In 2025, the retail and e-commerce sector continued to face intense pressure from cybercriminals. According to Kaspersky data, 14,41%* of users in the retail sectorIn 2025, the retail and e-commerce sector continued to face intense pressure from cybercriminals. According to Kaspersky data, 14,41%* of users in the retail sector

AI-driven shopping and privacy: what the retail and e-commerce sector should expect in 2026

For feedback or concerns regarding this content, please contact us at [email protected]
Press Release: Ai-Driven Shopping And Privacy: What The Retail And E-Commerce Sector Should Expect In 2026

In 2025, the retail and e-commerce sector continued to face intense pressure from cybercriminals. According to Kaspersky data, 14,41%* of users in the retail sector encountered web-based threats, while 22,20% were affected by on-device attacks.

Ransomware remains a serious concern for the industry. Last year, 8,25% of retail and e-commerce companies experienced ransomware incidents, and the number of unique B2B users in the sector affected by ransomware detections rose by 152% compared to 2023, signaling a sharp escalation in targeted attacks.

Phishing also continues to be a major threat vector. Kaspersky identified 6.7 million phishing attacks targeting users of online stores, delivery services, and payment systems in 2025. More than half of these attacks (50,58%) were aimed specifically at online stores, underscoring cybercriminals’ focus on e-commerce platforms as high-value targets for fraud and data theft.

A look at 2025 cybersecurity for retail & e-commerce: trends and what happened

A stealer with a taste for pizza delivery. Shopping and food ordering via mobile apps are routine user behaviors. However, 2025 demonstrated that even downloading a seemingly legitimate app from an official app store does not guarantee safety, nor does it ensure that user data and financial credentials will not be compromised.

Ransomware detections in the B2B sector increased due to a single dominant actor. The number of unique users in the Retail & E-commerce sector who encountered ransomware detections increased by 152% in 2025 compared to 2023 (Nov 2024 – Oct 2025 vs. Nov 2022 – Oct 2023). The most significant growth occurred during the 2024-2025 period and is largely attributable to the rapid spread of the Trojan-Ransom.Win32.Dcryptor family, which became highly prevalent across the retail and e-commerce sector in some of the analyzed markets. This malware is a trojanized ransomware variant that leverages the legitimate DiskCryptor utility to encrypt disk partitions on victim systems.

Phishing activity in the online retail segment stood out. Despite being a long-established attack technique, phishing remains highly prevalent in the context of online purchasing. From November 2024 through to October 2025, Kaspersky products blocked 6,651,955 attempts to access phishing links targeting users of online stores, payment systems, and delivery services. Of these attempts, 50.58% targeted online shoppers, 27.3% impersonated payment systems, and 22.12% targeted users of delivery companies.

Retail & E-commerce phishing attacks by category (November 2024 – October 2025)

Sales seasons continue to do the work for attackers. Seasonal peaks in online shopping consistently provide attackers with predictable opportunities to scale user-focused attacks. Periods of heightened promotional activity lower user vigilance and allow familiar phishing and spam scenarios to blend into legitimate marketing traffic, increasing their overall effectiveness. 

Predictions: what retail & e-commerce cybersecurity might face in 2026

Chatbots are likely to become a common product discovery tool across online marketplaces. Unlike traditional search, conversational interfaces encourage users to share more detailed, natural-language requests, revealing preferences, constraints, and contextual information. This shift expands the privacy attack surface, as platforms accumulate richer user profiles through chat interactions. As a result, chatbot logs may become as sensitive as transactional data, increasing the risks of over-collection, misuse, or exposure of personal information.

“Search itself is changing, including how people look for products online. In 2025, there was a gradual shift from simple keyword queries to more conversational and visual ways of finding what to buy. As these models rely on broader user input, careful handling of the data involved will remain an important consideration for maintaining user trust,” – comments Anna Larkina, Web data and privacy analysis expert at Kaspersky.

Changes in taxes and trade rules might be exploited in online fraud. Modifications in taxes, import duties, and cross-border trade rules are likely to be used as lures in phishing campaigns and fraudulent online stores, promoting unrealistically cheap offers or claims of avoided fees. As pricing and fee rules continue to evolve across markets, it may lower vigilance, increasing the effectiveness of such schemes, particularly against small and mid-sized retailers.

AI-powered shopping assistants are expected to increasingly operate outside retail platforms, embedding themselves into browsers, mobile apps, and third-party services. While designed to simplify navigation and price discovery, these tools shift data collection beyond the retailer’s perimeter, creating new and less visible privacy risks. To function effectively, external AI shopping agents require continuous access to user behavior, including browsing activity, search intent, location context and product interactions across multiple sites. This enables the aggregation of detailed behavioral profiles outside the direct control of both users and retail platforms, increasing the risks of over-collection, opaque data usage, and unintended exposure.

Image-based product search might become a new challenge in privacy risks. Previously, the main privacy concern around user images in e-commerce was limited to photos voluntarily shared in product reviews. However, image-based product search is expected to make photo uploads a routine part of the shopping experience across major retail platforms. While this feature improves product discovery, it also increases the risk of unintended exposure of personal data. User-submitted images may contain faces, home environments, or sensitive details, such as names, phone numbers, or addresses visible on shipping labels or packaging, making secure processing, data minimization, and limited retention critical requirements for retailers.

The full retail and e-commerce report is available by link.

Kaspersky experts recommend the following to keep safe:

  • Guard your privacy with smart tools. Be cautious about what you share and avoid uploading personal images or details in queries. Your interactions help build a profile used for ads and service improvements.
  • Verify senders and links. Don’t trust discounts or order notifications from emails or messages. Always double-check the sender’s address and manually type the store’s website URL into your browser instead of clicking on any links you receive.
  • Research the store before buying. If you’re shopping at a new or unfamiliar online store, take a moment to check its legitimacy: look for customer reviews, ensure the website address is spelled correctly, and confirm that the site pages look professional and polished.
  • Monitor your card transactions regularly. Fraudulent charges can slip through unnoticed. Make it a habit (e.g., once a week) to log into your online banking or mobile app to review all recent transactions. If you spot anything suspicious, block your card and contact your bank immediately.
  • Adopt a proactive security approach to protect against malware and data theft. Use reliable cybersecurity software like Kaspersky Premium to prevent infections and scan your device regularly. If you discover an infected app, remove it immediately and do not reinstall it until a confirmed, clean update is released. Complement this by managing sensitive data securely: avoid storing passwords or recovery phrases in your photo gallery or notes; instead, use a dedicated, trusted password software such as Kaspersky Password Manager.

For retail & e-commerce organizations we recommend:

  • Protect corporate infrastructure against a wide range of threats, including phishing and ransomware. Use solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and advanced response capabilities. If a company lacks cybersecurity workers, it can adopt managed security services such as Kaspersky Managed Detection and Response (MDR) and / or Incident Response that covers the entire incident management cycle – from threat identification to continuous protection and remediation.

*Figures in the press release are based on KSN Data, November 2024 through October 2025

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

This article was originally published as AI-driven shopping and privacy: what the retail and e-commerce sector should expect in 2026 on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Vitalik Buterin to Ethereum Developers: Build It Like It Has to Last Without You

Vitalik Buterin to Ethereum Developers: Build It Like It Has to Last Without You

Key Takeaways Vitalik Buterin wants Ethereum apps built to survive without developers, corporate servers, or trusted third parties Two major […] The post Vitalik
Share
Coindoo2026/03/07 15:49
Non-Opioid Painkillers Have Struggled–Cannabis Drugs Might Be The Solution

Non-Opioid Painkillers Have Struggled–Cannabis Drugs Might Be The Solution

The post Non-Opioid Painkillers Have Struggled–Cannabis Drugs Might Be The Solution appeared on BitcoinEthereumNews.com. In this week’s edition of InnovationRx, we look at possible pain treatments from cannabis, risks of new vaccine restrictions, virtual clinical trials at the Mayo Clinic, GSK’s $30 billion U.S. manufacturing commitment, and more. To get it in your inbox, subscribe here. Despite their addictive nature, opioids continue to be a major treatment for pain due to a lack of effective alternatives. In an effort to boost new drugs, the FDA released new guidelines for non-opioid painkillers last week. But making these drugs hasn’t been easy. Vertex Pharmaceuticals received FDA approval for its non-opioid Journavx in January, then abandoned a next generation drug after a failed clinical trial earlier this summer. Acadia similarly abandoned a promising candidate after a failed trial in 2022. One possible basis for non-opioids might be cannabis. Earlier this year, researchers at Washington University at St. Louis and Stanford published a study showing that a cannabis-derived compound successfully eased pain in mice with minimal side effects. Munich-based pharmaceutical company Vertanical is perhaps the furthest along in this quest. It is developing a cannabinoid-based extract to treat chronic pain it hopes will soon become an approved medicine, first in the European Union and eventually in the United States. The drug, currently called Ver-01, packs enough low levels of cannabinoids (including THC) to relieve pain, but not so much that patients get high. Founder Clemens Fischer, a 50-year-old medical doctor and serial pharmaceutical and supplement entrepreneur, hopes it will become the first cannabis-based painkiller prescribed by physicians and covered by insurance. Fischer founded Vertanical, with his business partner Madlena Hohlefelder, in 2017, and has invested more than $250 million of his own money in it. With a cannabis cultivation site and drug manufacturing plant in Denmark, Vertanical has successfully passed phase III clinical trials in Germany and expects…
Share
BitcoinEthereumNews2025/09/18 05:26
Short-term profit-taking pushes Bitcoin back below key $70K level – What next?

Short-term profit-taking pushes Bitcoin back below key $70K level – What next?

The post Short-term profit-taking pushes Bitcoin back below key $70K level – What next? appeared on BitcoinEthereumNews.com. Bitcoin [BTC] rallied as high as $74
Share
BitcoinEthereumNews2026/03/07 16:09