

APT Campaigns – 6.0
17 of 108 campaign updates (16%), rising from 7 in absolute terms, while share fell from 37% as the pool expanded almost sixfold. Lazarus Group leads by a clear margin, consistent with DPRK monetisation of consumer-facing targets. Cloud security software ranked second among targeted technologies, alongside two Citrix products, three Fortinet products, and Active Directory.
Cyber Incidents – 7.0
36 incidents, ranked 4th of 14, with roughly 26 million customer records taken from five named brands by a single actor in eleven weeks. Ransomware produced physical disruption, including suspended dairy production and a national cold-chain outage affecting food supply. Supplier compromise was the repeated route in, spanning logistics, subsidiaries, and an ERP platform flaw.
Dark Web Chatter – 7.2
4,480 mentions, 6th of 14 at 10.67%, with breach and leak chatter roughly tripling. Incidents fell from 17 to 11 in the final window while chatter climbed, a divergence characteristic of publication lag. Claimed figures have run substantially above verified counts, making this the sector where attacker assertion and confirmed exposure diverge most.
Vulnerabilities – 7.0
119 mentions, 5th of 14, a disclosure figure that alone would support Elevated. The score rests on active in-the-wild exploitation of an unauthenticated RCE flaw in Magento and Adobe Commerce where fully patched stores were compromised and a persistent Rust backdoor deployed. Platform concentration exposes a large share of the sector simultaneously.
Ransomware – 7.5
231 victims, up 21.6% Q-on-Q with share flat and August reaching a period high of 91. Retail Brick & Mortar and Hospitality & Leisure account for close to two-fifths of victims, where downtime converts directly into lost revenue. Country coverage widened from 42 to 52, and Majinahanashi entered in August with 45.5% of its activity directed here.
The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each week for a quarter. This report focuses on the consumer goods & services sector, presenting key trends and statistics in an engaging infographic format.
Welcome to the CYFIRMA infographic industry report, where we delve into the external threat landscape of the consumer goods & services industry over the past three months. This report provides valuable insights and data-driven statistics, delivering a concise analysis of attack campaigns, public reports, underground & dark web chatter, vulnerabilities, and ransomware incidents targeting consumer goods & services organizations.
We aim to present an industry-specific overview in a convenient, engaging, and informative format. Leveraging our cutting-edge platform telemetry and the expertise of our analysts, we bring you actionable intelligence to stay ahead in the cybersecurity landscape.
CYFIRMA delivers pre-emptive cybersecurity, cyber threat intelligence, and external threat landscape management through its platforms, DeCYFIR and DeTCT. These platforms have been purpose-built over many years to continuously collect, correlate, and analyse large volumes of external threat data, combining proprietary intelligence automation with deep, hands-on cyber threat research.
For the purpose of this report, the analysis draws on intelligence generated from CYFIRMA’s platforms. The data referenced has been processed through automated correlation and enrichment mechanisms, informed and validated by human-led research and investigative expertise, and sourced from both structured and unstructured external intelligence channels.
While this report contains data collected and processed by our in-house AI and ML, all charts, statistics, and analyses are done by human CYFIRMA CTI analysts to ensure the highest quality and provide accurate insights.
Consumer goods & services organizations featured in 17 out of the 108 campaign activity updates, which is a presence in 16% of all activity. Significant jump from previous period where retail organizations were present in 7 out of 19 campaigns. However, there was a decline in presence to 16% of observed activity.


APT activity targeting Consumer goods & services has been continuous, with campaign counts rising across June, July, and August. September reflects a partial month at the time of this report.

North Korea-associated Lazarus Group leads with the highest campaign count by a clear margin, consistent with known DPRK targeting of consumer-facing organizations for financially motivated operations. China-linked actors follow, including Stone Panda, MISSION2074, Leviathan, APT27, and Hafnium.
Russia-linked Fancy Bear and Cozy Bear both feature, alongside Iran-linked OilRig and additional Iranian-associated activity. Financially motivated actor TA505 also appears. The actor set is narrower than in most sectors, with a clear concentration around North Korean and China-linked activity rather than broad multi-origin targeting.

Victim distribution spans 36 countries, with the United States and Japan recording identical and highest victim counts, followed by Australia and South Korea. India, the United Kingdom, Germany, the Philippines, and Thailand form the next tier, reflecting targeting concentrated across major consumer markets in North America and the Indo-Pacific.
Southeast Asian representation is broad, covering Thailand, the Philippines, Singapore, Malaysia, Indonesia, Vietnam, Myanmar, Cambodia, Brunei, Timor-Leste, and Laos. European presence spans Germany, the United Kingdom, France, Belgium, the Netherlands, Austria, and Norway.
Middle Eastern presence is led by Saudi Arabia and the UAE, with Oman, Qatar, and Israel also recording victims. Remaining cases are spread across East Asia, Africa, Latin America, and Oceania.

Web applications account for the highest number of observed attacks, followed by cloud security software and operating systems in equal measure. Cloud security software ranking second is notable, pointing to threat actor interest in the controls protecting customer-facing cloud environments rather than the applications alone.
Remote desktop software features across three campaigns, with remote desktop protocol also recorded separately. Two Citrix products and three Fortinet products appear among targeted technologies, alongside Active Directory, indicating focused interest in network edge appliances and identity infrastructure. Development languages including Java, Go, and Perl also feature, reflecting targeting at the application layer.

Based on the observed trajectory across the two reporting periods, the consumer goods and services sector external threat landscape is expected to remain at Elevated through the next 90 days. Campaign presence grew from 7 to 17 in absolute terms, while the sector’s share declined from 37% to 16% as the overall campaign pool expanded substantially. This indicates the sector is being targeted consistently but is not attracting disproportionate attention relative to the wider threat landscape.
Sustained volume: Campaign presence grew from 7 out of 19 to 17 out of 108 observed campaign updates period over period. Monthly counts rose from June through August, with September representing a partial month at publication. 15 to 20 consumer goods and services sector campaigns over the next 90 days is a plausible baseline estimate.
Dominant actor continuity: Lazarus Group recorded the highest campaign count by a clear margin and is expected to maintain tempo. The concentration of DPRK activity against consumer-facing organizations points to financially motivated objectives alongside intelligence collection, a pattern unlikely to change over the forecast period.
Cloud and edge infrastructure exposure: Cloud security software ranking second among targeted technologies, alongside two Citrix products, three Fortinet products, and Active Directory, points to a targeting pattern focused on perimeter compromise and identity infrastructure rather than application-layer exploitation alone. Organizations with unpatched edge appliances or exposed directory services face the highest immediate risk.
Geographic targeting: The United States and Japan lead in victim count, followed by Australia and South Korea. North America and the Indo-Pacific corridor are expected to remain primary target zones, with sustained exposure across Southeast Asian consumer markets and Western Europe.
Concentrated actor profile: The actor set is narrower than in most sectors, with activity concentrated around North Korean and China-linked groups alongside limited Russian, Iranian, and financially motivated presence. Defenders should prioritize monitoring for credential access and data exfiltration indicators given the financially driven actor profile observed this period.
Over the past 90 days, DeCYFIR and DeTCT platforms tracked 682 cyber incidents reported publicly. We could identify the industry for 501 of these incidents (73.5%).
The consumer goods & services industry was detected in 36 incidents, which equals 5.28% of the incidents where we knew the industry, ranking 4th out of 14 industries.


Supply chain attacks were the most frequently identified technique, appearing across the first and previous 30 days. Ransomware and account takeover each appeared across two periods, with ransomware concentrated in the previous 30 days and account takeover split across the first and previous 30 days. Phishing appeared twice in the last 30 days. Credential theft, trojanized software, and social engineering each appeared once. The technique distribution reflects two distinct threat threads: opportunistic credential and data extortion on one side, and operationally disruptive ransomware and supply chain compromise on the other.
Reporting volume was stable at 50 to 60 incidents per week, with a dip at the end of June and a peak of 70 in the week of 20 July.
Supply chain attack led the technique distribution at 64 incidents, followed by a tight cluster of credential theft (59), social engineering (54), ransomware (53), phishing (52), and AI-assisted attack (52). AI-assisted attack reaching parity with phishing is the most significant structural change in the period.
ShinyHunters was the most reported actor by a wide margin at 28 incidents, four times the next most frequent. Attribution below it is fragmented, with Russia-linked APT at 7, Scattered Spider and Iran-linked APT at 6 each. Crimeware accounted for 174 of 320 categorised incidents, against 89 APT and 49 ransomware. Where an attacker country was identified, Russia led at 49, followed by China at 26 and Iran at 15. Victims were concentrated in the United States at 147 incidents, with the United Kingdom second at 24.
Three campaign clusters shaped the period. The Shai-Hulud and TeamPCP worms spreading through the npm and PyPI registries drove the supply chain figures. The FortiBleed campaign converted credentials exposed on 73,932 FortiGate devices into partnerships with the Inc and Lynx ransomware groups. Joint government advisories in July identified Iranian exploitation of programmable logic controllers in US critical infrastructure and Russian targeting of communications and energy providers through edge devices.
Consumer Goods & Services
The sector was identified in 36 incidents, ranking fourth of fourteen, with volume at 8, 17 and 11 across the three monthly windows.
Mass credential extortion dominated, with ShinyHunters responsible for 7 of the 9 attributed incidents: Ralph Lauren at 139,903 accounts on 18 June, JCPenney at 368,418 on 20 June, Madison Square Garden Sports at 9.8 million on 24 June, Sysco at 2.7 million on 28 June, and Carhartt at 12.9 million on 25 August. That is approximately 26 million customer records taken by a single actor in eleven weeks.
Ransomware produced operational disruption rather than data loss alone. Fairlife suspended US dairy production on 17 July, with Anubis claiming the attack on 21 July and Coca-Cola confirming data theft on 27 July. Japan’s largest cold-chain operator was disrupted on 15 July, affecting KFC and supermarket supply. Slovenian casinos were taken offline and reopened on 31 August.
The most repeated mechanism was compromise through a supplier rather than the retailer. Nintendo lost data through a WebMD subsidiary, Lidl through an external service provider across three countries, and Żabka through a compromised third-party account. De Bijenkorf, Pokémon Center, and Valve’s Steam hardware customers were all affected by the Ceva logistics compromise, and Estée Lauder was exposed through the Oracle E-Business flaw exploited by Cl0p. Six incidents carry an explicit supply chain classification and several more are third-party in substance.
Two threads are specific to consumer-facing businesses. The 2026 FIFA World Cup generated a sustained fraud wave, with more than 35,000 fake sites tracked by 29 July alongside purchase-scam and ticket-fraud campaigns through June and July. Hospitality infrastructure was used as an espionage vector, with Midnight Blizzard hijacking hotel Wi-Fi DNS to steal Microsoft 365 credentials from travellers, reported on 24 July and again on 3 and 4 August. This is the only sustained state-linked activity touching the sector, and the retailer serves as delivery infrastructure rather than the intended target.
Gaming platforms emerged as a consumer attack surface in their own right, through ClickFix attacks on Steam forums delivering XMRig cryptominers on 25 July and a trojanised Roblox script launcher distributing infostealers and remote access trojans on 3 August.

Threat level for the consumer goods and services sector over the next 90 days is assessed as an elevated risk.
The following developments are anticipated based on current trends, actor capabilities, and operational patterns:
Mass Credential Extortion as a Sustained Campaign. ShinyHunters took approximately 26 million customer records from five named consumer brands in eleven weeks. This is an established and repeating business model, not a campaign with an endpoint. Consumer brands holding large customer databases should assume they are in scope regardless of whether they have been previously targeted.
Ransomware Causing Operational Disruption. Fairlife, Coca-Cola, and Japan’s largest cold-chain operator confirm that ransomware in this sector produces physical operational consequences beyond data loss. Supply disruption, production suspension, and retail impact are now documented outcomes. The Anubis group’s claim against Fairlife and Cl0p’s exploitation of the Oracle E-Business flaw indicate multiple active ransomware actors with demonstrated consumer sector reach.
Supply Chain as Primary Exposure Path. Six incidents carried an explicit supply chain classification, with several more third-party in substance. Nintendo, Lidl, Zabka, and De Bijenkorf were all compromised through suppliers rather than directly. Consumer brands at the end of large supply chains have limited visibility into the security posture of second and third-tier vendors, and this gap is being actively exploited.
Gaming and Consumer Platform Targeting. ClickFix attacks on Steam forums and a trojanized Roblox script launcher distributing infostealers confirm gaming platforms have emerged as a consumer attack surface in their own right. These platforms reach large authenticated user bases with payment credentials attached, making them attractive delivery infrastructure for both cryptominers and remote access tools.
Event-Driven Fraud Waves. The 2026 FIFA World Cup generated more than 35,000 fake sites alongside sustained purchase-scam and ticket-fraud campaigns. Major sporting and entertainment events reliably produce this pattern. Organizations in travel, ticketing, and consumer retail should anticipate elevated fraud volumes around any comparable event in the next 90 days.
Over the past 90 days, CYFIRMA’s telemetry has identified 4,480 mentions of consumer goods & services organizations out of a total of 42,004 industry-linked mentions. This is from a total of 300k+ posts across various underground and dark web channels and forums.
Consumer goods & services organizations landed in 6th place out of 14 industries in the last 90 days, with a share of 10.67% of all detected industry-linked chatter.
Below is a breakdown by 30-day periods of all mentions.


Underground & dark web chatter related to the consumer goods & services sector over the last 90 days is dominated by data breach and data leak discussions, both of which rise steeply across all three periods and roughly triple over the window. Ransomware mentions remain broadly stable at modest levels, and web exploit volumes are flat throughout. Claimed hacks fluctuate at low levels, while DDoS and hacktivism drop sharply after the first period and remain minimal.

Consumer goods & services show breach and leak chatter roughly tripling across the window, with both categories accounting for almost the entire sector volume. Reported incidents moved the other way over the same period, falling in the final window. That divergence is characteristic of extortion publication lag rather than declining activity, where data taken earlier surfaces on leak sites weeks later and generates chatter about compromises that are already complete.
Data Breach and Data Leak: Both climb in every period and together account for the overwhelming majority of sector chatter. A single actor was responsible for the large majority of attributed sector incidents, taking approximately 26 million customer records across five retailers in eleven weeks. The volume of this kind reflects mass credential extortion rather than distributed opportunistic activity, and the final-period spike aligns with publication of previously stolen data rather than new intrusion.
Claim Inflation: Publicly claimed figures in this campaign have run substantially above verified counts, with one August retail dump independently confirmed at roughly half the claimed volume. Chatter measures attacker assertion, not confirmed exposure, and this sector is currently the one where that gap is widest.
Supplier Compromise as the Repeated Mechanism: The most consistent route into this sector was a third party rather than the retailer, spanning logistics providers, external service providers, subsidiaries, and an ERP platform flaw. Retailers hold limited visibility into these environments and cannot patch them, which makes supplier inventory and contractual breach notification more consequential here than perimeter hardening.
Ransomware: Stable and modest in chatter but disproportionately consequential in outcome. Sector incidents included suspended dairy production, disruption to a national cold-chain operator affecting downstream food supply, and casinos taken offline for an extended period. Encryption in this sector halts physical operations rather than only encrypting records, and low chatter volume understates that impact.
Consumer-Facing Fraud Surface: Two threads sit outside conventional enterprise compromise. A major sporting event drove a sustained fraud wave running to tens of thousands of fraudulent sites, and hospitality network infrastructure was used to harvest credentials from travellers. In the latter case, the consumer business is the delivery infrastructure rather than the intended target, which places the loss outside the organisation that was breached.
Web Exploit, DDoS, Claimed Hacks and Hacktivism: All remain low and largely flat. The absence of movement in disruption and claim-based categories, against steeply climbing breach and leak volumes, confirms attacker focus on quiet data acquisition and extortion rather than visible attack activity.
Over the past 90 days, CYFIRMA’s telemetry has identified 119 mentions of consumer goods & services organizations out of a total of 2,632 industry mentions. This is from over 10k CVEs reported and updated in the last 90 days.
Consumer goods & services organizations ranked 5th out of 14 industries in the last 90 days, with a share of 4.52% of all detected industry-linked vulnerabilities.
Below is a breakdown by 30-day periods of all mentions.


Reported CVEs in the consumer goods & services sector over the last 90 days are concentrated in the final period, following a mid-period dip. Remote code execution and injection attacks both rise sharply to reach parity as the joint dominant categories, an even split not seen in other sectors in this report. Cross-site scripting recovers to initial levels after a mid-period decline. Denial of service and memory and buffer vulnerabilities rise modestly from near zero. Privilege escalation declines slightly, while directory traversal and information disclosure appear only in the final period at minimal levels.

Consumer goods & services shows moderate CVE volume relative to other sectors, with a final-period rise following a mid-period dip. The disclosure figures alone would support an elevated rather than high rating. The score reflects an active unauthenticated remote code execution campaign against the sector’s dominant e-commerce platform that began immediately after this reporting window closed and is not represented in the data below.
Active E-Commerce Platform Exploitation: An unauthenticated remote code execution flaw in Magento Open Source and Adobe Commerce, tracked as CVE-2026-75650, has been exploited in the wild since early September, with a vendor patch released only in the last days. Fully patched stores were compromised, so patch currency prior to the hotfix was not a defence, and successful exploitation deploys a persistent Rust backdoor alongside PHP web shells. Any store internet-facing during the exposure window should be treated as compromise-suspect and scanned rather than assumed clean, with encryption key rotation following remediation.
Remote Code Execution and Injection at Parity: Both categories rise sharply in the final period to equal volume, an even split not present in other sectors where code execution dominates. Injection at this level in a retail context points at the data layer behind checkout, catalogue and customer account functions, where the objective is extraction of stored payment and customer records rather than system control.
Card Data as the Standing Objective: Compromise of checkout and payment flows produces continuous yield rather than a single extraction event, which is why web application flaws in this sector convert into sustained skimming rather than one-off theft. The backdoor deployment observed in current platform exploitation is consistent with that persistence objective.
Cross-Site Scripting: Recovers to initial levels after a mid-period dip. In consumer-facing retail, client-side flaws serve as the injection point for payment page skimming rather than as an endpoint in themselves, and should be assessed alongside the code execution categories rather than separately.
Scale of Deployment as the Multiplier: The severity here derives less from disclosure count than from platform concentration. A single flaw in a dominant e-commerce platform exposes a large share of the sector simultaneously, and smaller retailers running managed or unmanaged storefronts frequently lack the capacity to apply an out-of-cycle hotfix within the window that matters.
Remaining Categories: Denial of service, memory and buffer, privilege escalation, directory traversal, and information disclosure all remain minimal and do not currently shape the sector’s risk profile.
In the past 90 days, CYFIRMA has identified 231 verified ransomware victims in consumer goods & services organizations. This accounts for 8.61% of all 2,684 ransomware victims during the same period, placing this sector 6th out of 14 industries.

Furthermore, a quarterly comparison shows that the number of victims in consumer goods & services organizations has grown. It went up from 190 to 231 victims, a significant 21.6% increase. However, the overall interest, represented by share, has remained remarkably even, going from 8.54% to 8.61% of all victims.


Monthly activity has oscillated without a clear directional trend, moving between 61 and 96 victims across the period. Activity dipped in May before recovering steadily through June and July, reaching a period high of 91 in August. September only accounts for the first few days so far.

Qilin and Thegentlemen dominated the period, together accounting for roughly a quarter of all sector victims. Both escalated sharply from June into July and August, with Thegentlemen peaking at 14 victims in August and Qilin at 15 in July.
August brought a notable shift in the wider actor set. Majinahanashi entered with 10 victims and no prior sector history, alongside Orova, Cl0p, and Direwolf recording their first victims that month. LockBit5 and Stormous were early drivers in June before tapering off sharply, illustrating the rapid turnover among active groups.

Out of the 99 gangs, 61 recorded victims in the consumer goods & services industry in the last 90 days, representing a 62% participation rate.
Qilin and Thegentlemen had the highest numbers of victims by a wide margin, though both recorded relatively low shares of their overall activity in this sector, at 9.5% and 8.1%, respectively.
Majinahanashi stands out with 45.5% of its victims in this sector, the highest share among meaningful-volume gangs. Stormous (33.3%), Apt73/bashe (25.0%), and Blacknevas (21.4%) also show strong sector focus.
On average, gangs active in this industry recorded a 14.3% share of their victims from this industry. That is about 1 in 7 victims.

Retail – Brick & Mortar and Hospitality & Leisure accounted for the largest share of victims by a wide margin, together representing close to two-fifths of all sector victims. Both handle high volumes of payment card data and customer records while operating on thin margins that make prolonged downtime difficult to absorb.
Restaurants, Food & Beverage, Recreation & Fitness, and Apparel & Footwear formed a consistent second tier. Victims were recorded across all 18 tracked subsectors, from e-commerce and specialty retail through to gaming and funeral services, confirming broad targeting across the entire consumer vertical.

The geographic distribution heatmap underscores the widespread impact of ransomware, highlighting the countries where victims in this industry have been recorded.

Consumer goods & services victimology shows the USA as the most targeted, accounting for 31% of all victims.
The remaining activity is distributed among 51 countries, with 156 victims.
The UK, Canada, Malaysia, China, and Belgium recorded the highest elevations in the last 90 days.
Germany, the Netherlands, Turkey, and Chile saw the largest declines.
In the last 90 days, 52 countries recorded consumer goods & services victims, 10 more than the 42 countries in the previous period.

The Consumer Goods & Services sector threat landscape is expected to remain high through the next 90 days. Victim volume grew 21.6% quarter-on-quarter from 190 to 231, the sector ranks 6th of 14 industries at 8.61% of all ransomware victims, and August recorded a period high of 91 victims. The combination of rising volume, expanding geographic reach, and a broad active actor set supports a forward posture of sustained elevated targeting.
Volume outlook: Monthly activity has oscillated between 61 and 96 victims without a clear directional trend, though the last three months show consistent upward movement from the May trough of 63 to the August high of 91. A baseline of 240 to 270 victims over the next 90 days is the most plausible outcome, with upside risk if the groups that entered in August sustain their tempo.
Actor behaviour: 61 of 99 active gangs recorded consumer goods & services victims, a 62% participation rate indicating this vertical is a widely shared target across the ransomware ecosystem. Qilin and Thegentlemen lead by volume, and both escalated through the period. Majinahanashi is the most significant new development, entering in August with 10 victims and directing 45.5% of its total activity here, marking it as a deliberate sector specialist. Orova, Clop, and Direwolf also entered the sector in August with no prior history.
Specialist targeting risk: The average sector share across active gangs is 14.3%, roughly one in seven victims. Beyond Majinahanashi, Stormous at 33.3% and Apt73/bashe at 25.0% show disproportionate focus relative to their overall activity, indicating deliberate rather than incidental selection among a meaningful portion of the actor set.
Geographic targeting: Country coverage expanded from 42 to 52, a notable widening of the affected footprint. The USA held steady in absolute terms at 70 victims, but its share fell to 31% as activity redistributed. The UK, Canada, Malaysia, China, and Belgium all gained, while Germany recorded the sharpest decline. Continued expansion across Asia-Pacific and Latin America is expected.
Subsector risk: Retail – Brick & Mortar and Hospitality & Leisure represent the highest-risk subsectors. Both operate customer-facing environments where downtime translates directly into lost revenue, giving attackers strong leverage and making rapid payment more likely than in sectors with greater operational slack.
APT Campaigns (Elevated): Consumer goods & services featured in 17 of 108 campaign activity updates (16%), rising from 7 in absolute terms, while share fell from 37% as the campaign pool expanded almost sixfold. The sector is targeted consistently without attracting disproportionate attention relative to the wider landscape. Lazarus Group led campaign counts by a clear margin, consistent with known DPRK targeting of consumer-facing organisations for financially motivated operations, followed by China-linked Stone Panda, MISSION2074, Leviathan, APT27, and Hafnium. The actor set is narrower than in most sectors, concentrated around North Korean and China-linked activity. Cloud security software ranked second among targeted technologies, pointing to interest in the controls protecting customer-facing cloud environments rather than the applications alone, and two Citrix products, three Fortinet products, and Active Directory together indicate a perimeter and identity movement pattern. Victims span 36 countries, with the United States and Japan tied at the highest count.
Reported Cyber Incidents (Elevated): 36 incidents recorded, ranking 4th of 14, distributed at 8, 17, and 11 across the three monthly windows. Mass credential extortion dominated, with ShinyHunters responsible for the large majority of attributed sector incidents, taking approximately 26 million customer records from Ralph Lauren, JCPenney, Madison Square Garden Sports, Sysco, and Carhartt across eleven weeks. Ransomware produced operational disruption rather than data loss alone, with Fairlife suspending US dairy production, Japan’s largest cold-chain operator disrupted in a way that affected KFC and supermarket supply, and Slovenian casinos taken offline. The most repeated mechanism was compromise through a supplier rather than the retailer, spanning logistics providers, subsidiaries, and an ERP platform flaw exploited by Cl0p. Two threads sit outside conventional enterprise compromise: the FIFA World Cup drove a fraud wave exceeding 35,000 fake sites, and Midnight Blizzard hijacked hotel Wi-Fi DNS to harvest Microsoft 365 credentials from travellers, where the consumer business is delivery infrastructure and the loss falls outside the breached organisation.
Underground & Dark Web Chatter (Elevated): The sector placed 6th of 14 at 10.67% of industry-linked chatter with 4,480 mentions, with breach and leak discussion roughly tripling across the window and together accounting for almost the entire sector volume. Reported incidents fell in the final window while chatter climbed, a divergence characteristic of extortion publication lag, where data taken earlier surfaces on leak sites weeks later. Claimed figures have run substantially above verified counts, with one August retail dump independently confirmed at roughly half its claimed volume, making this the sector where attacker assertion and confirmed exposure diverge most. Ransomware chatter stayed stable and modest while producing disproportionate operational consequences, so low volume understates that impact. Web exploit, DDoS, claimed hacks, and hacktivism all stayed flat, confirming attacker focus on quiet data acquisition.
Vulnerabilities (Elevated): The sector ranked 5th of 14 at 4.52% of industry-linked disclosures across 119 mentions, concentrated in the final period following a mid-period dip. The disclosure figures alone would support an elevated rating. The high assessment reflects an active unauthenticated remote code execution campaign against Magento Open Source and Adobe Commerce, tracked as CVE-2026-75650, exploited in the wild from early September, with a vendor patch released only in the closing days of the window. Fully patched stores were compromised, so patch currency was not a defence, and exploitation deploys a persistent Rust backdoor alongside PHP web shells. Any store internet-facing during that window should be treated as compromise-suspect and scanned. Remote code execution and injection rose to parity in the final period, an even split not present in other sectors, pointing at the data layer behind checkout rather than system control alone.
Ransomware (High): 231 victims, up 21.6% from 190, ranking 6th of 14 with share steady at 8.61%. Monthly activity oscillated without clear direction but rose consistently through the final three months to an August high of 91. Retail Brick & Mortar and Hospitality & Leisure account for close to two-fifths of all sector victims, both handling high volumes of payment card data while operating on thin margins that make prolonged downtime difficult to absorb. 61 of 99 active gangs recorded victims, a 62% participation rate, though the 14.3% average sector share indicates broadly shared rather than concentrated targeting. Majinahanashi entered in August with 10 victims and 45.5% of its activity directed here, alongside first-time entries from Orova, Cl0p, and Direwolf. Country coverage expanded from 42 to 52.