Business Wire

CA-IMPERVA

Share
Retailers Take Notice: Automated Threats Caused 62% of Security Incidents in the Past 12 Months

Imperva, Inc., (@Imperva) the cybersecurity leader whose mission is to help organizations protect their data and all paths to it, releases The State of Security Within eCommerce 2022 report, a 12-month analysis by Imperva Threat Research of cybersecurity threats targeting the retail industry. A range of automated threats -- from account takeover, credit card fraud, web scraping, API abuses, Grinch bots, and distributed denial of service (DDoS) attacks -- were a persistent challenge for the eCommerce industry, threatening online sales and customer satisfaction. The continued barrage of attacks on retailers’ websites, applications, and APIs throughout the calendar year, and during the peak holiday shopping season, is a continued business risk for the retail industry.

“The holiday shopping season is a critical period for the retail industry, and security threats could undermine retailers’ bottom line again in 2022,” says Lynn Marks, Senior Product Manager, Imperva. “This industry faces a variety of security risks, the majority of which are automated and operate around the clock. Retailers need a unified approach to stop these persistent attacks, one that focuses on the protection of data and is equipped to mitigate attacks quickly without disrupting shoppers.”

An Automated Adversary: Bad Bots & Online Fraud Plague Retail Sites

In the past 12 months, nearly 40% of traffic on retailers’ websites didn’t come from a human. Instead, it came from a bot, software applications controlled by operators that run automated tasks, often with malicious intent. In the retail industry, the infamous Grinch bot is notorious for inventory hoarding during the holiday shopping season, scooping up high-demand items and making it challenging for consumers to purchase gifts online.

Some of the key trends monitored by Imperva include:

  • Of all the traffic on retailers’ websites, nearly one-quarter (23.7%) was attributed specifically to bad bots, malicious automation that contributes to online fraud. The proportion of advanced bots -- scripts that use the latest evasion techniques to mimic human behavior and avoid detection -- on retail sites grew over the prior year (from 23.4% to 31.1%). Advanced bots are a considerable challenge for organizations to stop without the right defenses in place.
  • In 2021, bot-related attacks on retail sites grew 10% in October and grew another 34% in November, suggesting that bot operators increase their nefarious efforts around peak holiday shopping periods.
  • Account takeover (ATO) is another form of online fraud in which cybercriminals attempt to compromise online accounts by using stolen passwords and usernames. In 2021, 64.1% of ATO attacks used an advanced bad bot. Of all login attempts on retail websites, 22.6% were malicious, nearly twice the volume that was recorded on sites across other industries. Attackers used leaked credentials 94.7% of the time in credential stuffing attacks targeting retailers, compared to 69.6% of the time in other industries.

API Abuses and Attacks Multiply, Creating New Challenges for Retailers

APIs are the invisible connective tissue that enable applications to share data and invoke digital services. Analysis by Imperva Threat Research finds that traffic from an API accounts for 41.6% of all traffic to online retailers’ sites and applications. Of that, 12% of traffic directs to endpoints, like a database, where personal data is stored (e.g. credentials, identification numbers, etc.). More concerning, 3 - 5% of API traffic is directed to undocumented or Shadow APIs, endpoints that security teams don’t know exist or no longer protect.

Exposed or vulnerable APIs are a considerable threat for retailers because attackers can use the API as a pathway for exfiltrating customer data and payment information. API abuses are often carried out through automated attacks where a botnet floods the API with unwanted traffic, seeking vulnerable applications and unprotected data. In 2021, API attacks increased by 35% between September and October, and then spiked another 22% in November on top of the previous months’ elevated attack levels. This finding suggests that bad actors scale their efforts around the holiday shopping season as more data is exchanged between the APIs and applications that power eCommerce services.

Beware of Downtime: DDoS Attacks Continue to Threaten Retailers

A distributed denial of service (DDoS) attack is an automated threat that attempts to disrupt critical business operations by flooding the network or application infrastructure with malicious traffic. The attacks are often launched by a botnet, a group of compromised connected devices that are distributed across the Internet and operated by a single party.

Imperva Threat Research finds that DDoS attacks in 2022 are larger and stronger across all industries. The number of incidents recorded that were greater than 100 Gbps doubled, and attacks larger than 500 Gbps/0.5 Tbps increased 287%. What’s more, those targeted by an attack are often attacked again within 24 hours. In fact, 55% of websites hit by an application layer DDoS and 80% hit by a network layer DDoS were attacked multiple times.

A DDoS attack is a nonstop threat for retailers. The downtime caused by a DDoS attack can lead to site disruption, reputational damage, and revenue loss. A DDoS is a critical threat to online retailers that rely on application performance and availability to enable digital storefronts.

Additional Information:

About Imperva:

Imperva is the comprehensive digital security leader on a mission to help organizations protect their data and all paths to it. Only Imperva protects all digital experiences, from business logic to APIs, microservices, and the data layer, and from vulnerable, legacy environments to cloud-first organizations. Customers around the world trust Imperva to protect their applications, data, and websites from cyber attacks. With an integrated approach combining edge, application security, and data security, Imperva protects companies ranging from cloud-native start-ups to global multi-nationals with hybrid infrastructure. Imperva Threat Research and our global intelligence community keep Imperva ahead of the threat landscape and seamlessly integrate the latest security, privacy, and compliance expertise into our solutions.

© 2022 Imperva, Inc. All rights reserved. Imperva is a registered trademark of Imperva, Inc.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20221103005435/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Megaport Expands into India, Accelerating Global Growth with Extreme IX Acquisition18.12.2025 02:15:00 CET | Press release

Through the Extreme Exchange (IX) acquisition, Megaport gains seven Internet Exchanges and access to 40+ data centres across India’s fastest-growing digital hubs. Megaport Limited (ASX: MP1) (“Megaport”), the world’s leading Network as a Service (NaaS) provider, today announced the acquisition of Extreme IX,India’s leading Internet Exchange operator, from Extreme Labs, a Bulgaria-headquartered software and network engineering company that incubated the Extreme IX platform. The acquisition expands Megaport’s global platform into one of the world’s fastest-growing digital infrastructure markets and supports the Company’s strategy to deliver scalable, high-performance connectivity services across APAC. The acquisition establishes Megaport’s presence across seven Internet Exchanges in major Indian metros: Delhi, Kolkata, Hyderabad, Chennai, Bengaluru, Mumbai, and Pune, connecting 40+ data centres and more than 400 customers. It also accelerates Megaport’s planned market entry by nearly thr

IonQ and QuantumBasel Expand Long-Term Partnership in Next-Generation Quantum Systems17.12.2025 22:10:00 CET | Press release

Extension solidifies QuantumBasel as IonQ’s Innovation Center in Europe; adds IonQ Tempo and next-generation system to advance quantum commercialization IonQ (NYSE: IONQ), the world’s leading quantum company, today announced an expanded agreement with QuantumBasel, the quantum initiative of uptownBasel, Switzerland’s innovation campus. The extended contract grants QuantumBasel ownership of its existing IonQ Forte Enterprise system and secures ownership of a next-generation Tempo system. This new agreement brings the total deal value of the QuantumBasel and IonQ partnership to over $60 million and extends IonQ’s on-site presence in Switzerland four more years, continuing through 2029. QuantumBasel is IonQ’s official Innovation Center in Europe, serving as a hub for European industry, academia, and research institutions to explore practical quantum computing applications and access IonQ’s latest enterprise-grade systems. “Our extended partnership with QuantumBasel represents a cornerston

Suzano Starts Up New Production Line, Boosting Its Fluff Pulp Capacity by 400%17.12.2025 21:50:00 CET | Press release

A R$490 million investment expands the supply of raw material used in the production of absorbent items Suzano, the world’s largest pulp producer, has commenced operations this week at its new fluff pulp production line located in its Limeira unit in Brazil’s São Paulo state. This R$490 million investment increases Suzano’s total fluff pulp production capacity by more than 400%, from 100,000 to 440,000 tonnes per year. The project involved converting the existing pulp line at the Limeira unit into a flexible machine, capable of producing both Eucafluff® and market pulp. Eucafluff® is used in the production of absorbent and personal hygiene products, such as baby and adult diapers, sanitary pads and pet pads. Then market pulp is supplied for making products including toilet paper, printing and writing papers, and paper packaging. Launched in 2015, Eucafluff® is the world’s first fluff pulp made from eucalyptus, delivering unique advantages like enhanced softness and flexibility, which t

SES Acknowledges Moody’s Rating Action and Reiterates Deleveraging Commitments17.12.2025 21:36:00 CET | Press release

SES S.A. (“SES” or the “Company”), a leading space solutions company, acknowledges the credit rating action announced by Moody’s Investor Service today, which follows the release of SES’ Q3 2025 results and Intelsat integration update. SES management reiterates that the Company continues to execute on its strategy with a clear plan to strengthen its key credit metrics over time. Consistent with this plan, it remains management’s intention to de-lever and return to credit metrics that are commensurate with investment grade, with a policy objective of reducing adjusted net leverage1 to at least 3.0x or below. Today’s rating action does not change the Company’s ability to operate its business, serve customers, or execute its strategic plan. SES maintains a balanced weighted average debt maturity profile of approximately five years, and the rating action from Moody’s is not expected to have a material impact on the interest payable under the Company’s existing debt facilities. SES also ben

Picsart and Zazzle Power the Creator-to-Commerce Evolution with Print-On-Demand Integration17.12.2025 20:47:00 CET | Press release

Partnership Gives Creators an End-to-End Solution to Create A Range of Products in the $205 Billion Creator Economy Picsart, the world’s leading digital creation platform with over two billion downloads and more than 100 million monthly active users, is partnering with Zazzle, the global leader in customized products and designs, to deliver an end-to-end printing solution for Picsart users. The new “vibe-design-to-print” integration works seamlessly with Picsart’s recently expanded suite of AI products, including AI Assistant and Flows, enabling creators to ideate, iterate, design, and bring their work to life as physical art and products. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251217882832/en/ Picsart and Zazzle Power the Creator-to-Commerce Evolution with Print-On-Demand Integration “At Picsart, our mission has always been to give creators the tools they need to bring their ideas to life,” said Hovhannes Avoyan, Fo

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye