How to stay cyber-safe when everyone else is shopping

How to stay cyber-safe when everyone else is shopping

Peak-season shopping has become a cyber gauntlet, warns Arda Büyükkaya, Senior Cyber Security Threat Analyst at EclecticIQ. Recent UK attacks on retailers including M&S, Co-op and Harrods show how criminals use urgency and AI-powered scams to exploit distracted buyers. Here’s how to stay safe, strengthen authentication, minimise data exposure, use virtual cards and treat every ‘too-good-to-be-true’ offer with scepticism.

The shopping season has become as much a test of cyber-resilience as it is a hunt for bargains. From Black Friday through to Boxing Day, millions of consumers rush online, primed for flash sales and last-minute deals. Yet behind the countdown clocks and ‘once-in-a-lifetime’ offers lies a darker reality as cybercriminals prepare to exploit distracted shoppers. Every click carries risk and every bargain can become an opportunity for fraud.

Recent events in the UK illustrate the scale of the problem. During the Easter break in April 2025, Marks & Spencer (M&S) fell victim to a major cyberattack, believed to be carried out by the group known as Scattered Spider. The incident disrupted online orders, click-and-collect services and even contactless payments in stores. Customers faced delays and shortages and the financial cost is expected to exceed £300 million in lost operating profit.

M&S was not alone. Around the same time, Co-op and Harrods also reported cyber incidents that affected payment systems, ordering platforms and internal IT operations. These incidents were not isolated events. They form part of a growing pattern of attacks on retailers, timed to coincide with busy trading periods. For consumers, the message is clear: these attacks will continue and shoppers need to be more vigilant than ever.

Why shoppers are easy targets

Shopping peaks are attractive to criminals not only because of the sheer volume or number of transactions but because of the psychology of the moment. Consumers are in a hurry, keen to secure discounts before they vanish and in that rush, caution is too often abandoned. Fraudsters exploit this urgency with cloned websites that mimic well-known retailers, phishing emails and texts that are virtually indistinguishable from genuine offers and by capitalising on the widespread habit of password reuse.

Artificial Intelligence has intensified the threat. Attackers can now write scam messages that are polished, localised and personalised to an individual’s interests or location. Some go further still, using AI to clone voices and impersonate friends, colleagues or financial institutions over the phone. This convergence of psychology and technology has created a threat landscape where scams are both harder to detect and more damaging when they succeed.

The smart shopper’s playbook: Dos and don’ts

Do strengthen your digital defences: Simple passwords or SMS codes are no longer enough. Enable two-factor authentication wherever possible and consider physical security keys such as FIDO2 devices, which are far harder to compromise. Using a password manager ensures that every account has a strong, unique login, reducing the chance that one breach cascades across multiple services.

Don’t reuse passwords or expose personal details: Recycling credentials is like giving criminals a master key. A password stolen from a fashion retailer could be used to unlock your email, cloud storage or bank account. Similarly, leaving phone numbers, addresses or other personal details visible online makes it easier for fraudsters to target you with convincing scams. Practicing good cyber hygiene by regularly reviewing and reducing your digital footprint is an essential line of defence.

Do shop with virtual cards: Many UK banks now offer temporary digital payment cards with pre-set balances. These disposable cards act as buffers: even if compromised, the criminal gains little. For high-risk or one-off purchases, virtual cards are a simple but powerful safeguard. Their value was underlined by the M&S breach, in which payment information was among the details exposed.

Don’t trust every message or call: Phishing does not come only via email. Voice phishing or vishing, is now increasingly common. With AI voice cloning, a fraudster can mimic the voice of someone you know and pressure you into handing over codes or transferring money. Treat unexpected calls with caution. Never share sensitive information on the spot and if in doubt, hang up and call back using an official number.

Do let AI work for you: While criminals exploit AI to make scams more convincing, consumers can also benefit from it. Banks, card issuers and email providers are deploying AI-driven systems to detect unusual transactions, flag suspicious logins and block fraud in real time. By choosing providers that invest in such protections, shoppers enlist a quiet but powerful ally that helps keep them safe.

The way ahead

The wave of cyberattacks against retailers such as M&S, Co-op and Harrods demonstrates that this is no longer a hypothetical risk. The impact on consumers is direct, from disrupted services to exposed personal data. Yet the power to shift the balance does not lie solely with institutions. Shoppers themselves can adopt practices that make them far harder targets.

Online shopping will always carry risk, but combining practical defences with a measure of scepticism makes it far safer. Cybercriminals thrive on distraction and urgency and the antidote is preparedness and caution. Awareness cannot be limited to one month in the calendar. It must become as instinctive as locking the front door. By strengthening authentication, reducing exposure and questioning offers that seem too good to be true, consumers can regain confidence in their online lives.

In a world where scams evolve at speed and AI makes deception more convincing, the smartest move any shopper can make is simple: pause, think critically and shop securely.

Browse our latest issue

Intelligent Retail.tech

View Magazine Archive