In an increasingly interconnected world, online shopping and electronic transactions have now transcended its innovation status to become part of our daily lives. Its ease of use and convenience, can also mean significant security risks since sensitive information and personal data are routinely shared among business owners and shoppers.
Some these security risks include the following:
Financial data theft/fraud: Many attackers target personal information such as names, addresses and credit card numbers. This allows them to make purchases online using someone else’s payment information. One method being used is called pharming or using fraudulent websites to manipulate people into giving out their credentials.
Another more effective and insidious method is deliberately targeting specific users and manipulating them into giving their personal information (also known as spear phishing). Other exploits used to steal financial information include, but are not limited to: SQL Injection, Cross-Site Scripting, Path Traversal, Session Hijacking, and Drive-by Downloading
Distributed Denial of Service (DDoS) attacks: A Denial of Service attack’s aim is to take down e-commerce sites by flooding them with requests. This kind of attack overloads the e-commerce site to the point where it can’t handle anymore requests, making the service slow down or even go offline.
Slow service for an e-commerce site means loss of potential revenue and massive impact to brand reputation.
Man in the middle attack: Man in the Middle attacks do exactly what they say — the attacker eavesdropping or intercepting the user’s (in this case, the online shopper’s) connection with the website. Even with Secure Sockets Layer (SSL)/Transport Layer Security (TLS) in place, there are still ways attackers can trick the browser to gain access to the plain text data.
Effects of a security breach for an e-commerce site
If such an attacker manages to compromise an e-commerce site, the following can happen:
Loss of revenue: The first, most obvious effect of a security breach is loss of income. Small businesses shell out an average of $38,000 to recover from a single data breach in direct expenses alone. On top of that, a company that experiences a security breach can also be held accountable for not following data protection policies, leading to hefty fines that can lead to a business’s insolvency.
Damage to brand reputation: Apart from the direct loss of sales due to site unavailability (due to a DDoS attack, for example), losses of sales can also be due to customers walking (or in this case, browsing) away from the shop in favour of other shops without such security breaches. Losing customers’ and stakeholders’ trust is the most harmful impact of a security breach.
People will not do business with a breached company, plain and simple.
Even if the company is eventually able to recover the financial losses, the impact on the company’s reputation would be a scar that would take a significant amount of time to fade. That is, if it even fades at all.
Intellectual property theft/damage: Another impact of a security breach is theft and damage to intellectual property like trade secrets, blueprints, and anything else that gives a company their competitive advantage. This can mean missing out on expanding the business since the company can no longer fully implement new and innovative ideas brewing in the pipeline.
How to protect e-commerce sites
The good news is there are ways e-commerce shop owners can protect their websites, their customers, and their data:
Security is number one from day one
Hackers and cybercriminals only get smarter and more sophisticated with each passing year. Therefore, the onus is on business owners to make security a priority.
While a cybersecurity endeavour takes a lot of time and resources, the upfront cost is still lower than the potential losses and is a worthwhile investment for all e-commerce setups.
Article by Horangi Cyber Security cyber operations researcher Samantha Cruz.