Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireRetail/Restaurants/Convenience

Holiday Mobile Threats Quadrupled in 2024 — What’s Expected This Year?

By Jordyn Alger, Managing Editor
Rendered shopping cart with boxes
Shutter Speed via Unsplash
November 14, 2025

“Where there’s money and momentum online, cybercriminals invariably follow — Black Friday and Cyber Monday deliver both in abundance,” says Anne Cutler, Cybersecurity Evangelist at Keeper Security. 

The closer the holidays, the greater the threats — according to a report from Zimperium zLabs, mobile phishing (mishing) and malware attacks quadrupled during 2024’s holiday season. With cyber threats only growing in sophistication and speed, it’s likely that retailers and shoppers alike will be facing another increase in attacks and scams this year. 

“This year we’re guaranteed to see ever more sophisticated scams, primarily fueled by artificial intelligence, whether that be convincingly forged order confirmations, spoofed retailer sites, and even AI-generated customer service messages designed to steal login details or payment information,” Cutler asserts. “Cybercriminals’ tactics are quickly evolving, but the target ultimately remains the same: your personal information.” 

This year, retailers have already been the focus of several major cyberattacks, so it stands to reason that threat actors may resume these targeted attacks as the holidays approach. The consequences of a successful attack could include data loss, financial repercussions, reputational damage and more. 

Chief Technology Officer at Sectigo Nick France elaborates, “From a business standpoint, the stakes are extremely high during Black Friday and Cyber Monday. This short window represents a critical revenue opportunity, and any website security hiccup — like an expired or misconfigured certificate causing browser warnings — can result in thousands of dollars in lost sales as shoppers quickly abandon sites that seem untrustworthy.” 

Why Are Holiday Scams So Prevalent? 

Mr. Mika Aalto, Co-Founder and CEO at Hoxhunt, explains, “Holiday scams continue to exist because they’re extremely successful. Cybersecurity leaders should take steps to bulk up defenses during the holiday season, when there is heightened email activity and emotions that cyber criminals can manipulate. Many employees use the same mobile devices for work as they do for personal use, therefore, opening a malicious link in a seemingly personal message could have disastrous consequences for the company.

“The holidays contain more travel and gift-buying activity, along with heightened emotions, so there are a lot more psychological buttons available to cyber criminals during this season of giving. Package delivery-themed phishing campaigns are common, and we see a number of spoofed sites which lead to credential harvesters. Travel-themed phishing campaigns might alert a victim that their flight has been canceled, so in a panic, someone might click something they otherwise wouldn’t and download malware that could compromise your system.” 

According to the report from Zimperium zLabs, more than 120,000 fraudulent retail apps were identified in 2025. Among these fake apps, 65% impersonated legitimate brands. 

Ms. Nivedita Murthy, Senior Staff Consultant at Black Duck, comments, “The online shopping experience has changed in recent years, and many users are now relying on the quick-click shopping experience on their mobile device. Users often also look out for the best deal, monitoring and tracking prices before they purchase, and Black Friday sales happen to be just the right time for many to make their move. With the number of users searching for sites that offer great deals they are also prime targets for scammers. Users are more likely to download an unknown app knowing they will get a good deal which makes mishing very common. App stores tend not to verify the authenticity or security of mobile applications due to the sheer volume of applications being hosted. There might be a base-level automated check, but malicious apps cannot be tested using automated scans.” 

Holiday Shopping in 2025: Evolving Technologies, Evolving Threats

The introduction of agentic AI into the retail space has come with beneficial developments as well as new risks and exposures. As some retailers have struggled to secure against the wave of cyberattacks that hit the sector this year, the introduction of agentic AI could leave an organization even more vulnerable than before if it is not prepared to provide proper protections. 

Will Glazier, Head of CQ Prime Threat Research Team at Cequence Security, states, “Many retailers are looking to see how ‘agentic commerce’ will truly look in the burgeoning era of AI. As we humans begin to let agents shop on our behalf, it will leave retailers one step removed from their human customers. The applications and agentic frameworks humans will delegate their shopping experience to will be vulnerable to the same type of spoofing that we see currently where malicious actors impersonate trusted brands or applications.” 

While impossible to say for certain, it’s not outside the realm of possibility that a wave of holiday attacks will target the retail space yet again. As the world of online shopping grows more and more mobile, enterprises and consumers alike should be on the lookout for phishing, social engineering, or other scams. 

France concludes, “Ultimately, security is a shared responsibility. Consumers can benefit by staying vigilant and shopping wisely, while businesses must maintain their security posture to promote trust and confidence. Together, these efforts help create a safer online shopping experience during the holiday season and beyond.” 

KEYWORDS: holiday season holiday shopping retail cyber security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

Popular Stories

Pixelated brain

Critical Thinking Erosion: A Hidden Threat to Security Career Resilience

Red block among white blocks

Plenty of Associations, But Not Enough Association

Person on iPhone

The Olympics Are Going Mobile — Your Security Strategy Has to Follow

Phone showing hearts and flirty emojis

Valentine’s Day 2026: Inside the Industrial-Scale Romance Scam Economy

Red and blue pawns with thought bubbles

Implementing Meaningful De-Escalation Training in Your Security Program

SEC 2026 Benchmark Banner

Events

April 8, 2026

The Future of Executive Protection: Layering Technology, Intelligence, and Response

Digital threats to executives and other high-profile employees are evolving faster than most corporate protection programs. Learn why modern executive protection programs require data-driven, intelligence-led strategies to keep pace with the magnitude of today’s threats.

April 15, 2026

How AI is Closing the Decision Gap in Leading GSOCs

Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders

Related Articles

  • Person looking at flight schedules

    REAL ID Enforcement in Effect — What Does This Mean for Biometric Data Security?

    See More
  • Money tied up

    How AI Could Impact Tax Season Security This Year

    See More
  • Padlock opened with computer keys

    630M Passwords Stolen, FBI Reveals: What This Says About Credential Value

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing