Friday, June 5, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » Why Attacks Are the New Normal for eCommerce and Travel

SBN

Why Attacks Are the New Normal for eCommerce and Travel

by Ashish Jain on July 15, 2021

Evolving trends in fraud and abuse show eCommerce and travel providers are prime targets as attackers leverage online shopping conveniences to monetize stolen credentials and payment details.  

In-person transactions shifted to online in 2020, as shopping at physical storefronts came to a halt. Consumers had to rely on digital channels to shop even for the most basic needs. As these habits become the new norm, the future of shopping changed for good.

Attackers Target Retail 

This mass transition to online was an attacker’s  dream come true. Insights from the Arkose Labs network reveal, during Q4 of 2020 retail was a highly attacked target. . This was the result of increased consumer spending  through Black Friday and the holiday season. 

Ecommerce fraud continued into the early part of the first quarter in 2021, before easing up a little by spring. As fraud teams try to catch up to the new normal volumes of digital commerce—redefined by the pandemic—attackers are focusing on payment attacks and scraping for information.

eCommerce: What is an Acceptable Level of Friction?
RECOMMENDED RESOURCE
eCommerce: What is an Acceptable Level of Friction?
ACCESS Whitepaper

Travel Suffers Attacks During Pandemic

Another area where consumer spending has returned is travel. Travel industry was perhaps the worst affected due to the pandemic with airlines, cruise operators, car rental agencies, and hotels shuttering down almost overnight. 

For several months at a stretch, demand slowed down to a trickle. However, as the world begins to open up and more people get vaccinated, travel is making a roaring comeback. Air and hotel bookings have nearly reached the pre-pandemic levels. Fraudsters, too, are scouting for opportunities to steal credit cards, gift cards, and rewards to capture their share of consumers’ dollars.

2021 Took Off From Where 2020 Left 

The beginning of 2021 was not much different from how 2020 ended for the e-commerce and travel industries. However, things quickly changed as pandemic-related restrictions lessened and life seemed a bit closer to normal. 

Since the beginning of the year, e-commerce and travel attacks increased by 63% as traffic across these platforms soared back to pre-pandemic levels. Following these changes, peak eCommerce and travel periods like Black Friday saw spikes up to 20x the average attack volume.

Payment Methods Are Prime Targets of eCommerce Fraud 

With volumes of new users increasing during the pandemic — as well as an increase in the traffic from returning eCommerce customers — attackers  are targeting users for their payment methods. Fraudsters can monetize compromised accounts in several ways, including stealing the payment or bank account information stored in the account, money laundering, payments fraud, stealing and redeeming loyalty or rewards points, and much more.

E-commerce fraud, especially payment fraud on gift cards is on the rise. Attackers use automation to brute force attacks on gift card websites. They test thousands of card numbers and PIN combinations every minute. Also, they deploy bots and sweatshops to continually check card balances in order to redeem them as quickly as possible.

Gift card fraud is particularly attractive to attackers  due to low authentication barriers when compared with authentication requirements for credit cards. In the case of gift cards, there is no additional verification for points redemption, making it easy for attackers  to escape with their loot, undetected. Also, much like cash theft, gift card fraud is difficult to trace.

Read how a major gift and prepaid card provider deterred attack: 

Payment Firm Foils Giftcard Fraud With Arkose Labs
RECOMMENDED RESOURCE
Payment Firm Foils Giftcard Fraud With Arkose Labs
ACCESS Case Study

ARKOSE LABS Fights eCommerce Fraud

Gift card fraud can disrupt consumers’ shopping experiences and damage retailer brand reputations, making it essential for retailers to secure their physical and digital cards. Detecting and stopping fraud is difficult, as there are no authentications or trails. Therefore, retailers must adopt a fraud-prevention approach that eliminates attacks without disrupting genuine user experiences. Arkose Labs’ bilateral approach targets automated bots and bad actors with adaptive, graduated friction to stop attacks, while making authentication fun and seamless for genuine users.

Arkose Labs helps online retailers accurately identify and thwart attackers using digital intelligence. Authentic users clear user-friendly enforcement challenges unseen, while bots and automated scripts fail instantly. Malicious humans are presented with increasingly complex challenges, wasting their time and resources until they call it quits, providing long-term protection for ecommerce and travel. 

Contact us to learn more!

*** This is a Security Bloggers Network syndicated blog from Arkose Labs authored by Ashish Jain. Read the original post at: https://www.arkoselabs.com/blog/why-attacks-are-the-new-new-normal-ecommerce-travel/

July 15, 2021March 1, 2023 Ashish Jain account takeover, credential stuffing, New Account Origination
  • ← Targeted Attack on Government Organizations Delivers Netwire RAT
  • Zero Trust Networking →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack
The Cost of Exposure: Managing the Operational Risks of Executive Security Incidents
The Future of Agentic Software Delivery: Unifying Source & Binaries
35 Million Lines, Zero Build-Breakers: How Adyen Scaled DevSecOps
Zero Trust for Agentic AI: Managing Non‑Human Identities at Scale

Podcast

Listen to all of our podcasts

Secure by Design

2 days ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

1 week ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

1 week ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

3 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

3 weeks ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Threat Actors Abuse ChatGPT Chats to Host Fake Outage Page, Deliver Malware
Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models
Sumo Logic Brings SIEM Platform to AWS European Sovereign Cloud
AI-Powered Computer Worm Reveals New Cybersecurity Threat
MazeBolt Adds AI Module to Simulate DDoS Attack
AI Governance for Startups: Pass Enterprise Reviews
Miasma: Red Hat Cloud Services npm Packages Hit by a Mini Shai-Hulud-Style Campaign
A Reference Architecture for Containing Agents: What Cequence Built and Anthropic Arrived At Independently
Imperva Customers Protected Against CVE-2026-49975 (HTTP/2 Bomb) DoS
OpenAI Codex Supply Chain Attack Exposes Growing Risks in AI Development Environments

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Featured Incident Response Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds

June 4, 2026 Jeffrey Burt | Yesterday 0
Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Endpoint Featured Governance, Risk & Compliance Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence 

Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models

June 3, 2026 Jeffrey Burt | 2 days ago 0
Sumo Logic Brings SIEM Platform to AWS European Sovereign Cloud
Cloud Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Sumo Logic Brings SIEM Platform to AWS European Sovereign Cloud

June 2, 2026 Michael Vizard | 3 days ago 0

Security Humor

Randall Munroe’s XKCD 'Types of Board Game'

Randall Munroe’s XKCD ‘Types of Board Game’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
7 Must-Read eBooks for Security Professionals
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.