Summary is AI-generated, newsdesk-reviewed
  • 64% of retailers face threats from mass fake account creation and account takeovers.
  • Most e-commerce sites lack multi-factor authentication and effective bot detection layers.
  • Retailers should block disposable emails and implement account lockout to thwart these threats.

As the e-commerce landscape increasingly embraces automation, retailers are facing new security challenges. The rise of AI agents that facilitate shopping tasks also opens the door for potential misuse by cybercriminals.

The upcoming Black Friday period is expected to highlight these challenges, as retailers must differentiate between legitimate AI-driven interactions and malicious automated threats.

Identity Verification Challenges Amid Automation

Both legitimate agents and malicious entities often follow similar paths for account creation and login

Verification at the account level is becoming more critical as automation grows. Both legitimate agents and malicious entities often follow similar paths for account creation and login, complicating the detection of fraudulent activities. 

According to a recent assessment, 64% of retailers are vulnerable to fake account creation, and more than half lack sufficient protection against account takeover attacks.

Persistent Vulnerabilities: Real Consequences

Many vulnerabilities identified in previous assessments remain unaddressed, resulting in issues such as stolen accounts and drained gift cards. Shoppers now face additional challenges as they compete with bots for holiday deals.

Recent findings from DataDome Advanced Threat Research reveal significant security gaps in several major e-commerce platforms, making them susceptible to automated account abuse.

Findings from DataDome Research

DataDome's research, led using open-source bot frameworks, evaluated 11 major e-commerce sites

DataDome's research, conducted using open-source bot frameworks, evaluated 11 major e-commerce sites, uncovering troubling security deficiencies.

These include the widespread ease of creating fake accounts, with 64% of retailers vulnerable and 73% accepting disposable emails. Only 27% of retailers effectively block automated account creation, and 36% lack multi-factor authentication.

Login Protection Concerns

Security lapses extend to the login processes, where 82% of platforms permit automated login attempts without challenge and 64% lack account lockout measures, leaving them exposed to credential stuffing attacks.

This environment allows AI-driven attackers to operate seamlessly, posing a significant risk of large-scale account breaches.

Impacts and Risks

The financial implications can be severe, with potential losses ranging from $50,000 to $500,000 per fraudulent campaign

Fake account creation is a critical threat, especially as Black Friday approaches. Attackers use disposable emails and simple aliasing methods to generate numerous accounts, bypass purchase limits, hoard inventory, and exploit promotional offers.

The financial implications can be severe, with potential losses ranging from $50,000 to $500,000 per fraudulent campaign.

Credential Stuffing and Account Takeover Threats

Credential stuffing continues to be a covert yet impactful threat. Many retailers fail to enforce lockouts or detect bot logins, aiding attackers in scaling their credential testing efforts.

As AI agents further enhance these attacks, adapting strategies based on platform responses, successful account takeovers become more frequent and damaging.

New Threats in Agentic Commerce

The trend of credential sharing with AI agents is expected to triple account takeover incidents by 2028

The trend of credential sharing with AI agents is expected to triple account takeover incidents by 2028, according to Gartner.

This scenario demands that retailers balance user convenience with stringent control measures, allowing for safe agent interactions without inviting credential abuse.

Mitigation Measures for Black Friday

Despite these challenges, retailers have opportunities to fortify their defenses before the holiday sales begin. Key recommendations include blocking disposable emails, normalizing email configurations, implementing account lockouts, and deploying advanced bot management solutions to handle malicious traffic from AI agents.

The assessment noted that while some retailers have robust security measures, the majority are still vulnerable to automated threats. Black Friday 2025 is predicted to experience widespread fraudulent activities, yet timely action can mitigate these risks. Retailers can resolve critical vulnerabilities swiftly to protect their revenues and maintain customer trust during this peak shopping period.

Learn why leading casinos are upgrading to smarter, faster, and more compliant systems

In case you missed it

Why Open Matters In The Age Of AI
Why Open Matters In The Age Of AI

Artificial intelligence (AI) creates efficiencies throughout various industries, from managing teams to operating businesses. Key outcomes include faster investigations, fewer fals...

What Are Emerging Applications For Physical Security In Transportation?
What Are Emerging Applications For Physical Security In Transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher's Perimeter Solutions With Fortified Partnership
Gallagher's Perimeter Solutions With Fortified Partnership

Global security manufacturer Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years o...