When you think of Black Friday, you probably picture unbeatable promotions, packed shopping carts and a surge of online activity. But behind the excitement lies one of the riskiest times of the year for cyberthreats – not just for consumers, but for the retailers powering those sales. Spencer Young, SVP, International at Delinea , outlines how retailers need to secure their machine identities.
Last year, phishing scams around Black Friday and Cyber Monday surged by 692% compared to early November. With AI-driven threats accelerating, we can expect these numbers to rise even further this season. Cybercriminals know that retail teams are stretched thin during major sales events – juggling website traffic, promotions and customer demand – making it easier for a fraudulent login or phishing email to slip through unnoticed.
While the most common attacks are about stealing people’s identities or committing fraud, what many businesses often overlook is that it’s not just people’s identities being targeted – it’s machines too. These are the credentials that silently connect platforms, automate transactions and power the entire digital retail ecosystem. Yet many retailers often overlook how critical they are until something goes wrong. And when it does, consequences can be severe – disrupting operations, crippling sales and damaging brand reputation and consumer trust that can take years to rebuild.
The hidden cyber loophole: Machine identities
Every digital interaction within the retailer ecosystem, from checkout to delivery, relies on a complex network of connected systems. Payment gateways, inventory management platforms and logistics software all communicate through machine identities.
From chatbots to APIs and autonomous agents, machine identities already outnumber humans and are projected to exceed 45 billion globally by the end of 2025. Despite their prevalence and critical role in keeping operations running smoothly, they remain among the least protected assets: only 28% of organisations prioritise securing machine identities.
According to Delinea’s 2025 AI in Identity Security report, while 76% of retailers in Australia are modernising their infrastructure to enhance customer experience, only 35% have visibility into their machine identities – let alone the controls needed to secure them. That means most retailers are operating blind across critical parts of their digital infrastructure, making it all too easy for attackers to slip through undetected.
Lessons from recent breaches
Recent high-profile breaches affecting retailers like Marks & Spencer and Adidas reveal just how vulnerable the sector is – especially when it comes to managing machine identities and the credentials that protect them. In the Marks & Spencer breach, attackers exploited weaknesses in authentication systems, successfully using stolen credentials to gain unauthorised access. They then deployed ransomware that disrupted the retailer’s online operations for weeks, costing millions in lost revenue and leaving customers unable to shop online.
A key takeaway is that it’s not always the data itself that attackers are after, it’s the access. And while machine identities, such as API keys and automated accounts, might seem invisible, they can quietly provide attackers the access they need to break in. Once inside, threat actors can impersonate legitimate users, manipulate data and even interrupt supply chains – turning a weak link into enterprise-wide disruption.
With Black Friday approaching, the stakes have never been higher. The focus can’t just be on customer-facing defences; neglecting the hidden web of machine identities leaves even the most advanced retailers extremely exposed.
Secure your systems before Black Friday
Retailers have invested heavily in digitising their operations to meet evolving consumer expectations. But those innovations depend on the trust between systems – and machine identities are the glue holding everything together.
You cannot secure what you cannot see. The first step is gaining full visibility: identify, manage and monitor every machine identity. From there, enforce least-privilege access so each identity has only the permissions it truly needs, only when it needs them. And replace shared, always-on accounts with just-in-time credentials that automatically expire after use.
Retailers have modernised their tech stacks – now it’s time to secure them. Until machine identities are properly protected, even the most advanced digital retail operation remains just one exposed credential away from disruption.

