01 logo

The Six-Week Outage That Changed How Retail Thinks About Security

Attackers stopped chasing card numbers alone. They now aim to take commerce offline. Threat intelligence and vulnerability management decide who survives peak season.

By ViitorCloud TechnologiesPublished 3 months ago 4 min read
Threat Intelligence Services for Retail Under Siege

In 2025, a cyberattack forced one of the UK's most recognized retailers to suspend online orders for six weeks. The combined financial impact of the Marks & Spencer and Co-op attacks reached an estimated £270 million to £440 million, and the UK Cyber Monitoring Centre classified the event as a Category 2 systemic incident. M&S alone forecast a £300 million hit to its 2025/26 profits.

The attack pattern matters more than the headline number. The intruders did not quietly skim card data. They shut down commerce operations. That shift defines the current threat picture for every retailer running high-traffic systems.

Retail Is the Most Attacked Sector Online

The data backs the anxiety security leads feel.

Commerce remains the single most attacked industry online, with retail accounting for 62% of attacks on the sector. Bots, increasingly AI-driven, now generate 39% of traffic to online retail per the Imperva 2025 Bad Bot Report.

Ransomware drives the operational damage. 44% of all confirmed data breaches in 2025 involved ransomware, up from 32% in 2024, per the Verizon 2025 DBIR. 58% of retailers hit by ransomware paid to recover their data, and the median retail ransom demand doubled year over year to $2 million.

The cost per incident keeps climbing. The IBM 2025 Cost of a Data Breach Report puts the average retail breach at $3.54 million, an 18% increase from the previous year.

Those numbers describe a sector under sustained pressure. The reasons sit inside the technology stack itself.

Technical Debt Is the Open Door

Retail technology environments age in layers. A point-of-sale system from 2014 connects to a loyalty database from 2018. Both feed an e-commerce platform rebuilt in 2021. Middleware written by a vendor who no longer exists holds the layers together.

63% of cyberattacks on retail companies exploit vulnerabilities tied to outdated software, and 54% of retail breaches involve weaknesses in point-of-sale systems.

End-of-life systems carry no patches. They sit on networks anyway because replacing them disrupts store operations. Each one extends the attack surface.

The checkout page adds a separate exposure. Modern retail sites load dozens to hundreds of external scripts. Analytics tags. Chat widgets. Payment processors. Review platforms. Each script runs in the customer's browser with access to the payment form. Magecart-style skimming campaigns target exactly this layer.

Regulators noticed. PCI DSS 4.0.1 made two requirements mandatory as of March 31, 2025. Requirement 6.4.3 requires all payment page scripts to be authorized, integrity-checked, and inventoried. Requirement 11.6.1 mandates tamper-detection that alerts personnel to unauthorized payment-page changes at least weekly.

A retailer that cannot inventory its own checkout scripts now fails a compliance requirement. Many cannot.

What Threat Intelligence Actually Buys a Retailer

Threat intelligence services convert outside signals into internal decisions. The signals come from several places.

Dark web monitoring catches stolen employee credentials before attackers use them. Credential dumps from unrelated breaches feed account takeover campaigns against retail logins. Knowing your domain appears in a fresh dump changes your password reset priorities that same day.

Campaign tracking identifies active skimmer infrastructure. When researchers map a new Magecart variant, retailers running the affected script libraries get a head start. Intelligence turns industry-wide reporting into a specific to-do list.

Exploit tracking matters most for vulnerability work. The U.S. Cybersecurity and Infrastructure Security Agency maintains the Known Exploited Vulnerabilities catalog, a public list of flaws attackers actively use. A vulnerability on that list deserves attention before a thousand theoretical ones.

The point of intelligence is timing. Retail cybersecurity teams that learn about a threat after exploitation run incident response. Teams that learn earlier run patching.

Vulnerability Management That Ranks by Real Risk

Most retailers already scan for vulnerabilities. The scans produce thousands of findings. The failure happens at prioritization.

A severity score alone does not rank work correctly. A medium-severity flaw on the checkout API matters more than a critical flaw on an internal wiki. Effective vulnerability management weighs three inputs together. Active exploitation status. Asset criticality. Exposure to the internet.

Attack surface management feeds this process. Retailers accumulate forgotten assets. Old promotional microsites. Staging servers are left public. Subdomains pointing at decommissioned services. Attackers find these through automated scanning within hours. The defending team needs the same visibility of its own perimeter.

The Peak Traffic Problem

Holiday windows compress every risk. Traffic multiplies. Revenue per minute climbs. Change freezes the lock on the codebase. Security teams cannot patch during the freeze without risking the systems the freeze protects.

A recent survey found 68% of retailers name business downtime as the most likely outcome of an attack, and 46% report being forced to shut down digital systems.

Attackers know the calendar. They time campaigns for the weeks when defenders have the least room to respond.

Continuous monitoring closes part of this gap. Real-time visibility into authentication anomalies, payment-page changes, and traffic patterns lets teams apply compensating controls without touching frozen code. Blocking a malicious IP range needs no deployment window. Neither does revoking a compromised credential.

The retailers that handle peak season well prepare the intelligence and monitoring layers months earlier. The freeze then locks code, not awareness.

Building the Program

Most retail security teams run lean. CISOs and IT directors rarely staff a full intelligence function internally. The common model pairs an internal operations lead with external specialists who supply the monitoring infrastructure, the threat feeds, and the prioritization logic.

Companies like ViitorCloud, which writes about how threat intelligence services apply to retail security, work in this space alongside retailers modernizing legacy commerce systems. The pairing matters because intelligence without remediation capacity produces reports nobody acts on. The development side and the security side have to move together.

The M&S incident closed the debate about whether high-traffic commerce needs continuous threat visibility. Six weeks offline answers the question. The retailers studying that incident now fall into two groups. One group builds the intelligence and vulnerability layers before the next peak season. The other group budgets for recovery instead. The first option costs less.

tech newscybersecurity

About the Creator

ViitorCloud Technologies

As a leading software development company, we’ve empowered 500+ startups, SMBs, and enterprises to transform their operations. Upgrade your business with our AI-First Software and Platforms that automate and scale, keeping you future-ready.

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by ViitorCloud Technologies