Cipher identifies more than 800 cyber attacks to the retail sector in Europe in 2024

Foto del autor

By Jack Ferson

Ciphercybersecurity division of Group Prosegur, through its X63 Unit intelligence unit, has detected More than 800 cyber attacks directed to sector retail In Europe during 2024, which reflects the growing pressure suffered by this important economic sector. In this context, Space stands out among countries with greater interannual increasewith a 178% increase in attacks with respect to 2023, standing together with the United Kingdom among the most affected European markets.

This escalation has placed Retail trade as One of the three most attacked sectorstogether with business services and manufacturing industry. In the United States, the trend also intensifies, with media cases such as cyber attacks suffered by MGM Resorts, Adidas, Salesforce or UBS, which They have affected both a critical infrastructure as to the customer data and logistics operations.

Los main attack vectors detected byCipher They include ransomware, personal and corporate data leaks, unauthorized access through social engineering, and attacks on the supply chain through committed third parties. Groups such as Ransomhub, Hunters or Alphv/Blackcat lead these campaigns, using Advanced infiltration and extortion techniquesas well as vulnerabilities in widely widespread software platforms in the sector, as was the case of the exploit in Moveit that affected several global suppliers.

The consequences of these attacks are Multiple and severe. On the operational level, many companies have suffered interruptions in their services, systems falls, sales paralysis and logistics impacts that have compromised consumer experience. On the economic level, costs derived from data rescue, operational recovery or regulatory sanctions amount to millions of euros. In the reputational field, the Confidence deterioration of the consumer and the damage to the brand image represents a long -term challenge for the affected actors. In addition, the growing normative pressure, both in Europe (RGPD) and in the US, forces companies to strengthen your data protection strategies and incident response plans.

A significant fact identified by Cipher is the Evolution of victims’ behavior before these attacks. For 2024, alone 28% of the affected organizations agreed to pay the rescue required by cybercriminalscompared to 41% registered in previous years. This figure reflects a greater awareness of the sector on the risks of financing criminal organizations, as well as a progressive improvement in preparation and cybercraft to face incidents without depending on payment as the only way of recovery.

In response, many companies in the retail sector are reinforcing your cybersecurity strategiesincreasing its investment in early detection tools, multifactor authentication, personnel training, segmentation of business continuity systems and plans. In addition, the collaborationpublic-private It has intensified, with shared initiatives for threat intelligence, the exchange of compromise indicators and the coordinated deployment of defensive measures in critical environments.

Para Santiago Anaya, Global Chief Technology Officer de Cipher, “The retail sector faces an increasingly hostile environment, in which digitalization not only promotes new business opportunities, but dangerously expands the attack surface. We are not talking only to protect online store commercial operations «.

Cipher emphasizes the Importance of anticipating threats Through proactive intelligence, attack simulations (Red Teaming), periodic audits and a robust governance of digital security. From the X63 Unit, it is recommended to companies in the retail sector to adopt a comprehensive strategy that combines technology, processes and peopleand that prioritizes prevention against reaction, in an increasingly sophisticated and persistent threats ecosystem.

Deja un comentario