SyloSpace

How do cyberattacks on retailers compromise personal data?

Retailer breaches mostly start with hacking, phishing or insider leaks, exposing personal data that is often sold on the dark web.

Updated 46 minutes ago5 min readVersion 2
CommentsFollow

Covers: This page explains the main ways attackers breach retailers — such as point-of-sale malware, e-commerce skimming, credential stuffing, ransomware and third-party vendor compromise — and how each path exposes payment, contact and account data. It does not cover individual incident timelines or give legal or remediation advice for a specific breach.

Also answers: How do hackers steal customer data from retailers? · How do retail data breaches happen? · What causes retailer cyberattacks and data theft? · How is personal data compromised in retail cyberattacks?

A person holding a credit card in front of a computer
Photo: SumUp

The short answer

Evidence-backed AI-prepared starting map

Retailer breaches compromise customer data mainly through hacking that exploits software vulnerabilities, social engineering such as phishing that tricks insiders into disclosing information, and accidental or intentional disclosure by insiders, along with loss or theft of unencrypted devices. Across a large global survey of organisations, hacking was the most frequent attack type reported (330 of 895 attacks, 37%), followed by spam email (13%), malicious domains (9%), mobile apps (8%), phishing (7%) and malware (7%); ransomware (2%), botnets (2%) and advanced persistent threats (1%) were far less common. The data exposed is personal information — contact details, account credentials and payment data — and criminals often sell it on the dark web. Breaches are frequently never detected, and prevention can reduce but not eliminate the risk.123

What this rests on5 independent sources
  • Evidence 16
  • Interpretation 3

Did this answer your question?

Be the first to vote
Your perspective belongs in the picture.Join free to vote

In brief

  1. Retailer breaches most often start with hacking that exploits software vulnerabilities, followed by social engineering such as phishing and insider disclosure; in one global survey hacking was 37% of reported attacks, with phishing and malware at 7% each.12

    Evidence-backed
    Join free to vote
  2. The data taken is personal information — contact details, account credentials and payment data — and it is often sold on the dark web.1

    Evidence-backed
    Join free to vote
  3. Supply-chain weaknesses can turn a localised breach into systemic disruption, because interconnected systems transmit the compromise along the chain.4

    Evidence-backed
    Join free to vote
  4. Prevention reduces but cannot eliminate breach risk, and many breaches are never detected — so published totals understate the real scale.1

    Evidence-backed
    Join free to vote
  5. Reported scope can change: Asos first described its breach as basic contact details, then updated after criminals told the BBC it went further — a claim that remains unconfirmed.3

    Evidence-backed
    Join free to vote

At a glance

The picture in numbers

Live · updated just now

Cross-industry total, not retail-specific

4.5 billion records

Records exposed in the first half of 201851
Cross-industry total, not retail-specific

26 billion records

Records in the January 2024 "mother of all breaches" database51

The evidence behind it

5 sources
  • Other studies and data2
  • Background3

Published in 2022 and 2026

Sources on this page by kind and year
SourceKindYear
Asos hackers took more personal details than first revealed, BBC findsBackground2026
Cyberattacks in supply chains: A multi-case study.Other studies and data2026
Data breach (Wikipedia)BackgroundUnknown
List of data breaches (Wikipedia)BackgroundUnknown
A deeper look into cybersecurity issues in the wake of Covid-19: A survey.Other studies and data2022

The community around it

No one has added to this page yet. Firsthand experience, a newer study or a different reading of the numbers would show up here, credited to you.

What it means for you

Which fits you?

Pick the situation closest to yours. Each answer says what it rests on.

If you want to understand the most likely way your data would be taken in a retail breach

focus on hacking of software vulnerabilities and phishing-style social engineering, which dominate reported attack types, rather than on rarer techniques like ransomware or advanced persistent threats.21

Evidence-backed

If you are assessing how much a retailer's breach could affect you

consider that exposed data may include contact details, account credentials and payment data, and that the retailer's initial description of scope can later expand, as in the Asos case.31

Evidence-backed

If you assume a retailer's own systems are the only weak point

account for third-party and supply-chain exposure, since coordination failures between interconnected systems can amplify a localised breach into wider disruption.4

Evidence-backed

If you are reading published breach totals

treat them as a floor, because many breaches are never detected and the available lists are non-exhaustive.15

Evidence-backed

If you are a retailer or supplier deciding where to invest

the supply-chain research points to secure architecture, cross-organisational threat intelligence sharing and supplier-support programmes, though these are presented as guidance rather than tested interventions.4

Evidence-backed

The full story · 4 chapters

01

How attackers get in

AI summary:Hacking software vulnerabilities is the most reported attack route, with phishing, insider disclosure and device loss also common.

Evidence-backed

Evidence-backed: The most common route is hacking into a system by exploiting software vulnerabilities. In a global survey of organisations, hacking was the single most frequent attack type, accounting for 330 of 895 reported attacks (37%). Social engineering — phishing in particular — is the other main human-facing route, where insiders are tricked into disclosing information; phishing accounted for 7% and malware 7% in the same survey, with spam email at 13% and malicious domains at 9%. Breaches can also stem from accidental or intentional disclosure by insiders and from loss or theft of unencrypted devices.12

Interpretation

Interpretation: The survey's ranking matters for expectations: ransomware (2%), botnets (2%) and advanced persistent threats (1%) were reported far less often than hacking, spam email and phishing. That does not mean those techniques are harmless — a single successful ransomware or supply-chain attack can be highly disruptive — but it does mean the everyday volume of retail breaches is dominated by more mundane entry methods.2

Readers' pollNo answers yet

How concerned are you about your personal data being compromised in a retailer cyberattack?

How concerned are you about your personal data being compromised in a retailer cyberattack?
Your perspective belongs in the picture.Join free to vote

Your individual answer is private. Only totals are shown.

02

What customer data gets exposed

AI summary:Breaches expose contact details, account credentials and payment data, which is often sold on the dark web.

Evidence-backed

Evidence-backed: A data breach is the unauthorised exposure, disclosure or loss of personal information. In retail settings that means contact details, account credentials and payment data. The Asos case illustrates the pattern: the retailer initially described the breach as involving "basic contact details", then issued an update after the BBC was contacted by cyber criminals who said the breach went beyond that. The wider claim that more personal details were taken is reported but not confirmed by the retailer in the material available.13

Evidence-backed

Evidence-backed: Once taken, stolen data is commonly sold on the dark web. Aggregate figures give a sense of scale: about 4.5 billion records were exposed in the first half of 2018 alone; a 2019 collection of 2.7 billion identity records included 774 million unique email addresses and 21 million unique passwords; and a January 2024 database dubbed the "mother of all breaches" contained over 26 billion records, including data linked to Twitter, Adobe, Canva, LinkedIn and Dropbox. These are cross-industry totals, not retail-specific, and the lists are non-exhaustive.51

03

Why third parties and supply chains amplify the damage

AI summary:Interconnected systems can spread a breach from one supplier along the chain, turning a local incident into wider disruption.

Evidence-backed

Evidence-backed: A multi-case study of supply-chain cyberattacks argues that disruption is systematically amplified by coordination failures between interconnected systems, and that resilience only emerges when proactive information sharing is activated by strong internal organisational readiness. It introduces the idea of "synergy dependency" — external relational governance is hierarchically contingent on internal organisational controls — and reframes points of penetration as dynamic transmission mechanisms that convert a localised digital breach into systemic operational paralysis. In other words, a breach at one vendor or subsystem can propagate along the chain as a lifecycle of entry, transmission and interruption.4

Interpretation

Interpretation: For customers, the practical implication is that the retailer they trust may be compromised through a supplier, contractor or shared system rather than through its own storefront. The study's recommended responses — secure architecture, cross-organisational threat intelligence sharing and supplier-support programmes — are aimed at organisations, not consumers, and are presented as analytical and practical guidance rather than tested interventions with measured effects.4

04

Detection, notification and limits of prevention

AI summary:Prevention reduces but cannot remove breach risk, and many breaches are never detected, so published totals understate the real scale.

Evidence-backed

Evidence-backed: Prevention efforts can reduce the risk of a breach but cannot eliminate it, and a large number of breaches are never detected. When a breach does become known to the company holding the data, post-breach efforts commonly include containing it, investigating its scope and cause, and notifying affected people as required by law in many jurisdictions. Law enforcement may investigate, though the hackers responsible are rarely caught.1

Interpretation

Interpretation: This is why reported breach counts should be read as a floor rather than a full picture: undetected breaches, non-exhaustive lists and unknown record counts for large organisations all push the true total higher than any published figure.15

Your turn

Have your say

See where others stand. Join free to add your perspective. One answer per account.

How do you feel about this?

No votes yet
Your perspective belongs in the picture.Join free to vote

Quick questions from connected pages

Before you go

What to remember

Try to recall each hidden figure before you reveal it. Remembering, not rereading, is what makes it stick.

  1. Retailer breaches most often start with hacking that exploits software vulnerabilities, followed by social engineering such as phishing and insider disclosure; in one global survey hacking was of reported attacks, with phishing and malware at 7% each.

  2. The data taken is personal information — contact details, account credentials and payment data — and it is often sold on the dark web.

  3. Supply-chain weaknesses can turn a localised breach into systemic disruption, because interconnected systems transmit the compromise along the chain.

This answer keeps changing

When new evidence or a better source comes in, this page is updated (it's on version 2, last changed 46 minutes ago). Follow it to be told when that happens.

Up nextIndex funds vs. actively managed fundsDo actively managed funds beat low-cost index funds over the long run, and why?

Ask this Sylo

Still wondering about something?

Answers come only from this page's reviewed material, with citations, and say plainly when the page doesn't cover it yet.

Behind this page

Who's adding to it, where it comes from, how it changed and what would make it better. Always open to everyone.

Discussion

Nobody has added anything yet. If you have experience, evidence or a different view, you could be the first.

Sources

Numbers match the citations in the article. A working link isn't proof that a page supports a claim; check the quoted passage and date.

  1. 1
    Data breach (Wikipedia)
    WikipediaPublished Oct 5, 2026Checked Oct 10, 2026
    “A data breach, also known as data leakage, is "the unauthorized exposure, disclosure, or loss of personal information". Attackers have a variety of motives, from financial gain to political activism, political repression, and espionage. There are several technical root causes of data breaches, including accidental or intentional disclosure of information by insiders, loss or theft of unencrypted devices, hacking into a system by exploiting software vulnerabilities, and social engineering attacks such as phishing where insiders are tricked into disclosing information. Although prevention efforts can reduce the risk of a data breach, they cannot eliminate it. A large number of data breaches are never detected. If a breach becomes known to the company holding the data, post-breach efforts commonly include containing the breach, investigating its scope and cause, and notifications to people whose records were compromised, as required by law in many jurisdictions. Law enforcement agencies may investigate breaches, although the hackers responsible are rarely caught. Criminals often sell data obtained in breaches on the dark web.”
  2. 2
    A deeper look into cybersecurity issues in the wake of Covid-19: A survey.
    Journal of King Saud University. Computer and information sciences (Alawida et al.)Published Aug 11, 2022Checked Oct 10, 2026
    “The data was generated between March 2020 and December 2021, from a global survey through online contact and responses, especially from different organizations and business executives. The result show differences in cyber-attack techniques; as hacking attacks was the most frequent with a record of 330 out of 895 attacks, accounting for 37%. Next was Spam emails attack with 13%; emails with 13%; followed by malicious domains with 9%. Mobile apps followed with 8%, Phishing was 7%, Malware 7%, Browsing apps with 6%, DDoS has 6%, Website apps with 6%, and MSMM with 6%. BEC frequency was 4%, Ransomware with 2%, Botnet scored 2% and APT recorded 1%. The study recommends that it will continue to be necessary for governments and organizations to be resilient and innovative in cybersecurity decisions to overcome the current and future effects of the pandemic or similar crisis, which could be long-lasting. Hence, this study's findings will guide the creation, development, and implementation of more secure systems to safeguard people from cyber-attacks.”
  3. 3
    Asos hackers took more personal details than first revealed, BBC finds
    BBC NewsPublished Oct 8, 2026Checked Oct 10, 2026
    “Retailer issues update after BBC contacted by cyber criminals who said this week's breach went beyond "basic contact details"”
  4. 4
    Cyberattacks in supply chains: A multi-case study.
    PloS one (Zhang et al.)Published May 22, 2026Checked Oct 10, 2026
    “The scale of disruption is systematically amplified by inter-system coordination failures, while resilience emerges only when proactive information sharing is activated by strong internal organizational readiness. We introduce the concept of synergy dependency, demonstrating that external relational governance is hierarchically contingent on internal organizational controls, and reconceptualize Points of Penetration (PoPs) as dynamic transmission mechanisms that convert localized digital breaches into systemic operational paralysis. This research offers empirically grounded insights that adapt the SCCSS framework from a classificatory tool into a process-oriented model capable of explaining how cyber risk propagates as a lifecycle of entry, transmission, and interruption. The findings contribute analytical interpretations to supply chain governance theory by showing that cyber resilience is conditionally interdependent across subsystems. Practically, the study offers actionable guidance for implementing secure architecture, cross-organizational threat intelligence sharing, and supplier-support programs to strengthen the resilience of complex global supply chain ecosystems.”
  5. 5
    List of data breaches (Wikipedia)
    WikipediaPublished Sep 29, 2026Checked Oct 10, 2026
    “This is a non-exhaustive list of reports about data breaches, using data compiled from am news articles. The list includes those involving the theft or compromise of 30,000 or more records, although many smaller breaches occur continually. Note that other sources compile more complete lists. Breaches of large organizations where the number of records is still unknown are also listed. In addition, the various methods used in the breaches are listed, with hacking being the most common. As a result of data breaches, it is estimated that in first half of 2018 alone, about 4.5 billion records were exposed. In 2019, a collection of 2.7 billion identity records, consisting of 774 million unique email addresses and 21 million unique passwords, was posted on the web for sale. In January 2024, a data breach dubbed the "mother of all breaches" was uncovered. Over 26 billion records, including some from Twitter, Adobe, Canva, LinkedIn, and Dropbox, were found in the database. No organization immediately claimed responsibility.”

How it changed

Published 1 time since Oct 10, 2026.

  1. Version 2Oct 10, 2026Live now

    AI-prepared Starting Map from live research.

    • First published version.
Every version, side by side

Help improve it

The brief is open about what's uncertain. These are the specific gaps that new material would fill.

  • “Why third parties and supply chains amplify the damage” rests on one independent source

    A second, independent source that confirms or challenges it would make this part more reliable.

Open questions

  • How do attack-type frequencies differ for retailers specifically, rather than for organisations in general?

    No answers yet

  • Which breach paths most often expose payment data versus contact details versus account credentials?

    No answers yet

  • What was the confirmed scope of the Asos breach, and did it go beyond basic contact details as criminals claimed?

    No answers yet

  • How often do third-party or vendor compromises, rather than direct attacks, cause retail customer-data breaches?

    No answers yet

Around this topic

Sylos connect: narrower topics report up to broader ones, so what's learned in one place shows up where it matters.

Ask this Sylo

Answers only from “How do cyberattacks on retailers compromise personal data?”

Ask anything about this page. The AI reads only its reviewed brief, sources and contributions, cites what it used, and says when the page doesn't cover something.