Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireRetail/Restaurants/Convenience

Holiday Mobile Threats Quadrupled in 2024 — What’s Expected This Year?

By Jordyn Alger, Managing Editor
Rendered shopping cart with boxes
Shutter Speed via Unsplash
November 14, 2025

“Where there’s money and momentum online, cybercriminals invariably follow — Black Friday and Cyber Monday deliver both in abundance,” says Anne Cutler, Cybersecurity Evangelist at Keeper Security. 

The closer the holidays, the greater the threats — according to a report from Zimperium zLabs, mobile phishing (mishing) and malware attacks quadrupled during 2024’s holiday season. With cyber threats only growing in sophistication and speed, it’s likely that retailers and shoppers alike will be facing another increase in attacks and scams this year. 

“This year we’re guaranteed to see ever more sophisticated scams, primarily fueled by artificial intelligence, whether that be convincingly forged order confirmations, spoofed retailer sites, and even AI-generated customer service messages designed to steal login details or payment information,” Cutler asserts. “Cybercriminals’ tactics are quickly evolving, but the target ultimately remains the same: your personal information.” 

This year, retailers have already been the focus of several major cyberattacks, so it stands to reason that threat actors may resume these targeted attacks as the holidays approach. The consequences of a successful attack could include data loss, financial repercussions, reputational damage and more. 

Chief Technology Officer at Sectigo Nick France elaborates, “From a business standpoint, the stakes are extremely high during Black Friday and Cyber Monday. This short window represents a critical revenue opportunity, and any website security hiccup — like an expired or misconfigured certificate causing browser warnings — can result in thousands of dollars in lost sales as shoppers quickly abandon sites that seem untrustworthy.” 

Why Are Holiday Scams So Prevalent? 

Mr. Mika Aalto, Co-Founder and CEO at Hoxhunt, explains, “Holiday scams continue to exist because they’re extremely successful. Cybersecurity leaders should take steps to bulk up defenses during the holiday season, when there is heightened email activity and emotions that cyber criminals can manipulate. Many employees use the same mobile devices for work as they do for personal use, therefore, opening a malicious link in a seemingly personal message could have disastrous consequences for the company.

“The holidays contain more travel and gift-buying activity, along with heightened emotions, so there are a lot more psychological buttons available to cyber criminals during this season of giving. Package delivery-themed phishing campaigns are common, and we see a number of spoofed sites which lead to credential harvesters. Travel-themed phishing campaigns might alert a victim that their flight has been canceled, so in a panic, someone might click something they otherwise wouldn’t and download malware that could compromise your system.” 

According to the report from Zimperium zLabs, more than 120,000 fraudulent retail apps were identified in 2025. Among these fake apps, 65% impersonated legitimate brands. 

Ms. Nivedita Murthy, Senior Staff Consultant at Black Duck, comments, “The online shopping experience has changed in recent years, and many users are now relying on the quick-click shopping experience on their mobile device. Users often also look out for the best deal, monitoring and tracking prices before they purchase, and Black Friday sales happen to be just the right time for many to make their move. With the number of users searching for sites that offer great deals they are also prime targets for scammers. Users are more likely to download an unknown app knowing they will get a good deal which makes mishing very common. App stores tend not to verify the authenticity or security of mobile applications due to the sheer volume of applications being hosted. There might be a base-level automated check, but malicious apps cannot be tested using automated scans.” 

Holiday Shopping in 2025: Evolving Technologies, Evolving Threats

The introduction of agentic AI into the retail space has come with beneficial developments as well as new risks and exposures. As some retailers have struggled to secure against the wave of cyberattacks that hit the sector this year, the introduction of agentic AI could leave an organization even more vulnerable than before if it is not prepared to provide proper protections. 

Will Glazier, Head of CQ Prime Threat Research Team at Cequence Security, states, “Many retailers are looking to see how ‘agentic commerce’ will truly look in the burgeoning era of AI. As we humans begin to let agents shop on our behalf, it will leave retailers one step removed from their human customers. The applications and agentic frameworks humans will delegate their shopping experience to will be vulnerable to the same type of spoofing that we see currently where malicious actors impersonate trusted brands or applications.” 

While impossible to say for certain, it’s not outside the realm of possibility that a wave of holiday attacks will target the retail space yet again. As the world of online shopping grows more and more mobile, enterprises and consumers alike should be on the lookout for phishing, social engineering, or other scams. 

France concludes, “Ultimately, security is a shared responsibility. Consumers can benefit by staying vigilant and shopping wisely, while businesses must maintain their security posture to promote trust and confidence. Together, these efforts help create a safer online shopping experience during the holiday season and beyond.” 

KEYWORDS: holiday season holiday shopping retail cyber security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Digital, tablet and hands

The 2025 Annual Guarding Report: Unrest Inspires Upgrades in Training, Technology

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Code

Security Leaders Discuss the Marquis Data Breach

Digital human mind

Should Organizations Block AI Browsers? Security Leaders Discuss

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

January 14, 2026

Is Your Organization Prepared to Navigate Interconnected Threats in 2026?

The 2026 threat environment will be louder, faster, and more interconnected. The most pressing risks, from global political volatility to emerging tech disruptions, will challenge organizations to act amid ambiguity and protect credibility in an era of accelerating uncertainty.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Person looking at flight schedules

    REAL ID Enforcement in Effect — What Does This Mean for Biometric Data Security?

    See More
  • Padlock opened with computer keys

    630M Passwords Stolen, FBI Reveals: What This Says About Credential Value

    See More
  • People using mobile phones

    Mobile phishing threats are evolving, according to new research

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing