Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Study: Cyber Monday Attacks Cost Enterprises Up To $3.4M Per Hour

Holiday shopping season is popular time for launch of sophisticated attacks, RSA study says

The upcoming holiday shopping season could be prime time for attackers who hope to catch enterprises at their weakest moments, according to a study published this week.

According to a new survey of 1,100 retail companies conducted by the Ponemon Institute and sponsored by RSA, daily revenue surges by an average of 55 percent during the holiday season. If a retail site is hacked or disabled, average losses may amount to as much as $500,000 per hour, or $8,000 per minute.

Two-thirds of respondents (66 percent) said that such a disruption would also result in customer churn that would damage reputation and brand, pushing losses as high as $3.4 million from a single hour of disruption.

"This time of year is not just an opportunity for retail fraud, but an opportunity to launch attacks that take advantage of business logic vulnerabilities, DDoS [distributed denial-of-service] attacks, and more sophisticated attacks as well," says Demetrios Lazarikos, IT threat strategist at RSA.

Yet while 64 percent of organizations said they see significant increases in attack activity during the holidays, more than 70 percent of organizations do not take additional precautions in anticipation of increased attacks. And with their currently installed technology, 51 percent say that they do not have real-time visibility into Web traffic, making it difficult to identify the root cause of such attacks, the study says.

Just 23 percent of respondents said they feel that most holiday-season attacks can be quickly detected and remediated.

The report also identifies the top nine attacks organizations will likely face during the holiday season. In order of likelihood, these attacks are:

1. Botnet and distributed denial-of-service (DDoS)
2. App store fraud
3. Mobile access/account compromise
4. Click fraud
5. Stolen credit card validation
6. E-coupon abuse
7. Account hijacking
8. Electronic wallet abuse
9. Brand promotion hijacking

"We expect to see more of these attacks this year, and more attacks targeted at specific companies," says Lazarikos.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23134
PUBLISHED: 2021-05-12
Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.2 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
CVE-2021-23135
PUBLISHED: 2021-05-12
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.
CVE-2020-28722
PUBLISHED: 2021-05-12
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
CVE-2020-18165
PUBLISHED: 2021-05-12
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
CVE-2020-19275
PUBLISHED: 2021-05-12
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.