Retailers are facing sustained cyber pressure as attackers target high-value customer and payment data, and consumer trust is increasingly sensitive to breach history and perceived security posture. A SOTI survey cited by Dark Reading found 88% of consumers “think twice” before shopping with a retailer that has experienced a cyberattack, and 22% would avoid a retailer altogether after a breach; others report changing behavior by avoiding a merchant’s website/social channels or withholding personal information. The article notes ransomware activity has been particularly active against UK retailers and points to ongoing global risk to customer data, with Nike mentioned as a potential recent victim.
Separately, ransomware operators are escalating coercion beyond data theft and encryption into more aggressive extortion, including threats of physical harm to executives, according to Semperis research cited in Dark Reading. The same commentary highlights that while Chainalysis estimated ransomware payments fell to $814M in 2024 (down 35% from 2023), groups are adapting by intensifying pressure on victims who are more likely to pay; it recommends resilience-focused controls such as rapid patching, user education, and multi-factor authentication. A TechTarget statistics roundup provides broader context on rising cyber risk (e.g., growth in disclosed vulnerabilities and supply-chain attack impact projections) but does not report on the same specific retail-consumer trust dynamic or the “violent ransomware” trend as a discrete event.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Semperis research reported that executive physical-harm threats appeared in roughly two-fifths of ransomware incidents it studied, reflecting an escalation in coercive tactics beyond data encryption and theft.
A SOTI report found that 88% of consumers think twice before shopping at a retailer that has suffered a cyberattack, and 22% would avoid that retailer altogether after a breach.
The article cites Nike as a possible recent victim in the retail sector, indicating continued targeting of major consumer brands.
The retail-focused reporting says ransomware attacks increased against UK retailers last year, underscoring the sector's growing exposure to extortion campaigns.
Chainalysis estimated that ransomware payments dropped to $814 million in 2024, a 35% decline from 2023. The reporting suggests attackers increasingly concentrated on victims still willing to pay.
Chainalysis estimated that ransomware payments totaled about $1.3 billion in 2023, establishing a high-water mark used for later year-over-year comparisons.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.