Summary is AI-generated, newsdesk-reviewed
  • 64% of retailers face threats from mass fake account creation and account takeovers.
  • Most e-commerce sites lack multi-factor authentication and effective bot detection layers.
  • Retailers should block disposable emails and implement account lockout to thwart these threats.

As the e-commerce landscape increasingly embraces automation, retailers are facing new security challenges. The rise of AI agents that facilitate shopping tasks also opens the door for potential misuse by cybercriminals.

The upcoming Black Friday period is expected to highlight these challenges, as retailers must differentiate between legitimate AI-driven interactions and malicious automated threats.

Identity Verification Challenges Amid Automation

Both legitimate agents and malicious entities often follow similar paths for account creation and login

Verification at the account level is becoming more critical as automation grows. Both legitimate agents and malicious entities often follow similar paths for account creation and login, complicating the detection of fraudulent activities. 

According to a recent assessment, 64% of retailers are vulnerable to fake account creation, and more than half lack sufficient protection against account takeover attacks.

Persistent Vulnerabilities: Real Consequences

Many vulnerabilities identified in previous assessments remain unaddressed, resulting in issues such as stolen accounts and drained gift cards. Shoppers now face additional challenges as they compete with bots for holiday deals.

Recent findings from DataDome Advanced Threat Research reveal significant security gaps in several major e-commerce platforms, making them susceptible to automated account abuse.

Findings from DataDome Research

DataDome's research, led using open-source bot frameworks, evaluated 11 major e-commerce sites

DataDome's research, conducted using open-source bot frameworks, evaluated 11 major e-commerce sites, uncovering troubling security deficiencies.

These include the widespread ease of creating fake accounts, with 64% of retailers vulnerable and 73% accepting disposable emails. Only 27% of retailers effectively block automated account creation, and 36% lack multi-factor authentication.

Login Protection Concerns

Security lapses extend to the login processes, where 82% of platforms permit automated login attempts without challenge and 64% lack account lockout measures, leaving them exposed to credential stuffing attacks.

This environment allows AI-driven attackers to operate seamlessly, posing a significant risk of large-scale account breaches.

Impacts and Risks

The financial implications can be severe, with potential losses ranging from $50,000 to $500,000 per fraudulent campaign

Fake account creation is a critical threat, especially as Black Friday approaches. Attackers use disposable emails and simple aliasing methods to generate numerous accounts, bypass purchase limits, hoard inventory, and exploit promotional offers.

The financial implications can be severe, with potential losses ranging from $50,000 to $500,000 per fraudulent campaign.

Credential Stuffing and Account Takeover Threats

Credential stuffing continues to be a covert yet impactful threat. Many retailers fail to enforce lockouts or detect bot logins, aiding attackers in scaling their credential testing efforts.

As AI agents further enhance these attacks, adapting strategies based on platform responses, successful account takeovers become more frequent and damaging.

New Threats in Agentic Commerce

The trend of credential sharing with AI agents is expected to triple account takeover incidents by 2028

The trend of credential sharing with AI agents is expected to triple account takeover incidents by 2028, according to Gartner.

This scenario demands that retailers balance user convenience with stringent control measures, allowing for safe agent interactions without inviting credential abuse.

Mitigation Measures for Black Friday

Despite these challenges, retailers have opportunities to fortify their defenses before the holiday sales begin. Key recommendations include blocking disposable emails, normalizing email configurations, implementing account lockouts, and deploying advanced bot management solutions to handle malicious traffic from AI agents.

The assessment noted that while some retailers have robust security measures, the majority are still vulnerable to automated threats. Black Friday 2025 is predicted to experience widespread fraudulent activities, yet timely action can mitigate these risks. Retailers can resolve critical vulnerabilities swiftly to protect their revenues and maintain customer trust during this peak shopping period.

In case you missed it

Enhancing Security At Lincoln's Inn With KeyWatcher
Enhancing Security At Lincoln's Inn With KeyWatcher

The Honourable Society of Lincoln’s Inn is one of the four Inns of Court and operates as an active and thriving society of lawyers, sprawling across 11 acres in central Londo...

How Are New Technologies Reshaping Casino Surveillance And Security?
How Are New Technologies Reshaping Casino Surveillance And Security?

Casinos are tasked with monitoring vast gaming floors, cashier cages, and access points. The market for casino security and surveillance demands software and hardware that provide...

ASSA ABLOY Showcases At GSX 2026 In Atlanta
ASSA ABLOY Showcases At GSX 2026 In Atlanta

ASSA ABLOY will be exhibiting at Global Security Exchange (GSX) 2026 from September 14 - 16 at the Georgia World Congress Center in Atlanta, Georgia. The company invites attendees...