Half of APAC Retail Staff Share Sensitive Credentials

Nearly nine in ten retailers globally, including businesses across the Asia-Pacific, experienced a cyber incident over the past year, according to new research from Kaspersky. The study also found that half of retail employees in the APAC region admitted to sharing sensitive corporate credentials with colleagues or external parties, underscoring how human error remains one of the sector’s biggest vulnerabilities.

The findings, drawn from a survey of 1,800 IT security specialists and management representatives across 18 countries, paint a picture of a retail industry increasingly exposed as it embraces AI-driven and personalised customer experiences. Only 13 per cent of retailers surveyed said they had avoided a cyber incident altogether in the past 12 months.

Phishing and credential sharing among top threats

Phishing was the most commonly reported threat, affecting 21 per cent of retailers, followed by cyber espionage (19 per cent) and web application exploits (18 per cent). Attackers’ primary targets were customer and employee personal data, cited by 34 per cent and 28 per cent of respondents respectively.

In APAC specifically, the most common consequences of recent attacks included theft of employees’ personal data (44 per cent), theft of clients’ personal data (39 per cent), and irrecoverable data loss (33 per cent).

Internal risk factors compounded the problem. A lack of IT security awareness was cited by 46 per cent of APAC respondents as the leading internal vulnerability, followed by insufficient expertise among IT security staff and outdated software or hardware, both at 31 per cent. Half of APAC respondents admitted to sharing sensitive corporate credentials with colleagues or third parties, while 46 per cent said employees had downloaded or installed software tools without IT security approval.

Retailers turning to external security providers

Despite the risks, 77 per cent of retailers in APAC increased their IT security budgets this year, with many opting to work with third-party security providers rather than expand in-house teams.

“Retail is a highly dynamic industry: business priorities, workloads, infrastructure requirements, and economic conditions change rapidly. To ensure that cybersecurity keeps pace with these changes, retailers choose to turn to external security service providers, gaining access to the required expertise and technologies without having to continuously expand their in-house teams,” said Elizaveta Komarova, Solution Architect, Finance & Retail at Kaspersky.

The report also flagged growing AI adoption in the sector, with 15 per cent of APAC retailers already running a working large language model-based tool and a further 77 per cent in the discussion, design or pilot phases.

“Our APAC findings highlight an important gap in retail cybersecurity in the region. As retailers here adopt more connected and AI-driven technologies, it is becoming clear that some of their vulnerabilities stem from how technology and data are used and protected across the organisation,” said Adrian Hia, Managing Director for APAC at Kaspersky.

Kaspersky recommends that retailers strengthen employee awareness programmes, update AI usage policies to address inadvertent data exposure, identify and prioritise protection of critical assets, and deploy advanced endpoint protection across devices.

Author

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading