Retail & Consumer — Cyber Threat Activity
Retail and consumer businesses are attacked at the moment they can least afford it, and the sector shows the sharpest recent acceleration in our log: more than 600 recorded incidents, but over 330 of them in the trailing 180 days and 187 in the last 90. 71 groups have been attributed at least one claim, led by Qilin (85), Cl0p (73), Akira (56), SafePay (34) and The Gentlemen (34). Two distinct threats sit behind that number. The first is ordinary extortion timed against trading peaks, when an outage costs revenue by the hour and stock cannot be moved. The second is social engineering aimed at people rather than software. The UK's National Cyber Security Centre issued direct guidance to retailers after a run of 2025 incidents, singling out help-desk password reset procedures as the weak point, and CISA's advisory on Scattered Spider documents the method in detail: impersonate an employee using stolen personal data, talk a help desk into resetting credentials and multi-factor enrolment, then move through single sign-on into cloud data stores. That path requires no malware and defeats most technical controls, because every step is a legitimate action performed by a convincing caller. Retailers are attractive to it because they run large, high-turnover, distributed workforces where an unfamiliar voice is unremarkable. Recorded geography is United States-led at 320 claims, then Canada, Germany, the United Kingdom, Australia and Italy. These figures are extortion-site claims rather than confirmed breaches, and the sector's card-fraud and e-skimming exposure is largely absent from them, so treat the count as a floor on the sector's real incident rate.
- Recorded incidents: 1,053
- Incidents, trailing 180 days: 429
- Tracked threat actors: 112
- Malware families: 97
Recent incidents
- Fanatics (global sports commerce platform) 2026-09-20
- ShopDunk 2026-09-20
- Diarco 2026-09-17
- STP Fashion Lab 2026-09-17
- Javep Chevrolet 2026-09-17
- naturesplus.com 2026-09-17
- palletshop 2026-09-16
- Leisure Coast Kitchens 2026-09-16
- Librería Santa Fe 2026-09-15
- Sarku Japan 2026-09-15
- McCarthy Tire Service 2026-09-15
- laconcepcion.com.mx 2026-09-15
- stoecklin-kuechen.ch 2026-09-15
- Medical Department Store 2026-09-11
- Professional Retail Services 2026-09-10
- Lowerys 2026-09-09
- Mitsuwa Trading Co., Ltd 2026-09-09
- GT Distributors 2026-09-08
- LIBRERIA SANTA FE A P S SRL 2026-09-07
- Jinny Beauty Supply 2026-09-07
Threat actors targeting Retail & Consumer
- Qilin 134 incidents
- Cl0p 108 incidents
- Akira 85 incidents
- The Gentlemen 55 incidents
- SafePay 46 incidents
- INC Ransom 44 incidents
- Play Ransomware 44 incidents
- DragonForce 37 incidents
- ShinyHunters 27 incidents
- LockBit 21 incidents
- NightSpire 21 incidents
- Medusa Ransomware 17 incidents
- Lynx Ransomware 16 incidents
- RansomHub 16 incidents
- Krybit 14 incidents
- Cactus 11 incidents
- Settra 11 incidents
- Coinbase Cartel 10 incidents
- KillSec 9 incidents
- Stormous 9 incidents
- FunkSec 8 incidents
- BlackNevas 7 incidents
- Global Secret Group 7 incidents
- Sarcoma 7 incidents
Where these victims are
- United States 419
- Canada 53
- Germany 47
- Australia 25
- Italy 25
- Singapore 24
- United Kingdom 24
- France 23
- Japan 20
- Mexico 20
- Brazil 17
- Spain 16
Malware used against Retail & Consumer
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- BlackCat Malware
- Clop Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- REvil Malware
- Ryuk Malware
- TrickBot Malware
- AdFind Tool
- Amadey Malware
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.