate offices must understand phishing, social engineering and physical device security.

5. Incident Response Readiness – Regular tabletop exercises, red teaming and forensic capabilities must be built and tested continuously.

A Call to Action

The cyber threats facing retail aren’t going away, they’re evolving. The stakes aren’t just technical; they’re reputational and financial. A single breach can shatter customer trust and impact stock performance, particularly for publicly traded organizations.

As professionals entrusted with safeguarding these organizations, we must stay ahead of attackers by building adaptive, risk-informed programs. Cybersecurity isn’t just an IT issue, it’s a business imperative.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.