How do cyberattacks on retailers compromise personal data?
Retailer breaches mostly start with hacking, phishing or insider leaks, exposing personal data that is often sold on the dark web.
Covers: This page explains the main ways attackers breach retailers — such as point-of-sale malware, e-commerce skimming, credential stuffing, ransomware and third-party vendor compromise — and how each path exposes payment, contact and account data. It does not cover individual incident timelines or give legal or remediation advice for a specific breach.
Also answers: How do hackers steal customer data from retailers? · How do retail data breaches happen? · What causes retailer cyberattacks and data theft? · How is personal data compromised in retail cyberattacks?
- One page for this question6 other ways of asking lead here
- 5 independent sourcesEvery claim links to what supports it
- Joins the mapLinked as related pages appear
- Clean discussionScreened before anything appears
The short answer
Evidence-backed AI-prepared starting mapRetailer breaches compromise customer data mainly through hacking that exploits software vulnerabilities, social engineering such as phishing that tricks insiders into disclosing information, and accidental or intentional disclosure by insiders, along with loss or theft of unencrypted devices. Across a large global survey of organisations, hacking was the most frequent attack type reported (330 of 895 attacks, 37%), followed by spam email (13%), malicious domains (9%), mobile apps (8%), phishing (7%) and malware (7%); ransomware (2%), botnets (2%) and advanced persistent threats (1%) were far less common. The data exposed is personal information — contact details, account credentials and payment data — and criminals often sell it on the dark web. Breaches are frequently never detected, and prevention can reduce but not eliminate the risk.123
- Evidence 16
- Interpretation 3
Did this answer your question?
Be the first to voteIn brief
The data taken is personal information — contact details, account credentials and payment data — and it is often sold on the dark web.1
Evidence-backedSupply-chain weaknesses can turn a localised breach into systemic disruption, because interconnected systems transmit the compromise along the chain.4
Evidence-backedPrevention reduces but cannot eliminate breach risk, and many breaches are never detected — so published totals understate the real scale.1
Evidence-backedReported scope can change: Asos first described its breach as basic contact details, then updated after criminals told the BBC it went further — a claim that remains unconfirmed.3
Evidence-backed
At a glance
The picture in numbers
Live · updated just now
4.5 billion records
26 billion records
The evidence behind it
5 sources- Other studies and data2
- Background3
Published in 2022 and 2026
| Source | Kind | Year |
|---|---|---|
| Asos hackers took more personal details than first revealed, BBC finds | Background | 2026 |
| Cyberattacks in supply chains: A multi-case study. | Other studies and data | 2026 |
| Data breach (Wikipedia) | Background | Unknown |
| List of data breaches (Wikipedia) | Background | Unknown |
| A deeper look into cybersecurity issues in the wake of Covid-19: A survey. | Other studies and data | 2022 |
The community around it
No one has added to this page yet. Firsthand experience, a newer study or a different reading of the numbers would show up here, credited to you.
What it means for you
Which fits you?
Pick the situation closest to yours. Each answer says what it rests on.
If you want to understand the most likely way your data would be taken in a retail breach
focus on hacking of software vulnerabilities and phishing-style social engineering, which dominate reported attack types, rather than on rarer techniques like ransomware or advanced persistent threats.21
Evidence-backedIf you are assessing how much a retailer's breach could affect you
consider that exposed data may include contact details, account credentials and payment data, and that the retailer's initial description of scope can later expand, as in the Asos case.31
Evidence-backedIf you assume a retailer's own systems are the only weak point
account for third-party and supply-chain exposure, since coordination failures between interconnected systems can amplify a localised breach into wider disruption.4
Evidence-backedIf you are reading published breach totals
treat them as a floor, because many breaches are never detected and the available lists are non-exhaustive.15
Evidence-backedIf you are a retailer or supplier deciding where to invest
the supply-chain research points to secure architecture, cross-organisational threat intelligence sharing and supplier-support programmes, though these are presented as guidance rather than tested interventions.4
Evidence-backedThe full story · 4 chapters
01
How attackers get in
AI summary:Hacking software vulnerabilities is the most reported attack route, with phishing, insider disclosure and device loss also common.
Evidence-backed: The most common route is hacking into a system by exploiting software vulnerabilities. In a global survey of organisations, hacking was the single most frequent attack type, accounting for 330 of 895 reported attacks (37%). Social engineering — phishing in particular — is the other main human-facing route, where insiders are tricked into disclosing information; phishing accounted for 7% and malware 7% in the same survey, with spam email at 13% and malicious domains at 9%. Breaches can also stem from accidental or intentional disclosure by insiders and from loss or theft of unencrypted devices.12
Interpretation: The survey's ranking matters for expectations: ransomware (2%), botnets (2%) and advanced persistent threats (1%) were reported far less often than hacking, spam email and phishing. That does not mean those techniques are harmless — a single successful ransomware or supply-chain attack can be highly disruptive — but it does mean the everyday volume of retail breaches is dominated by more mundane entry methods.2
How concerned are you about your personal data being compromised in a retailer cyberattack?
Join free to voteAlready a member? Sign inYour individual answer is private. Only totals are shown.
02
What customer data gets exposed
AI summary:Breaches expose contact details, account credentials and payment data, which is often sold on the dark web.
Evidence-backed: A data breach is the unauthorised exposure, disclosure or loss of personal information. In retail settings that means contact details, account credentials and payment data. The Asos case illustrates the pattern: the retailer initially described the breach as involving "basic contact details", then issued an update after the BBC was contacted by cyber criminals who said the breach went beyond that. The wider claim that more personal details were taken is reported but not confirmed by the retailer in the material available.13
Evidence-backed: Once taken, stolen data is commonly sold on the dark web. Aggregate figures give a sense of scale: about 4.5 billion records were exposed in the first half of 2018 alone; a 2019 collection of 2.7 billion identity records included 774 million unique email addresses and 21 million unique passwords; and a January 2024 database dubbed the "mother of all breaches" contained over 26 billion records, including data linked to Twitter, Adobe, Canva, LinkedIn and Dropbox. These are cross-industry totals, not retail-specific, and the lists are non-exhaustive.51
03
Why third parties and supply chains amplify the damage
AI summary:Interconnected systems can spread a breach from one supplier along the chain, turning a local incident into wider disruption.
Evidence-backed: A multi-case study of supply-chain cyberattacks argues that disruption is systematically amplified by coordination failures between interconnected systems, and that resilience only emerges when proactive information sharing is activated by strong internal organisational readiness. It introduces the idea of "synergy dependency" — external relational governance is hierarchically contingent on internal organisational controls — and reframes points of penetration as dynamic transmission mechanisms that convert a localised digital breach into systemic operational paralysis. In other words, a breach at one vendor or subsystem can propagate along the chain as a lifecycle of entry, transmission and interruption.4
Interpretation: For customers, the practical implication is that the retailer they trust may be compromised through a supplier, contractor or shared system rather than through its own storefront. The study's recommended responses — secure architecture, cross-organisational threat intelligence sharing and supplier-support programmes — are aimed at organisations, not consumers, and are presented as analytical and practical guidance rather than tested interventions with measured effects.4
04
Detection, notification and limits of prevention
AI summary:Prevention reduces but cannot remove breach risk, and many breaches are never detected, so published totals understate the real scale.
Evidence-backed: Prevention efforts can reduce the risk of a breach but cannot eliminate it, and a large number of breaches are never detected. When a breach does become known to the company holding the data, post-breach efforts commonly include containing it, investigating its scope and cause, and notifying affected people as required by law in many jurisdictions. Law enforcement may investigate, though the hackers responsible are rarely caught.1
Your turn
Have your say
See where others stand. Join free to add your perspective. One answer per account.
How do you feel about this?
No votes yetQuick questions from connected pages
Before you go
What to remember
Try to recall each hidden figure before you reveal it. Remembering, not rereading, is what makes it stick.
Retailer breaches most often start with hacking that exploits software vulnerabilities, followed by social engineering such as phishing and insider disclosure; in one global survey hacking was of reported attacks, with phishing and malware at 7% each.
The data taken is personal information — contact details, account credentials and payment data — and it is often sold on the dark web.
Supply-chain weaknesses can turn a localised breach into systemic disruption, because interconnected systems transmit the compromise along the chain.
Your reading
0 of 4 chaptersThis answer keeps changing
When new evidence or a better source comes in, this page is updated (it's on version 2, last changed 46 minutes ago). Follow it to be told when that happens.
Ask this Sylo
Still wondering about something?
Answers come only from this page's reviewed material, with citations, and say plainly when the page doesn't cover it yet.
Behind this page
Who's adding to it, where it comes from, how it changed and what would make it better. Always open to everyone.
Discussion
Sources
Numbers match the citations in the article. A working link isn't proof that a page supports a claim; check the quoted passage and date.
- 1Data breach (Wikipedia)WikipediaPublished Oct 5, 2026Checked Oct 10, 2026
“A data breach, also known as data leakage, is "the unauthorized exposure, disclosure, or loss of personal information". Attackers have a variety of motives, from financial gain to political activism, political repression, and espionage. There are several technical root causes of data breaches, including accidental or intentional disclosure of information by insiders, loss or theft of unencrypted devices, hacking into a system by exploiting software vulnerabilities, and social engineering attacks such as phishing where insiders are tricked into disclosing information. Although prevention efforts can reduce the risk of a data breach, they cannot eliminate it. A large number of data breaches are never detected. If a breach becomes known to the company holding the data, post-breach efforts commonly include containing the breach, investigating its scope and cause, and notifications to people whose records were compromised, as required by law in many jurisdictions. Law enforcement agencies may investigate breaches, although the hackers responsible are rarely caught. Criminals often sell data obtained in breaches on the dark web.”
- 2A deeper look into cybersecurity issues in the wake of Covid-19: A survey.Journal of King Saud University. Computer and information sciences (Alawida et al.)Published Aug 11, 2022Checked Oct 10, 2026
“The data was generated between March 2020 and December 2021, from a global survey through online contact and responses, especially from different organizations and business executives. The result show differences in cyber-attack techniques; as hacking attacks was the most frequent with a record of 330 out of 895 attacks, accounting for 37%. Next was Spam emails attack with 13%; emails with 13%; followed by malicious domains with 9%. Mobile apps followed with 8%, Phishing was 7%, Malware 7%, Browsing apps with 6%, DDoS has 6%, Website apps with 6%, and MSMM with 6%. BEC frequency was 4%, Ransomware with 2%, Botnet scored 2% and APT recorded 1%. The study recommends that it will continue to be necessary for governments and organizations to be resilient and innovative in cybersecurity decisions to overcome the current and future effects of the pandemic or similar crisis, which could be long-lasting. Hence, this study's findings will guide the creation, development, and implementation of more secure systems to safeguard people from cyber-attacks.”
- 3Asos hackers took more personal details than first revealed, BBC findsBBC NewsPublished Oct 8, 2026Checked Oct 10, 2026
“Retailer issues update after BBC contacted by cyber criminals who said this week's breach went beyond "basic contact details"”
- 4Cyberattacks in supply chains: A multi-case study.PloS one (Zhang et al.)Published May 22, 2026Checked Oct 10, 2026
“The scale of disruption is systematically amplified by inter-system coordination failures, while resilience emerges only when proactive information sharing is activated by strong internal organizational readiness. We introduce the concept of synergy dependency, demonstrating that external relational governance is hierarchically contingent on internal organizational controls, and reconceptualize Points of Penetration (PoPs) as dynamic transmission mechanisms that convert localized digital breaches into systemic operational paralysis. This research offers empirically grounded insights that adapt the SCCSS framework from a classificatory tool into a process-oriented model capable of explaining how cyber risk propagates as a lifecycle of entry, transmission, and interruption. The findings contribute analytical interpretations to supply chain governance theory by showing that cyber resilience is conditionally interdependent across subsystems. Practically, the study offers actionable guidance for implementing secure architecture, cross-organizational threat intelligence sharing, and supplier-support programs to strengthen the resilience of complex global supply chain ecosystems.”
- 5List of data breaches (Wikipedia)WikipediaPublished Sep 29, 2026Checked Oct 10, 2026
“This is a non-exhaustive list of reports about data breaches, using data compiled from am news articles. The list includes those involving the theft or compromise of 30,000 or more records, although many smaller breaches occur continually. Note that other sources compile more complete lists. Breaches of large organizations where the number of records is still unknown are also listed. In addition, the various methods used in the breaches are listed, with hacking being the most common. As a result of data breaches, it is estimated that in first half of 2018 alone, about 4.5 billion records were exposed. In 2019, a collection of 2.7 billion identity records, consisting of 774 million unique email addresses and 21 million unique passwords, was posted on the web for sale. In January 2024, a data breach dubbed the "mother of all breaches" was uncovered. Over 26 billion records, including some from Twitter, Adobe, Canva, LinkedIn, and Dropbox, were found in the database. No organization immediately claimed responsibility.”
How it changed
Published 1 time since Oct 10, 2026.
- Version 2Oct 10, 2026Live now
AI-prepared Starting Map from live research.
- First published version.
Help improve it
The brief is open about what's uncertain. These are the specific gaps that new material would fill.
“Why third parties and supply chains amplify the damage” rests on one independent source
A second, independent source that confirms or challenges it would make this part more reliable.
Open questions
How do attack-type frequencies differ for retailers specifically, rather than for organisations in general?
No answers yet
Which breach paths most often expose payment data versus contact details versus account credentials?
No answers yet
What was the confirmed scope of the Asos breach, and did it go beyond basic contact details as criminals claimed?
No answers yet
How often do third-party or vendor compromises, rather than direct attacks, cause retail customer-data breaches?
No answers yet
Around this topic
Sylos connect: narrower topics report up to broader ones, so what's learned in one place shows up where it matters.