Half of APAC Retail Employees Share Sensitive Credentials with Colleagues and External Parties: Kaspersky Research 

Half of APAC Retail Employees Share Sensitive Credentials with Colleagues and External Parties: Kaspersky Research 

Retail is moving into an AI‑driven and personalised landscape, where every digital touchpoint creates both convenience and risk. A new global study conducted by Kaspersky’s Internal Research Centre surveyed IT security specialists working in the retail sector across 18 countries and revealed key target areas, the most relevant threats, and the potential damage to business.

 

Cyber incidents and the goals behind the attacks

The global retail sector, encompassing e-commerce, loyalty programs, and personalised offerings, spans the entire transaction process from initial browsing to final payment, thereby accumulating massive volumes of personal data. With only 13% of the sector escaping cyber incidents over the past year, it is clear that this environment is highly vulnerable to cyber threats and appealing for cybercriminals.

 

As for the nature of the recently experienced incidents, phishing appeared to be the prevalent threat, reported by more than one-fifth of retailers (21%). Other social engineering-related attacks on retailers featured deepfakes (13%), invoice or payment fraud (13%), business email compromise (9%), and vishing (voice phishing) (8%). The top 3 most frequently experienced incidents in retail organisations also comprised cyber espionage (19%) and web application exploits (18%).

 

During attacks, adversaries’ primary aims were stealing clients’ and employees’ personal data (34% and 28% respectively). Taken together, this diversity of threats shows that retailers are exposed not only to manipulation of employees and partners, but also to technically complex attacks against their online infrastructure.

 

Most harmful consequences experienced by organisations over the past 12 months

The most common actual results of the recent attacks on retailers in APAC included employees’ personal data theft (44%), clients’ personal data theft (39%), the theft of sensitive data such as financial credentials and legal documents (33%), and even irrecoverable data loss (33%), putting business operations and sensitive information at risk.

 

Internal incident risk factors

The survey also raised the question of internal factors which increase the likelihood of successful cyberattacks on retailers. According to the poll across the APAC region, human actions tend to be the primary concern, with a lack of IT security awareness (46%) topping the list. It is followed by insufficient expertise among IT security staff (31%) or outdated software or hardware (31%). Technical shortcomings also had a strong impact: the lack of necessary security solutions was recorded by one in every four organisations (27%).

 

A lack of security awareness may be the reason behind risky workplace behaviours and associated losses. In APAC, when asked about most typical digital misbehaviour of their colleagues, half of respondents (50%) stated sharing sensitive corporate credentials with colleagues or third parties. The act of downloading and installing software tools without IT security approval stood at 46% among the respondents. More than a third of respondents (38%) stated the use of personal devices for work‑related activities and the storage of corporate data. Employees were found to still practice irresponsible password habits, including weak or reused passwords (38%) and also connect corporate devices to public Wi‑Fi networks without using a secure connection (38%).

 

Budget changes and plans for future

Willing to enhance their IT security function, 77% of retailers in APAC increased their IT security budget this year. Unlike the general trend across other sectors, where organisations are largely planning to expand their internal IT teams, the retail industry is increasingly turning to third-party IT security providers. Only one in four companies in the region (23%) stated not increasing IT security budget by much.

 

“Retail is a highly dynamic industry: business priorities, workloads, infrastructure requirements, and economic conditions change rapidly. To ensure that cybersecurity keeps pace with these changes, retailers choose to turn to external security service providers, gaining access to the required expertise and technologies without having to continuously expand their in-house teams,” says Elizaveta Komarova, Solution Architect, Finance & Retail at Kaspersky.

 

“By outsourcing part of their cybersecurity functions, retailers effectively entrust an external partner with the resilience of their business processes and the financial risks associated with security incidents. This makes it essential to have confidence in the provider’s experience, including a proven track record with retailers of different sizes, and to eliminate potential security blind spots through 24/7/365 protection. This is especially critical during peak periods, such as seasonal sales, periods of increased consumer demand, and holidays, when the cost of any disruption is particularly high and in-house teams may have limited availability”.

 

The future of retail seems to be inextricably linked to AI. More companies in APAC are implementing AI tools in their infrastructure: 15% of retailers already have a working LLM-based tool, while 77% are currently in the discussion, design, or pilot phases. Although it speeds up operations, interestingly, only 23% of retail companies claim they don’t see any risks in AI.

 

“Retail has traditionally been one of the most receptive to new digital technologies industries. Intense competition, pressure on margins, and constantly changing consumer behaviour give retailers a direct economic incentive to adopt technologies that can improve business efficiency faster than their competitors. This is also supported by the fact that, compared with sectors such as banking, retail often faces fewer industry-specific constraints when introducing new digital solutions,” explains Elizaveta. “However, businesses should constantly balance potential returns against the level of risk they are willing to accept in pursuit of those returns. The more actively a company uses new technologies, the more important it becomes to manage the associated risks in a deliberate and structured way. This is particularly evident today with the rapid adoption of artificial intelligence. Since a serious incident can cause data breaches, operational disruption, and severe financial losses, cybersecurity must evolve at the exact same pace as the business”.

 

“Our APAC findings highlight an important gap in retail cybersecurity in the region. As retailers here adopt more connected and AI-driven technologies, it is becoming clear that some of their vulnerabilities stem from how technology and data are used and protected across the organisation. That is a good indication that cybersecurity needs to extend beyond the IT team and become part of how retailers operate, employees work and new technologies are introduced into the business,” said Adrian Hia, Managing Director for APAC at Kaspersky.

 

Enhancing protection: recommendations for retail safety

To prevent cyber incidents or at least minimize their disruptive consequences, Kaspersky recommends retail companies implement the following measures:

  • Elevate the organization’s overall cyber culture by implementing a continuous awareness program that regularly educates all employees about cybersecurity, stays up‑to‑date and includes the newest threat intelligence. This measure will foster a stronger security mindset and improve defensive behaviours.
  • Update or introduce the organization’s AI usage policies. These should explicitly address the risk of inadvertent data exposure. Define clear guidelines for how employees may interact with AI‑driven tools and specify what types of data can be entered, how to anonymise sensitive information, and which AI services are approved for use.
  • Identify the most valuable assets and essential business processes. Customer data, intellectual property, core applications, and supply‑chain workflows should stay entirely protected. This enables the organisation to understand the most critical parts of the business and, therefore, to implement a more suitable defence system.
  • Regularly monitor the current state of cybersecurity in your industry. Conduct threat assessments and examine the most likely adversaries and vulnerabilities that could have the highest impact on operations. Retail Cybersecurity Solutions will allow to build a customised security control that maximises effectiveness and stays up-to-date. They combine all the necessary features for stable growth and reliable protection from emerging threats.
  • Strengthen the capabilities of your digital environment: deploy advanced endpoint protection solutions on workstations, laptops, and mobile devices to detect and prevent cyber incidents. Ensure continuous updates of all security solutions so they stay aligned with emerging threats.
Chat with CIONow.in