Retail and hospitality are being hit on two fronts at once.
Ransomware against retail doubling between holiday seasons, PCI DSS v4.0.1 fully mandatory, Privacy Act penalties reaching $50 million or more, and Scattered Spider turning helpdesk phishing into a repeatable playbook. The sector is being hit on regulatory, criminal and technique fronts simultaneously.
Why Retail, Hospitality and Aviation are in the crosshairs
Five shifts shaping the consumer-operator threat environment — from helpdesk social engineering to vendor software cascades.
Scattered Spider has industrialised helpdesk social engineering
The group's 2025 campaign moved sector by sector — US and UK retail in April–May, insurance in June, airlines in late June. The tactic is consistent: call the outsourced IT helpdesk, impersonate a senior employee, request MFA reset or credential reset. Traditional pentesting scopes rarely cover helpdesk process. Phished-credential and third-party testing modes are built for exactly this class of attack.
Third-party IT and outsourced helpdesks are the attack surface
M&S was compromised via its outsourced third-party IT helpdesk. Clorox has publicly sued Cognizant, alleging its outsourced helpdesk repeatedly reset credentials without proper identity verification. Qantas's July 2025 incident involved a third-party contact centre. The larger the enterprise, the more likely its helpdesk is outsourced — and the less likely its own security team has tested the controls on those outsourced human workflows.
Downtime-sensitivity drives payment pressure
Scattered Spider specifically targets industries that face significant customer pressure and financial losses from the impact of even hours of downtime. Retail during the holidays, casinos on a Saturday night, airlines at summer peak — the pressure to restore operations creates pressure to pay. CyberCube flagged roughly 300 high-revenue companies at elevated risk on this basis.
Customer data concentration is enormous and now regulated
Airline loyalty programs, hotel reward databases, retailer credit-card-linked accounts, and hospitality group PCI environments all hold concentrated, monetisable PII and payment data. Australia's strengthened Privacy Act penalties and global PCI DSS 4.0 requirements put direct financial exposure on every operator. Qantas's July 2025 incident affected 5.7 million records.
Vendor software ecosystems cascade the risk
CDK Global in June 2024 — a single dealer management software provider compromise cost US and Canadian auto dealers an estimated $1.02 billion in about three weeks. British Airways / Zellis / MOVEit in 2023 — a single payroll provider compromise affected employees at BA, Boots, BBC, Aer Lingus and more. Hertz / Cleo in April 2025 — Hertz customer data exposed via a file-transfer vendor.
What regulators and experts are saying
Hackers entered M&S's systems via "human error" at a third party. Then, over the Easter break holiday, it became clear we were facing a highly sophisticated and targeted attack.
The adversary used help desk voice-based phishing in almost all observed 2025 incidents to compromise Microsoft Entra ID, single sign-on (SSO), and virtual desktop infrastructure (VDI) accounts.
Airlines and firms in the aviation industry consist of an attractive cocktail of critical infrastructure, sometimes outdated tech, and massive customer databases… Many aviation industry businesses still rely on legacy systems bolted onto newer platforms, which determined hackers like Scattered Spider love to exploit.
PCI DSS v4.0.1 is fully mandatory
All 51 future-dated requirements became effective 31 March 2025. First full assessment cycles due in 2026. Retailers must demonstrate annual penetration and segmentation testing, and MFA enforcement.
Any entity that stores, processes, or transmits cardholder data must comply with PCI DSS v4.0.1 — the Payment Card Industry Data Security Standard. PCI DSS has 12 principal requirements covering network security, data protection, vulnerability management, access control, monitoring, and security policy. All future-dated v4.0.1 requirements became mandatory on 31 March 2025, with first full assessment cycles due in 2026. The Essential Eight is not mandatory for retail but is increasingly adopted as a baseline cyber security framework, particularly by organisations subject to SOCI Act obligations or seeking to satisfy cyber insurance requirements.
Applies to any entity that stores, processes, or transmits cardholder data. All future-dated v4.0.1 requirements became mandatory 31 March 2025.
Increasingly adopted by Australian retail organisations as a baseline cyber security framework. Aligns with SOCI obligations where applicable.
Retailers and hospitality businesses with annual revenue over $3M are bound by the Australian Privacy Principles when handling customer loyalty, booking, and employment data.
Where NodeZero appliesRelevant for retail technology providers, e-commerce platforms, and hospitality SaaS vendors managing customer data on behalf of merchants.
Where NodeZero appliesAdopted by larger retail groups and franchise operators to demonstrate security maturity to partners and payment processors.
Where NodeZero appliesMandatory ransomware reporting applies to retail and hospitality businesses meeting the reporting threshold under the Cyber Security Act.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
PCI DSS v4.0.1 — Full compliance mandatory
31 Mar 2025All 51 future-dated requirements became effective 31 March 2025. Annual penetration testing (Req 11.4), segmentation testing — six-monthly for service providers, annual for merchants (Req 11.4) — and MFA for CDE access (Req 8.4) are now fully enforced. First full assessment cycles due 2026.
Cyber Security Act 2024
30 May 2025Major retailers and hospitality operators over $3M turnover, or with critical infrastructure responsibilities, must report ransomware payments within 72 hours. Security standards for smart devices apply to the connected products operators deploy — IoT-enabled POS terminals, self-checkout systems, and smart locks.
New Franchise Code of Conduct
1 Apr 2025Effective 1 April 2025, the remade Franchising Code tightens franchisor disclosure obligations. Franchise networks remain squarely subject to the Privacy Act — franchisors managing shared customer and franchisee data carry the APP 11 security obligation across the network.
SOCI Act — Food and grocery critical infrastructure
In effectFood and grocery retail is designated a critical infrastructure sector. Major food and grocery retailers such as Woolworths and Coles fall under SOCI scope with mandatory Risk Management Programs and annual compliance reporting.
Find your organisation
See how the changes affect you specifically
Major retail chains
Woolworths, Coles, JB Hi-Fi, Myer, Harvey Norman — tier-1 retailers with dedicated security teams and PCI compliance programmes; food and grocery operators carry SOCI Act obligations on top.
View details →Franchise networks
McDonald's, Domino's, KFC, Hungry Jack's — franchise operators where shared POS and payment systems create aggregate attack surface across hundreds of locations.
View details →Hospitality chains
Accor, IHG, Marriott AU, Crown Resorts, Star Entertainment, ALH Group — operators where guest WiFi, PMS, and payment systems often share network infrastructure.
View details →The only autonomous pentesting platform that is:
Prove your CDE isolation before your 2026 PCI assessment
See how NodeZero delivers PCI DSS v4.0.1 compliance for your retail or hospitality environment


