Survey Found 87 Percent of Retailers Faced Cyber Attacks

Data theft and business disruption occurred across 18 countries as security budgets rose to combat rising digital threats.

Updated on Oct. 1, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy and cream, showing a simplified steel server rack and conduit representing retail cybersecurity infrastructure.
Nearly 90% of retail companies reported experiencing cyber incidents in the past year, prompting increased security spending to combat rising digital threats. AI Illustration. Upload story photo >

Live Poll

Do you trust that major retailers are doing enough to protect your personal data?

A global survey of IT security specialists revealed that 87% of retail companies experienced cyber incidents during the past 12 months. The findings underscore the scale of digital threats targeting the sector, which accumulates large volumes of personal data.

Why it matters

Retailers remain high-value targets due to the vast amounts of personal information gathered through e-commerce platforms and loyalty programs. The shift in security spending reflects an urgent effort to mitigate risks from phishing and application exploits.

Approximately 28% of incidents resulted in data theft, while 25% caused financial losses and 25% triggered business disruptions. While 82% of organizations increased their security budgets, 33% of retailers still report no perceived risk from AI-driven threats.

The details

Retailers faced attacks primarily through phishing—fraudulent attempts to obtain sensitive information by posing as a trustworthy entity—cyber espionage, and web application exploits. Vulnerabilities were often exacerbated by a lack of internal security expertise, insufficient awareness, and poor password hygiene. Many firms are attempting to close these gaps by outsourcing essential security functions to third-party providers.

Timeline

  1. The survey tracked cyber incident data over the past 12 months.

The Tech Race

This data follows a pattern set by the 2024 ENISA Threat Landscape report, which documents the increasing sophistication of e-commerce focused cyberattacks. Retailers are currently in an arms race against automated exploit kits that target weaknesses in legacy web infrastructure.

Shoppers may notice more frequent multi-factor authentication requirements as retailers shift security policies to combat weak password habits. These changes are designed to protect loyalty accounts and transaction data against the phishing tactics identified in the report.

The takeaway

Retailers are struggling to balance the convenience of data-rich loyalty programs with the rising cost of defending against cyber espionage. The high percentage of firms ignoring AI-related risks remains a critical metric to watch in future annual security audits.

Further reading

For more on evolving threat vectors and corporate defense strategies, visit our Cybersecurity section.

Source note: This article includes information reported by SC Media.

Live Poll

Do you trust that major retailers are doing enough to protect your personal data?