A global study conducted by cybersecurity firm Kaspersky found that 87% of retailers faced cyber incidents over the past 12 months, with phishing emerging as the most prevalent threat (21%).
Other social engineering attacks reported included deepfakes (13%), invoice or payment fraud (13%), business email compromise (9%), and vishing or voice phishing (8%).
For retailers in the Asia-Pacific (APAC) region, the most common consequences of these attacks were the theft of employees’ personal data (44%), theft of clients’ personal data (39%), theft of sensitive credentials or legal documents (33%), and irrecoverable data loss (33%).
The study also highlighted that human actions were the internal factors that increased the likelihood of successful cyberattacks.
In APAC, a lack of IT security awareness was cited as the top risk factor (46%), followed by insufficient expertise among IT security staff (31%) and outdated software or hardware (31%).
Regarding risky digital workplace behaviours in APAC caused by a lack of security awareness, half of the respondents (50%) reported that employees shared sensitive corporate credentials with colleagues or third parties.
Other risky digital workplace behaviours include downloading and installing software tools without IT approval (46%), using personal devices for workplace activities (38%), irresponsible password habits (38%) and connecting company devices to public WiFi without a secure connection (38%).
To minimise these risks, Kaspersky recommends that retailers educate employees through continuous awareness programs, establish clear AI usage policies, regularly assess cyber threats, and deploy endpoint protection on corporate devices.
