Cybercriminals target e-commerce sites over holiday season

By Joanna England
Online shopping portals are being flooded with millions of ‘bad bots’ over the festive shopping season, experts warn...

Christmas online shopping is under attack from cybercriminals who are using ‘bad bot personas’ that are exploiting vulnerabilities in thousands of e-commerce sites.

According to Barracuda Networks, an email and cloud security company headquartered in California, widespread distributed denial of service (DDoS) attacks are being run from thousands of distinct IP addresses, making fraudulent purchases and exploiting vulnerabilities on online retail portals.

Barracuda networks revealed the breaches in their most recent analysis report Threat Spotlight, which highlighted the dangers facing vendors and shoppers over the Christmas season. 

The opportunities for cybercrime have increased exponentially following the global pandemic that has seen millions of retail outlets globally focus heavily on their online sales to survive. 

Christmas is the biggest shopping season in the UK and due to the tier system, most retail activity will be almost entirely online this year. The Barracuda Advanced Bot Protection solution ran a test web application, and observed that it had been targeted by over 90 million bad bot personas from over 340,000 distinct IP addresses, in just a few weeks.

Bad bot numbers

The data gathered by Barracuda researchers indicates 72% of bad bot traffic belonged to unspecified malicious users, 5% belonged to HeadlessChrome personas, and there was an increase in yerbasoftware and M12bot personas.

The researchers also observed that UK bot activity peaks mid-morning and doesn't fall off until closer to 5pm, which suggests that the cybercriminals (aka 'bot herders') follow a regular working day.

Brett Wolmarans, Director of Application Security Engineering for Barracuda Networks, said, "The holiday shopping season this year will be like no other. E-Commerce teams must ensure they carry out the necessary precautions to safeguard their applications against bad bots.

He added, “This includes installing a web application firewall, or ‘WAF-as-a-Service solution’, and making sure it is properly configured. Teams must also ensure application security solutions include anti-bot protection so they can effectively detect advanced automated attacks, and ‘credential stuffing protection’ should be enabled to prevent account takeover.”

Share

Featured Articles

Roxer Supports Refurbished Devices with Waterproof Testing

Roxer’s innovative Smartrox water resistance testing solution supports durability of new and refurbished smartphones, tablets and smartwatches

MWC24: Harnessing AI to Modernise Telcos with Tech Mahindra

We spoke with Tech Mahindra’s Manish Mangal at MWC Barcelona 2024 about how AI can transform telco network operations and facilitate greater innovation

Xsolla Unveils Web Shop 2.0 for Direct-to-Consumer Sales

Web Shops are white label digital stores where players purchase in-game items, currencies and top up accounts, all from the developers branded website

MWC24: Mimik Hybrid Edge Cloud Drives Cognitive Internet Era

Technology & AI

AMD: Expanding Telco Partnerships and Advancing 5G and 6G

5G & IOT

MWC24: Expect Gen AI Progress, Cloud, Edge & Sustainability

5G & IOT