HomeCyber SecurityThe Most Costly Cyber-attacks In The eCommerce Industry

The Most Costly Cyber-attacks In The eCommerce Industry

Date:

Security has become indispensable to preventing cyber-attacks on eCommerce. Consumers are increasingly buying online, so online stores are having a great rise; however, it is important to remember that everything that is online is within the reach of hackers. E-commerce, being one of the sectors with the highest volume on the Internet, is precisely one of the most exposed.

The objectives of cybercriminals are of different kinds, but among the most common is the theft of information, identity theft, and the paralysis of computer networks. Therefore, when an organization is the victim of an attack, it not only affects eCommerce in the short term but can also ruin the credibility and prestige of the company.

- Advertisement -

The growth of e-commerce during this pandemic has not only contributed to the reactivation of the country’s economy but at the same time has brought with it a series of challenges in terms of cybersecurity, which will continue in the face of this new normality.

2 out of 10 businesses have experienced growth of more than 300%; by 2020 and by 2021, 19% plan for e-commerce to represent more than 30% of their total sales, according to the Mexican Association of Online Sales (AMVO).

However, few businesses proved to have the capacity to meet the demand, including several department stores that experienced bad episodes when their systems were overwhelmed, which leads to question the reliability of their cybersecurity strategies and workload capacity.

Any business that accepts online payments is at risk of fraud. For example, the 2020 AFP Payment Fraud and Control Survey found that 81% of organizations were targeted for payment fraud in 2019. Likewise, according to Review 42, card-not-present (CNP) fraud is projected to increase by 14% by 2023.

- Advertisement -

In Mexico, according to the National Commission for the Protection and Defense of Financial Services Users (CONDUSEF), cyber fraud grew 35% in the first quarter of 2019 over the same period in 2018, plus it estimates that CNP fraud will have cost retailers $130 billion from 2019 through 2023.

The e-commerce market, and therefore the risk of fraud, is very large in our country. In 2020 the Buen Fin campaign generated $239 billion pesos in total sales (107% more than in 2019) and 188.5 million transactions were recorded (157% more than the previous year). Online sales accounted for 15.2% of total sales, or just over $36 billion pesos, an increase of 225% compared to 2019.

While online shopping is very popular, this format significantly increases the risk of fraud. In 2020 alone, CNP fraud cost businesses $35.54 billion worldwide. Significant increases in fraud attacks are causing huge losses for mid-to enterprise-level businesses, and these types of attacks are even among small online businesses.

In Latin America, companies have the possibility of having Artificial Intelligence business services that provide the necessary infrastructure to protect themselves from fraudulent transactions and save the large costs they generate. The truth is that few companies have escaped being in the center of the target, despite their investment in security and the talent they have hired internally. For these premises, take a look at the 8 most famous cyberattacks in the last decade aimed at large companies that most sell online.

2011- Sony PlayStation Network

In this data breach, the names, emails, login details, and other personal information of some 77 million people with PlayStation Network accounts (the PlayStation service that allows you to buy games online) were compromised, and the service went down for a week. At the time, the Japanese company did not rule out the possibility that users’ bank details had been stolen.

2013 – Yahoo

The American company acknowledged that, in 2013, it was the victim of a major computer attack that affected more than 1,000 of its users’ personal data. One of its major failures was, precisely, to have kept quiet for years, something that caused its CEO to be dismissed from his duties. The security breach cost Yahoo about 3,000 million dollars as it exposed sensitive data such as email addresses, passwords, birthdays, phone numbers, names, and surnames of people registered on the platform.

2014 – eBay

In May 2014, eBay issued a statement asking its 145 million users to change their passwords after discovering that its network had been subject to a cyberattack. Hackers were able to break into the company’s system through unauthorized access to some employees’ passwords and made off with customer names, encrypted passwords, emails, addresses, phone numbers, and dates of birth. eBay was widely criticized for the length of time it took to notify its customers of the incident, which took place between February and March 2014.

2015 – Ashley Madison

This dating platform for married people suffered a major setback in 2015. A group of hackers – ‘The Impact Team’ – exposed the personal and financial data of the company’s more than 37 million customers on the internet. From their names and surnames – some of them very well known – to their most intimate sexual fantasies. It cost him more than $30 million.

2016- Tesco Bank

Hackers stole £2.26 million (about €2.65 million) in 48 hours from the British supermarket chain’s banking subsidiary. Tesco Bank reported that it had detected “suspicious transactions” in about 40,000 bank accounts, of which money had been withdrawn from about half. The bank was fined £16.4 million (€19.2 million) for failing to properly protect its customers.

2017- Uber

The news stood out in the media, not only because of the number of victims affected, 57 million but also because Uber paid a hundred thousand dollars to two hackers to delete the stolen data and hide the cyber-attack, keeping it secret. The attack took place in October 2016 a year before its publication and included the exposure of names, emails, and phone numbers of 57 million customers worldwide, as well as the personal information of 7 million drivers of that transportation company.

2018- Cambridge Analytica

Who said cyberattacks are just about “extorting” money or revealing sensitive information? Cambridge Analytica showed the world how data theft can be used in politics: in this case, to influence the 2016 U.S. presidential election. Cambridge Analytica, a data analytics firm that worked with Donald Trump’s team, used information from 50 million Facebook profiles without consent to identify users’ behavior patterns and tastes and use them in the dissemination of political propaganda.

2019- Facebook

A year after the Cambridge Analytica scandal, Facebook was once again involved in a case of data exposure. About 419 million Facebook phone and user ID numbers were stored on an online server that was not password protected. While not as sensitive as financial data, phone numbers can be used by hackers for spam, phishing, or SIM card-associated fraud. The US, UK, and Vietnam were the most affected countries.

2020- Tesla

This is a story that may have resulted in a fatal mishap, but which, fortunately, was resolved without incident. Teslarati reported in August of 2020 that a Tesla employee had received an offer from a cybercriminal group to install the malware in their Nevada factory. Elon Musk himself responded on Twitter, saying it was “a serious attack.” The attack is thwarted by the employee’s negative response, who shared the information with Tesla and now with the FBI.

And if you are also selling online, you have your eCommerce or you were thinking of starting to do it, see how to quickly detect an attack on your eCommerce and also how to protect it:

How to detect a cyberattack on my eCommerce?

Many times these system breaches go completely unnoticed, and only after some time, or when the damage is done, do companies manage to detect the security breach. It is therefore important to take into account these aspects to identify them:

  • Creation, deletion, or editing of company-sensitive data.
  • Unusual system performance.
  • Unusual web traffic from one or several IPs.

How to protect my eCommerce from a possible cyber-attack?

Ensure that the site runs under HTTPS protocol so that buyers have a minimum of encryption in their connection to the store.

  1. Passwords should be changed on a regular basis for sales channel administrators.
  2. Do not review sales on public networks.
  3. Include two-step verification in the sales channel.
  4. Use a reputable payment service and keep the online payment platform software up to date.
  5. Use an IT and cybersecurity solution to protect the business and customers.

The evolution of online payment solutions is inevitable, digital payment trends promise safer and faster transactions, and bank cards are striving to maintain control of the payments market in 2022, but face increasing competition from technology companies adding more and more payment solutions to their platforms.

In this regard, some online payment trends for 2022 are contactless digital payments, and biometric credit cards, by the way, read here our blog on computer biometrics and how it helps cybersecurity.

Both the variety and number of cyber threats in our country continue to grow, just like in the rest of the world. In the end, it’s a matter of taking a rigorous balance of the resources you have and deciding how much risk you are willing to take. For some people, their eCommerce is a minor project, and for others, ensuring the continuity of their online business is a priority.

- Advertisement -

Related articles:

Boost Your Career: Top 5 Computer Security Courses for Aspiring Cybersecurity Professionals

Discover the top 5 computer security courses to kickstart your cybersecurity career. Learn essential skills and gain certifications to protect digital assets.

Securing the Cloud: Best Practices for Cybersecurity in Cloud Computing Environments

Discover essential cybersecurity practices for cloud computing environments. We explore how to safeguard your data and infrastructure in the ever-evolving digital landscape.

Learning Through Play: 7 Cybersecurity Games That Sharpen Your Hacking Defense Skills

Discover 7 engaging cybersecurity games that make learning fun while boosting your hacking defense skills. We explore how these cyber security games sharpen your expertise.

The Backbone of Cybersecurity: A Deep Dive into Modern Network Security Practices

Discover how network security in cyber security protects organizations from threats. Learn about firewalls, encryption, and best practices for safeguarding digital assets.

5 Critical IT Security Threats You Can’t Afford to Ignore

Discover the top 5 IT security threats that could put your business at risk. Learn how to protect your data and systems from these critical vulnerabilities.

12 COMMENTS

  1. Wow, these cyber-attacks keep getting bigger and badder! Can’t wait to see what’s next. 😱💻

    • Are you serious? Cyber-attacks are a serious threat that affects individuals, organizations, and even governments. It’s not something to be excited about. We should be working together to find solutions, not waiting for the next disaster to strike.

    • Yeah, like we didn’t have enough chaos in the world already. These cyber-attacks are just a testament to how vulnerable we all are. It’s a wake-up call for sure, but I doubt anything substantial will change.

    • Well, maybe you should’ve thought twice before signing up for a website that promotes cheating. Take responsibility for your own choices instead of blaming others.

    • Wow, it’s surprising how some people still find pleasure in other people’s pain. Let’s not forget that behind the scandal were countless lives affected. It’s not a topic to be taken lightly or celebrated.

LEAVE A REPLY

Please enter your comment!
Please enter your name here