movefaster@commercemind.se

Black Week: here come the hackers

If you follow the security conversation, you know it is not only the buyers who look forward to this period. Those with a different sort of intent are also rubbing their hands right now. Phishing emails, ransomware operators and outright DDoS attacks tend to increase during Black Week, when focus is on other things and traffic is high.

Rickard Jönsson22 November 2021

At Commerce Mind we had a short chat with Alexandra Dornérus , Head of Business Development at Ellos Group, also a good friend of several of us in the company after having worked together a few years back, to hear what is bubbling around Black Friday in her world. Naturally, at Ellos Group they are looking forward to Friday. The campaigns are ready, customer service is sharpened, and logistics and warehouse production stand ready to deliver on time to the customers. We at Commerce Mind suspect it will be a sales record again at Ellos Group. But there are storm clouds in the industry that not everyone may have thought about. Alexandra brought up something we think is easy to forget: the hackers are coming.

If you follow the security conversation, you know it is not only the buyers who look forward to this period. Those with a different sort of intent are also rubbing their hands right now. Phishing emails, ransomware and outright DDoS attacks often increase during Black Week, now that focus is on other things and traffic is high.

"We are getting indications from industry colleagues that threats have started rolling in ahead of Black Week."

You have probably all read about MediaMarkt's problems , so these were not empty tips buzzing around the industry, but they seem to have handled the worst of it to make it to Black Week, and are running the campaigns as planned, which we can congratulate them for, and one can suspect it has been sweaty times at IT recently.

Security, hacks and threat attacks are often either very public (hard to hide for Coop when the tills do not work) or they are secret and hush hush. No one wants to advertise that they have been targeted because they missed patching a server or configured something wrong. It is easy for a blame game to break out, and in the end there is a server technician who slipped up and gets the blame for something that feels more like a systemic issue. Everything is so complex that it is incredibly hard to be 100% protected against everything.

With that said, you obviously have to do everything to protect yourself. Alexandra continues:

"Focusing on security and intrusion is critical, on top of everything else that has to work. Unfortunately I think the whole industry is aware of how sophisticated both threats and intrusions have become, especially during Black Week when you as an e-commerce operator are most vulnerable due to extreme sales pressure and traffic."

With increased traffic and sales come not only security intrusions like Magecart attacks, but also fraud.

Magecart attacks, which have their history in Magento, have in the last year focused on other platforms that have grown large. A Magecart attack works by exploiting front-end JavaScript and stealing information the customer enters on their mobile or browser. Just as the e-commerce operator's customers use mobiles for shopping to a greater extent, the hackers have of course followed the same trend. An evolution of Magecart to be "mobile first" is called MobileInter.

A common way for Magecart attacks to take over your e-com site is through a third-party add-on or plugin. Review which third-party scripts you use, and be extra careful about adding new ones ahead of Black Friday, when it can be harder to spot abnormal patterns in sales and traffic.

When it comes to fraud, a lot of it is about taking control of logistics and customer knowledge. Rickard Jönsson at Commerce Mind offers some final tips:

  • Do not send packages without tracking.

  • New customers, primarily B2B, may need a separate review before you send the order.

  • If possible, do an extra check on orders containing certain types of products (branded jackets, Apple products and so on).

  • Be alert to orders where the customer wants to change the delivery address.

We at Commerce Mind hope you have everything patched and configured right ahead of the weekend, but keep an eye on what happens and make sure customer service is trained not to fall for the simplest trick, the human scam.

Rickard Jönsson

Author

Rickard Jönsson

Rickard has delivered more than 30 e-commerce projects as a senior systems and solutions architect, focused on driving his clients' sales. With 20 years of software development experience, Rickard has repeatedly been the key to ensuring project success.

Related articles

Technical debt: when 'we will fix it later' becomes 'why is everything on fire?'

Technical debt is more than a technical concept, it is a business-critical reality that affects everything from time-to-market to customer experience. In e-commerce, where every millisecond and every click counts, the choices you make in your technical platform can have far-reaching consequences. When quick fixes are prioritised over long-term durability, an invisible but growing debt is built up. It affects not only development speed and stability, but at worst can slow the company's ability to innovate and compete. To face the future the right way, technical debt has to be understood, quantified and managed as the strategic investment it actually is.

John Järpling