Retailers experienced a significant increase in both legitimate and malicious online activity during the 2025 holiday shopping season, with Black Friday setting new records for consumer spending and cyberattacks. Automated bot attacks surged by 50%, targeting authentication, inventory, and transaction workflows, as attackers sought to exploit the extended peak shopping period and blend in with high consumer traffic. This rise in malicious activity underscores the expanding window of exposure for retailers and the need for robust defenses against account takeover attempts and automated abuse.
At the same time, consumers and enterprises faced a wave of holiday-themed cyber scams, including business impersonation, phishing, fraudulent invoices, and social engineering attacks leveraging AI and cryptocurrency. Threat actors exploited the seasonal rush, increased online shopping, and distracted staff to launch scams such as fake e-cards, bogus charity requests, and payment fraud. Security experts and government advisories highlighted the importance of heightened vigilance, secure device usage, and careful validation of transactions to mitigate risks during the holiday period.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Security guidance published during the holiday season warned that distracted staff, remote work, public Wi-Fi, BYOD, phishing, and business email compromise-style fraud increase enterprise risk. Recommended mitigations included MFA, least-privilege access, patching, monitoring, employee training, vendor verification, network segmentation, and tested incident response and backup plans.
The U.S. Department of the Treasury issued an advisory warning that holiday-season scams are surging, with criminals exploiting online shopping, charitable giving, and gift card purchases. The advisory highlighted business impersonation, fake charities, and gift card draining, and noted the use of AI voice cloning, deepfakes, and cryptocurrency to make fraud more convincing and harder to trace.
During Black Friday 2025, U.S. online retail spending reached a record $11.8 billion and retail web traffic rose 37% through the weekend. At the same time, bot attacks against retailers increased 50%, targeting authentication, inventory, and transaction endpoints, especially in the US, UK, and Australia.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
imperva.com
Open sourcezdnet.com
Open sourcearcticwolf.com
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.