According to “The Retail and eCommerce Threat Landscape Report” from October 2018, there is a 297% increase in the number of phishing websites that target online retail businesses and customers of these businesses. There is an average of 23 phishing sites for each retail company included in the study. In 2017 the data showed that there were only 5.9 phishing websites per company.
A report illustrates how cybercriminals are increasingly targeting retailers and their customers through digital and social channels as retailers leverage new channels for increased revenue opportunities
“The Retail and eCommerce Threat Landscape Report” (October 2018), notes a 297 percent rise in the number of false retailer websites designed to “phish” for customer credentials. In Q3 alone, there was an average of 23 phishing sites per company, which is a significant increase from 2017, which averaged 5.9 phishing attacks per company.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Also, says the report, there was a 278 percent rise in stolen goods listed on black markets for resale. Even more:
- An average of 22.1 internal login pages or development servers exposed per retail company in 2018. When accessed this gives cybercriminals a portal into the retailer’s internal network
- Fake apps and social media profiles are on the rise with a 469 percent spike in suspicious applications and a 345 percent increase in fake social media profiles (respectively) in Q4 2017
What we all know is confirmed by this data. The need for increased security will be amplified exponentially as this trend continues in the future. This will increase the demand for cybersecurity professionals to the point that salaries for these positions will be driven up toward the stratosphere.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
8 common phishing emails: How to protect yourself
Cybercriminals who carry out phishing attacks have become much more proficient. These scams may hide behind people and organizations that you know...
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
The 5-Minute Cyber Brief: September 23, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.