84% of Commerce DDoS Attacks Hit Retail. Is Your Defense Ready? | Steve Winterfeld, Akamai
Watch on YouTubeVideo summary
The transcript highlights that retail commerce is the primary target for application layer DDoS attacks, accounting for a staggering 84% of all such incidents in the sector. Cybercriminal groups are increasingly employing sophisticated multi-vector approaches that combine AI-assisted malware with Internet of Things (IoT) botnets, a tactic referred to as "turbo malware." These evolved attacks have escalated in scale from gigabytes to multiple terabytes, forcing Chief Security Officers to significantly upgrade their defensive capabilities. A key example provided is how everyday devices like refrigerators can be co-opted into massive botnets, allowing attackers to simultaneously target specific commerce sites with unprecedented volume and complexity.
Beyond traditional denial-of-service tactics, the discussion emphasizes a shift toward logic exploits facilitated by generative AI agents. Unlike standard AI models, these agents possess decision-making capabilities that allow them to manipulate systems in novel ways, such as honoring expired promotional codes, authorizing fraudulent returns, or leaking proprietary inventory data. The transcript notes that while vulnerabilities like those seen in "Project Glass Wing" have been identified, they are not yet widely operationalized by criminals; however, the integration of AI introduces new attack surfaces specifically targeting chatbots and autonomous agents used for customer service and transaction processing.
The speaker also addresses the concept of token freeloading within malware, where attackers leverage tokens to bypass security controls and gain persistent access to accounts. This evolution means that threats now extend beyond simple credential theft to include complex fraud enablement and data exfiltration driven by AI-driven decision logic. Although many theoretical vulnerabilities exist, the real danger lies in how these new AI capabilities are being weaponized to disrupt business operations and cause financial loss.
In conclusion, the video urges organizations to look closely at their logs and protective infrastructure to detect these emerging threats before they can be exploited in the wild. While not every identified vulnerability is currently being used by cybercriminals or activists to cause immediate disruption, the landscape is changing rapidly as AI becomes a common vector for exposure. Security teams must adapt their strategies to handle these new logic-based attacks and ensure their defenses are ready for the next generation of commerce-focused cyber threats that blend traditional DDoS methods with advanced artificial intelligence.
Read the full video transcript
Can you also talk about beyond
agentic shoppers uh what other trends
are you seeing like uh DOS uh and uh
other traditional uh attacks as well? Uh
so as you know Agamite does a lot around
DOS protection and so we have a a ton of
insights regional insights industry
insights uh but within commerce retail
accounted for 84% of all commerce
application
layer DOS attacks and so you know there
are groups out there like the Iran Iraq
hackist group 313
that have been really focused on some of
this stuff doing multi vector approach
combining AI assisted Marai uh internet
of things botnet we're calling it turbo
marai uh and there are variants of this
that have have really peaked the old you
know gigabyte to terabyte to multiple
terabyte size attacks and so that's
requiring csos to go reook their
defensive capability ilities with these
new peak capabilities of all internet of
things. So you know this is the classic
uh you know your refrigerator is now
part of a a botn net which is just a
collection of of different systems and
they're all trying to attack one
commerce site at the same time. Um you
know and and we talked a little bit
about there that you know there's AI
capabilities being added in here. I
haven't seen a ton of these in the
wilds. We talk a thing about things like
Project Glass Wing, if you've heard
about that, where they're just stacking
up all these vulnerabilities.
I haven't seen a ton of those
vulnerabilities be operationalized.
So, a lot of them were were real
vulnerabilities, but they haven't been
used in the wild by cyber criminals or
activists to to cause damage or
disruption. And so, you know, we think
about this, but as AI gets in here,
there's this this new vulnerability
areas. A lot of us when you go, there's
a chatbot there. Can I help you? Well,
they're attacking those chat bots. If
there's agents, like let's say you go in
and you want to get a credit card from
your from your shopping store, a lot of
that may now be handled by AI agents to
make those decisions because again, a
Gentic AI is different than your
traditional Gen AI and that it makes
decisions. And then tokens, tokens are
those thing capabilities that let you um
leverage all this. In fact, we have a
section on our malware talking about
token freeloading.
So, you know, all of this is now logic
exploits honoring expired promotional
codes, authorizing fraudulent returns,
leaking proprietary inventory data.
There's a lot of different types of
attacks happening out here with this new
AI capabilities beyond just those
traditional DOS. And then we do a
malware deep dive. You know, we talk
about those traditional traditional
things, credential theft, uh leading to
account takeover,
uh fraud enablement, persistent access,
and AI is a common vulnerability
exposures, numbering authority. So, we
we do a lot of this kind of research,
but we talk in detail about some of this
capability out there and what you should
be looking for within your logs and
within your protective uh organizations
today.