Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Buy now - breached later current page
Link copied

Buy now - breached later

Oct 20, 2017
Author:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Blog banner default
Buy now - breached later
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

Once again retailers are ramping up operations in time for the infamous Black Friday and Cyber Monday sales. Given the recent huge scale DDoS attacks powered by IOT devices under the control of the Mirai botnet retailers are taking many precautions to keep transactions flowing during the sales. Unfortunately, just as the retailers are getting prepared so are the attackers, ready to seize any opportunity to steal user’s data or hold retailers to ransom.

Attackers often use the sales period to mask fraudulent transactions and attacks relying on security teams being unable to process the ever-larger volumes of data quickly enough. Take for example financial fraud. In FBI investigations, they often find that denial of service attacks are used to cover up fraud. This works because security teams are busy firefighting the attack and don’t notice the money being taken out the back door. The same is true on Black Friday, it effectively simulates a denial of service attack and provides great cover for attackers looking to exploit vulnerabilities in sites and services as network and security teams battle with increased traffic volumes. Fraudulent card transactions are more likely to succeed as banks and card processors are expecting a sudden flurry of increased spending.

The main threat on offer this year is ransomware as users quickly plow through email offers in the pursuit of a bargain. We are already seeing attackers generating phishing campaigns that appear to be offers or delivery notes in order to manipulate the user into opening malicious content and becoming infected. One major issue faced by organisations is users browsing shopping websites and using personal web based email as this often bypasses network safeguards such as email filters resulting in threats reaching the endpoint. This is why it is important to build on solid proactive endpoint security and not rely on network or detection products alone.

Retailers are also a key target as attackers know that they can demand high ransoms for access to data, systems, and even websites during this critical period. The retail environment is driven by money and as such has little to no tolerance for downtime, especially during peak times such as Black Friday. If a reactive security solution such as AV detects a threat during Black Friday, a retailer might be faced with a decision between definitely losing millions in revenue or leaking customers details.

In the worst cases, security may be removed or disabled if it gets in the way of taking payments. This is why it is important to have proactive measures in place and an understanding of security from the board level down because these decisions need to happen fast. As the sales get bigger every year so does the risk, with huge quantities of money at stake. It is important then to think about robust proactive security measures to protect yourself and your organisation.

Hopefully retailers have learnt the lessons of past breaches and begun to shift to a more proactive security model. They should have learnt that compliance with industry regulations does not equate to security and that AV isn’t the best defence in 2016. Stay secure this year and grab yourself a bargain not a breach on Black Friday.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • 2021 Gartner Buyers’ Guide for Privileged Access Management: A 5-Step Approach to Selecting the Right PAM Tool
    Jun 24, 2021 2021 Gartner Buyers’ Guide for Privileged Access Management: A 5-Step Approach to Selecting the Right PAM Tool
    Blog
    1m
  • PCI-DSS And Least Privilege
    Aug 8, 2011 PCI-DSS And Least Privilege
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.