{"id":1259,"date":"2024-11-21T06:00:00","date_gmt":"2024-11-21T14:00:00","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=1259"},"modified":"2024-11-20T13:44:21","modified_gmt":"2024-11-20T21:44:21","slug":"gift-or-grift-how-retailers-can-combat-cyber-threats-this-season","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/","title":{"rendered":"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season"},"content":{"rendered":"\n<p>A lot goes into deciding what to buy during the holiday shopping season \u2013 shipping times, sale prices, and finding the perfect gift for your niece (who is impossible to shop for) are likely to be at the top of your mind. Unfortunately, attackers are counting on that.&nbsp;<\/p>\n\n\n\n<p>An attacker\u2019s best friend is urgency and Black Friday kicks off a perfect season for them. Not only are online retailers primarily focused on meeting shopping demand \u2013 and avoiding downtime on their sites \u2013 but shoppers are rushed, stressed, and primed to act fast to get a good deal. Because of this, both retailers and shoppers can create a prime environment for attackers to deploy ransomware, scam buyers, or steal valuable PII.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The countdown begins<\/h2>\n\n\n\n<p>Despite not celebrating American Thanksgiving, sites worldwide mark Black Friday and Cyber Monday as the beginning of the holiday sales season. Because of this, we decided to look at ecommerce assets in the UK and Europe, as well as global trends, to understand where external assets could be vulnerable to attackers this shopping season.&nbsp;<\/p>\n\n\n\n<div class=\"inset narrow right looser-top\">\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"800\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp\" alt=\"\" class=\"wp-image-1263\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp 600w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii-384x512.webp 384w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\n\n\n\n<\/div>\n\n\n\n<p>We examined an anonymized set of ecommerce assets collected from November 2023 to October 2024. These assets are web applications (web apps) or web interfaces. To identify whether they are used for ecommerce or part of an ecommerce system, we used machine learning and natural language processing to identify indications like payment functions, cart functions, or common keywords like \u201ccheckout.\u201d&nbsp;<\/p>\n\n\n\n<p>Ecommerce assets aren\u2019t only in high demand on Cyber Monday \u2013 they also represent a potential treasure trove of data. <strong>The majority (53%) of ecommerce assets collect user PII. <\/strong>Although this number has gone slightly down compared to 58% last year, it presents a tempting target for attackers looking to harvest PII, steal payment card details, or damage a brand\u2019s reputation. Collecting and storing PII makes an asset fundamentally more attractive to attackers and, combined with other vulnerabilities, can expose massive risks for an organization.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Some ecommerce websites are still on the naughty list<\/h2>\n\n\n\n<div class=\"inset left\">\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"1646\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-web-apps-lacking-https-1280x1646.webp\" alt=\"\" class=\"wp-image-1269\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-web-apps-lacking-https-1280x1646.webp 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-web-apps-lacking-https-398x512.webp 398w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-web-apps-lacking-https-768x987.webp 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-web-apps-lacking-https-1195x1536.webp 1195w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-web-apps-lacking-https.webp 1400w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n\n\n\n<\/div>\n\n\n\n<p>In the 2024 edition of our <a href=\"https:\/\/www.cycognito.com\/resources\/reports\/cycognito-state-of-external-exposure-management-2024\/\">State of External Exposure Management Report<\/a>, we looked at adoption rates of HTTPS and web application firewalls (WAFs) as a proxy for \u201cbasic care\u201d on web interfaces and web applications. These measures aren\u2019t the best protections available, but if an asset is missing them, it can be a sign of deeper neglect (or that the asset was forgotten about entirely).&nbsp;<\/p>\n\n\n\n<p>HTTPS just celebrated its 30th birthday, but we found that adoption rates have gotten worse, not better, when it comes to ecommerce sites. <strong>Although the vast majority of ecommerce sites use HTTPS, 3% of ecommerce web apps still lack this protection,<\/strong> <strong>increasing from 2% last year. Adoption rates are even lower in Europe, with almost 5% of ecommerce assets hosted by European companies lacking HTTPS.&nbsp;<\/strong><\/p>\n\n\n\n<p>When it comes to WAFs, last year we found they were missing from over a quarter (28%) of ecommerce web apps. This year protections declined even further, with over 40% of assets lacking a WAF. This was consistent in both the UK and Europe as a whole as well.&nbsp;<\/p>\n\n\n\n<div class=\"clear\"><\/div>\n\n\n\n<div class=\"inset right looser-top\">\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"1097\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-assets-with-pii-missing-waf-1280x1097.webp\" alt=\"\" class=\"wp-image-1274\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-assets-with-pii-missing-waf-1280x1097.webp 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-assets-with-pii-missing-waf-512x439.webp 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-assets-with-pii-missing-waf-768x658.webp 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-ecommerce-assets-with-pii-missing-waf.webp 1400w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n\n\n\n<\/div>\n\n\n\n<p>While it\u2019s never good for a web application to be missing a WAF, it becomes more serious if that asset is attractive to attackers or in some way presents a tempting target. <strong>We found that the number of ecommerce assets that contain PII and are missing a WAF also increased, from one in four (24%) in 2023 to over one in three (35%) this year.<\/strong> Numbers are worse in the UK, with 43% of ecommerce assets that collect PII missing a WAF, and in Europe, with 40% lacking this protective measure.&nbsp;<\/p>\n\n\n\n<p>Certificate validity issues have improved, with only 6% of ecommerce assets having certificate validity issues compared to 13% last year. Unfortunately, in the UK rates actually increased, with 14% of ecommerce assets with certificate validity issues. Europe fared slightly better, with 11% of assets having certificate validity issues. Missing certificates creates a massive customer trust issue for retailers hoping to make a sale on Cyber Monday, as buyers may close a window or click away rather than trusting their details to a suspicious or insecure looking site.&nbsp;<\/p>\n\n\n\n<p>Asking users to consent to cookies is a basic regulatory issue, especially for sites operating or with customers in Europe. Although companies have had years to become compliant with GDPR, we found that 79% of all ecommerce assets <em>fail <\/em>to ask users to consent to cookies, creating a potential compliance headache for the organization. This number has increased 1% since 2023. Across the pond, figures are only slightly better: only 67% of UK-based ecommerce assets fail to ask, and 76% across all of Europe.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">But a lot to be thankful for<\/h2>\n\n\n\n<p>At the end of the holiday season, a lot of people make big commitments for their New Year&#8217;s resolutions \u2013 eating healthier, picking up a hobby, or even running a marathon.&nbsp;<\/p>\n\n\n\n<p>The New Year\u2019s resolutions to clean up web apps worked, at least for retail organizations \u2013 fewer than 1% of ecommerce assets have any critical security issues, a 50% decrease from last year. Only 17% of those assets store PII, another marked improvement from last year where half of all ecommerce assets with critical issues collected or used PII.&nbsp;<\/p>\n\n\n\n<p>Security teams are also focusing on the right issues, with the number of easily exploitable critical issues decreasing from 76% to only 67%. Easily exploited issues in general dropped as well, falling to 19% from 31% last year. This hard work has also cut the number of ecommerce assets affected by an issue in the OWASP top ten in half, dropping from 7% to 4%.&nbsp;&nbsp;<\/p>\n\n\n\n<p>We found that almost 2 in 5 (38%) of ecommerce assets have one or more cryptographic vulnerabilities. It appears that the retail industry has made progress on this since last year, with a 10% decrease in vulnerable assets (48% to 38%). Over 40% of ecommerce assets in the UK have at least one cryptographic vulnerability, however, and numbers are even worse for Europe as a whole \u2013 50% of ecommerce assets owned by European organizations have at least one cryptographic issue.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Unlike the holidays, good cybersecurity lasts the whole year<\/h2>\n\n\n\n<p>No matter when the sales start, retailers need to take the time to make sure their ecommerce sites are keeping valuable PII and financial information safe. Checking for basic issues, like HTTPS or missing WAFs, can serve as indicators of more serious security issues. Don\u2019t leave discovering, testing, and remediating issues until the last minute \u2013 it\u2019s more effective to conduct continuous discovery and low-and-slow testing throughout the year.&nbsp;<\/p>\n\n\n\n<p>Making a list and checking it twice may be good enough for Santa Claus, but it\u2019s not enough for ecommerce sites. Don\u2019t leave discovering and testing your attack surface to once or twice a year \u2013 to stay ahead of attackers, prioritize continuous, comprehensive surveys of your entire external attack surface. You don\u2019t want customers to find they received a piece of coal when they meant to buy a new sweater.&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>At CyCognito, we know you want to focus on the joyous parts of the holiday season. That\u2019s why we spend the whole year continuously identifying, testing, and prioritizing externally exposed assets, giving organizations time to resolve critical issues before attackers can exploit them.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Methodology<\/h2>\n\n\n\n<p>For this piece, CyCognito\u2019s research team aggregated and analyzed ecommerce web application assets across its customer base from November 2023 to October 2024. All findings are anonymized and normalized. These customers span multiple industry verticals and include a mix of small, medium, and large enterprises across the globe, including Fortune 500 companies.<\/p>\n\n\n\n<p>References to security scores are based on the common vulnerability scoring system (CVSS) scores derived from the National Institute of Standards and Technology\u2019s (NIST) National Vulnerability Database (NVD).&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Interested in learning more?\u00a0<\/h2>\n\n\n\n<p>To learn more about CyCognito\u2019s platform and see it in action, explore our platform with a self-guided, interactive <a href=\"https:\/\/app.getreprise.com\/launch\/4yj23py\/\">dashboard product tour<\/a>. If you\u2019d like to chat to an expert about external risks that might affect your organization, you can schedule a demo at https<a href=\"https:\/\/www.cycognito.com\/demo\">:\/\/www.cycognito.com\/demo<\/a>.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CyCognito examined an anonymized set of ecommerce assets collected from November 2023 to October 2024. While there is evidence of better security practices, some basic vulnerabilities and misconfigurations persist. Retailers need to take the time to make sure their ecommerce sites are keeping valuable PII and financial information safe. <\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[208,209,16],"class_list":["post-1259","post","type-post","status-publish","format-standard","hentry","category-research","tag-cyber-monday","tag-ecommerce","tag-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season | CyCognito Blog<\/title>\n<meta name=\"description\" content=\"CyCognito examined an anonymized set of ecommerce assets. While there is evidence of better security practices, basic issues persist.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season\" \/>\n<meta property=\"og:description\" content=\"CyCognito examined an anonymized set of ecommerce assets. While there is evidence of better security practices, basic issues persist.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-21T14:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/banner-blog-2024-11-21-2400x1256-email.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Emma Zaballos\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Emma Zaballos\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\"},\"author\":{\"name\":\"Emma Zaballos\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58\"},\"headline\":\"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season\",\"datePublished\":\"2024-11-21T14:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\"},\"wordCount\":1341,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp\",\"keywords\":[\"Cyber Monday\",\"ecommerce\",\"Research\"],\"articleSection\":[\"Research\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\",\"name\":\"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp\",\"datePublished\":\"2024-11-21T14:00:00+00:00\",\"description\":\"CyCognito examined an anonymized set of ecommerce assets. While there is evidence of better security practices, basic issues persist.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp\",\"width\":600,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58\",\"name\":\"Emma Zaballos\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g\",\"caption\":\"Emma Zaballos\"},\"description\":\"Product Marketing Manager\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/emma-zaballos\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season | CyCognito Blog","description":"CyCognito examined an anonymized set of ecommerce assets. While there is evidence of better security practices, basic issues persist.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/","og_locale":"en_US","og_type":"article","og_title":"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season","og_description":"CyCognito examined an anonymized set of ecommerce assets. While there is evidence of better security practices, basic issues persist.","og_url":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/","og_site_name":"CyCognito Blog","article_published_time":"2024-11-21T14:00:00+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/banner-blog-2024-11-21-2400x1256-email.png","type":"image\/png"}],"author":"Emma Zaballos","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Emma Zaballos","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/"},"author":{"name":"Emma Zaballos","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58"},"headline":"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season","datePublished":"2024-11-21T14:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/"},"wordCount":1341,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp","keywords":["Cyber Monday","ecommerce","Research"],"articleSection":["Research"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/","url":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/","name":"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp","datePublished":"2024-11-21T14:00:00+00:00","description":"CyCognito examined an anonymized set of ecommerce assets. While there is evidence of better security practices, basic issues persist.","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#primaryimage","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/illus-53-percent-of-ecommerce-assets-collect-user-pii.webp","width":600,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/gift-or-grift-how-retailers-can-combat-cyber-threats-this-season\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"\u200b\u200bGift or Grift? How Retailers Can Combat Cyber Threats This Season"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/42c314196e7f096a74bd885693643d58","name":"Emma Zaballos","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7ff812a5ab34a955a1e815e6719c68a7?s=96&d=mm&r=g","caption":"Emma Zaballos"},"description":"Product Marketing Manager","url":"https:\/\/www.cycognito.com\/blog\/author\/emma-zaballos\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/1259","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=1259"}],"version-history":[{"count":21,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/1259\/revisions"}],"predecessor-version":[{"id":1297,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/1259\/revisions\/1297"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=1259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=1259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=1259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}