Proofpoint research reveals 40% of the leading retailers are not actively blocking bogus emails that spoof their brand
SUNNYVALE, Calif., November 21, 2024–(BUSINESS WIRE)–Black Friday marks the unofficial start of the holiday shopping season. With just days to go until the annual event, Proofpoint Inc., a leading cybersecurity and compliance company, today released new research revealing two out of five of the leading retailers are not taking adequate measures to protect consumers from email fraud and cybercrime.
These findings are based on a Domain-based Message Authentication, Reporting and Conformance (DMARC) adoption analysis of the top 50 retailers in the United States. DMARC is a widely-used email protocol that helps protect domain names from being spoofed and misused by cybercriminals. It authenticates an email sender’s identity before allowing a message to reach its intended destination, ensuring the sender is who it says it is. With three levels of protection—monitor, quarantine, and reject—DMARC ensures that only verified senders can send emails using a retailer’s domain. The ‘reject’ policy is the most secure, preventing any fraudulent emails from reaching the inbox.
The National Retail Federation (NRF) expects sales to grow steadily this year, forecasting that Americans will spend between $979.5 billion and $989 billion during the holiday season. Online shopping—which the NRF predicts will be the primary contributor of overall retail sales growth—spurs a flurry of email communications from retailers, presenting an opportunity for cyber criminals to spoof brands to launch fraudulent attacks. Email is a widely used marketing tool and a popular channel for cyber criminals to conduct large-scale phishing campaigns to steal personal information or credit card details that can then be used to engage in identity and financial fraud.
Proofpoint’s analysis of the top 50 retailers according to the NRF and their adoption of DMARC finds:
60% of online retailers in the U.S. have implemented the highest level of protection to reject suspicious emails from reaching consumers’ inboxes, a 12-point increase compared to 2023
However, this means that 40% of online retailers are not actively blocking fraudulent emails from reaching consumers
One in 10 retailers have no DMARC record in place at all
18% have implemented a monitor policy, meaning unqualified emails can still arrive in the recipient’s inbox; only 12% have implemented a quarantine policy to direct unqualified emails to spam/junk folders
“Email continues to be the vector of choice for cybercriminals and the retail industry remains a key target. It’s encouraging to see that more retailers are taking the right steps to protect their customers from email fraud this holiday season compared to last year,” said Robert Holmes, group vice president and general manager of Proofpoint’s Sender Security and Authentication business. “However, there is still a lot of room for improvement, especially as guards are down as consumers vie to quickly snag seasonal bargains.”
New York CNN — Walmart’s business is surging. Customers making more than $100,000 a
Photo: David Parry/PA Media AssignmentsNew research by American Express Shop Small reveals the nation’s top 10 hotspots for independent shops, showcasing th
Well-known American actor John Malkovich, who was on stage last week at the National Theatre in Timișoara, visited the city’s first official souvenir shop on
By ZAC CAMPBELL Published: 07:57 GMT, 16 November 2024 | Updated: 08:36 GMT, 16 November 2024