We review vendors based on rigorous testing and research but also take into account your feedback and our affiliate commission with providers. Some providers are owned by our parent company.
Learn more
vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.
Advertising Disclosure

vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.

Report: 97% of Top US Retailers Have Experienced a Breach

Report: 97% of Top US Retailers Have Experienced a Breach
Hendrik Human Published on 28th November 2024 Cybersecurity Researcher

A SecurityScorecard report released on November 20, 2024, shows that 97% of the top 100 US retailers experienced third-party data breaches in the past year, underscoring critical vulnerabilities in the retail sector ahead of the holiday shopping rush.

The report analyzed over 14,000 domains linked to the top 100 US retailers, with a focus on the importance of strengthening security as cyber threats escalate during the busiest shopping season of the year.

With the vast amount of sensitive customer data retailers handle — such as payment information and personal identifiers —third-party breaches pose significant risks. Cybercriminals target this data for identity theft, fraud, and other malicious activities.

Ryan Sherstobitoff, Senior Vice President of Threat Research and Intelligence at SecurityScorecard, highlighted the urgency of addressing these vulnerabilities:

“In the hustle to keep up with holiday sales, retailers must not let their guard down. Cybercriminals are lurking, ready to exploit any distraction. A single data breach could devastate a company’s bottom line and irreparably damage consumer trust. With all eyes on retailers in the coming month, they can’t afford to stand still. It’s imperative to prioritize security — not just for themselves, but for their vendors as well.”

Here are some of the key findings from the report:

  • 97% of retailers faced third-party breaches, while 97% also experienced fourth-party breaches (from only 2% of vendors).
  • All of the top 20 US retailers reported third-party breaches.
  • Only 12 retailers were directly compromised.
  • Retailers with a “B” security rating are nearly three times more likely to experience breaches compared to those with an “A” rating. However, only 20% of retailers have an “A” rating.

Based on its findings, SecurityScorecard also released a number of recommendations for retailers to help mitigate the risk of future cyber incidents:

  • Monitor external attack surfaces with automated scanning tools
  • Identify and mitigate single points of failure across supply chains
  • Ensure external technologies supporting e-commerce platforms are secure

Considering a number of high-profile retail cyberattacks this year, these findings are not too surprising. Hot Topic recently fell victim to a cyberattack that compromised the data of 56 million consumers. As hackers get more creative, data leaks are not the only cyber threat the industry faces. Cybercriminals were recently found to have hacked thousands of online stores to post fake product listings that scammed the user, for example.

About the Author

Hendrik is a writer at vpnMentor, specializing in VPN comparisons and user guides. With 5+ years of experience as a tech and cybersecurity writer, plus a background in corporate IT, he brings a variety of perspectives to test VPN services and analyze how they address the needs of different users.

Please, comment on how to improve this article. Your feedback matters!

Leave a comment

Sorry, links are not allowed in this field!

Name should contain at least 3 letters

The field content should not exceed 80 letters

Sorry, links are not allowed in this field!

Please enter a valid email address