DrochaidHorizon3.ai
NodeZero/Industries/Retail & Hospitality
The state of play — Retail, Hospitality & Aviation, 2026

Retail and hospitality are being hit on two fronts at once.

Ransomware against retail doubling between holiday seasons, PCI DSS v4.0.1 fully mandatory, Privacy Act penalties reaching $50 million or more, and Scattered Spider turning helpdesk phishing into a repeatable playbook. The sector is being hit on regulatory, criminal and technique fronts simultaneously.

~287
major companies (about 2% of organisations with revenues above $500 million) flagged at heightened risk from Scattered Spider tradecraft, based on the technologies they run and their security conditions.
CyberCube analysis, via Cybersecurity Dive
100%
jump in ransomware attacks on retail between the 2022 and 2023 holiday seasons, with attacks spiking by up to 100% in the latter half of each year.
VikingCloud — Ransomware Statistics 2026
56%
increase in ransomware attacks on manufacturers — the suppliers behind retail — in 2025 (937 to 1,466), with average ransom demands more than doubling from $523,000 to nearly $1.2 million.
Comparitech — 2025 Ransomware Roundup
The trend

Why Retail, Hospitality and Aviation are in the crosshairs

Five shifts shaping the consumer-operator threat environment — from helpdesk social engineering to vendor software cascades.

Scattered Spider has industrialised helpdesk social engineering

The group's 2025 campaign moved sector by sector — US and UK retail in April–May, insurance in June, airlines in late June. The tactic is consistent: call the outsourced IT helpdesk, impersonate a senior employee, request MFA reset or credential reset. Traditional pentesting scopes rarely cover helpdesk process. Phished-credential and third-party testing modes are built for exactly this class of attack.

Third-party IT and outsourced helpdesks are the attack surface

M&S was compromised via its outsourced third-party IT helpdesk. Clorox has publicly sued Cognizant, alleging its outsourced helpdesk repeatedly reset credentials without proper identity verification. Qantas's July 2025 incident involved a third-party contact centre. The larger the enterprise, the more likely its helpdesk is outsourced — and the less likely its own security team has tested the controls on those outsourced human workflows.

Downtime-sensitivity drives payment pressure

Scattered Spider specifically targets industries that face significant customer pressure and financial losses from the impact of even hours of downtime. Retail during the holidays, casinos on a Saturday night, airlines at summer peak — the pressure to restore operations creates pressure to pay. CyberCube flagged roughly 300 high-revenue companies at elevated risk on this basis.

Customer data concentration is enormous and now regulated

Airline loyalty programs, hotel reward databases, retailer credit-card-linked accounts, and hospitality group PCI environments all hold concentrated, monetisable PII and payment data. Australia's strengthened Privacy Act penalties and global PCI DSS 4.0 requirements put direct financial exposure on every operator. Qantas's July 2025 incident affected 5.7 million records.

Vendor software ecosystems cascade the risk

CDK Global in June 2024 — a single dealer management software provider compromise cost US and Canadian auto dealers an estimated $1.02 billion in about three weeks. British Airways / Zellis / MOVEit in 2023 — a single payroll provider compromise affected employees at BA, Boots, BBC, Aer Lingus and more. Hertz / Cleo in April 2025 — Hertz customer data exposed via a file-transfer vendor.

On the record

What regulators and experts are saying

Hackers entered M&S's systems via "human error" at a third party. Then, over the Easter break holiday, it became clear we were facing a highly sophisticated and targeted attack.
Stuart Machin
CEO, Marks & Spencer
May 2025
The adversary used help desk voice-based phishing in almost all observed 2025 incidents to compromise Microsoft Entra ID, single sign-on (SSO), and virtual desktop infrastructure (VDI) accounts.
CrowdStrike Services
Q2 2025 Observations
July 2025
Airlines and firms in the aviation industry consist of an attractive cocktail of critical infrastructure, sometimes outdated tech, and massive customer databases… Many aviation industry businesses still rely on legacy systems bolted onto newer platforms, which determined hackers like Scattered Spider love to exploit.
Graham Cluley
Cybersecurity expert, to ITV News
July 2025
What is now required

PCI DSS v4.0.1 is fully mandatory

All 51 future-dated requirements became effective 31 March 2025. First full assessment cycles due in 2026. Retailers must demonstrate annual penetration and segmentation testing, and MFA enforcement.

Any entity that stores, processes, or transmits cardholder data must comply with PCI DSS v4.0.1 — the Payment Card Industry Data Security Standard. PCI DSS has 12 principal requirements covering network security, data protection, vulnerability management, access control, monitoring, and security policy. All future-dated v4.0.1 requirements became mandatory on 31 March 2025, with first full assessment cycles due in 2026. The Essential Eight is not mandatory for retail but is increasingly adopted as a baseline cyber security framework, particularly by organisations subject to SOCI Act obligations or seeking to satisfy cyber insurance requirements.

Frameworks that apply
PCI DSS v4.0.1

Applies to any entity that stores, processes, or transmits cardholder data. All future-dated v4.0.1 requirements became mandatory 31 March 2025.

ASD Essential Eight Maturity Level 2

Increasingly adopted by Australian retail organisations as a baseline cyber security framework. Aligns with SOCI obligations where applicable.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

PCI DSS v4.0.1 — Full compliance mandatory

31 Mar 2025

All 51 future-dated requirements became effective 31 March 2025. Annual penetration testing (Req 11.4), segmentation testing — six-monthly for service providers, annual for merchants (Req 11.4) — and MFA for CDE access (Req 8.4) are now fully enforced. First full assessment cycles due 2026.

Cyber Security Act 2024

30 May 2025

Major retailers and hospitality operators over $3M turnover, or with critical infrastructure responsibilities, must report ransomware payments within 72 hours. Security standards for smart devices apply to the connected products operators deploy — IoT-enabled POS terminals, self-checkout systems, and smart locks.

New Franchise Code of Conduct

1 Apr 2025

Effective 1 April 2025, the remade Franchising Code tightens franchisor disclosure obligations. Franchise networks remain squarely subject to the Privacy Act — franchisors managing shared customer and franchisee data carry the APP 11 security obligation across the network.

SOCI Act — Food and grocery critical infrastructure

In effect

Food and grocery retail is designated a critical infrastructure sector. Major food and grocery retailers such as Woolworths and Coles fall under SOCI scope with mandatory Risk Management Programs and annual compliance reporting.

Platform credentials

The only autonomous pentesting platform that is:

PCI DSS v4.0.1
Segmentation proof
CDE-mapped
Essential Eight
Mapped ML1–3
ASD baseline
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Prove your CDE isolation before your 2026 PCI assessment

See how NodeZero delivers PCI DSS v4.0.1 compliance for your retail or hospitality environment