Cybercriminals are increasingly exploiting the holiday shopping season to launch account takeover (ATO) attacks against online retailers and their customers. The surge in online traffic during peak shopping periods creates opportunities for attackers to blend in with legitimate users, using automated tools and AI-driven bots to compromise accounts and access sensitive information such as payment details, loyalty points, and personal data. According to industry reports, ATO attacks have risen sharply, with a 40% increase in 2024 and over 50% since 2022, driven by the widespread availability of stolen credentials and the expanding digital footprint of businesses.
The FBI has issued warnings about the growing prevalence of ATO fraud schemes, highlighting the sophistication of attackers who employ credential stuffing, credential cracking, and brute force techniques to gain unauthorized access. These attacks often go undetected until significant financial losses and customer frustration occur. Retailers are urged to strengthen authentication processes and monitor for suspicious login activity, especially during high-traffic periods, to mitigate the risk of account compromise and fraud.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Thales, via an Imperva blog post, outlined how its security measures help defend against account takeover during the peak holiday shopping season. The post reflects an industry response focused on mitigating elevated seasonal ATO risk.
The FBI issued a warning about a rise in account takeover fraud schemes, highlighting increased risk to consumers and organizations. The alert prompted security vendors and practitioners to emphasize defensive measures against ATO activity.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.