Surveys

Report: US Retailers Are Top Targets for Data Breaches

SurveysAug 02, 2018

Report: US Retailers Are Top Targets for Data Breaches

According to the 2018 Thales Data Threat Report, U.S. retailers experienced twice as many IT security breaches than other retailers worldwide last year.

New York—A new report says that retailers in the United States are experiencing the most IT security breaches worldwide.

The retail edition of the 2018 Thales Data Threat Report based its findings on input from 100 senior retail IT security managers in the U.S. and 96 IT security managers from retailers in other countries to establish the state of IT security today.

It found that despite an increase in IT security spending—84 percent of U.S. retailers polled plan on upping their budgets this year, compared to 77 percent last year and 67 percent of international retailers this year—cyber-attackers are by and large staying one step ahead of companies.

Fifty percent of U.S. retailers surveyed said they experienced IT security breaches last year alone, compared to 19 percent in the 2017 report. Only 27 percent of global retailers, meanwhile, said they experienced a breach last year.

RELATED CONTENT: Saks, Lord & Taylor the Latest Hit by Hackers
Seventy-five percent of the respondents in the U.S. said they’ve experienced at least one breach, while 60 percent of global retailers said the same.

The retail industry, which is becoming increasingly digital, is a target for cyber attackers due to its high volume of credit card transactions. In fact, Thales says that overall, it’s the second most breached industry in the United States behind the federal government.

The results of the Thales study on IT security in retail mirror what the Jewelers Security Alliance found in its 2017 crime report. The JSA saw such a large uptick in cybercrime last year that for the first time ever, it broke the losses out separately.

The average dollar loss from cybercrime in the jewelry industry was $1.2 million last year, with JSA President John J. Kennedy calling it a “dangerous and growing crime trend.”

A Bad Investment

Despite the uptick in IT security budgets, the Thales report concluded that retailers are putting their money in places that even they recognize to be ineffective. what they themselves deem the most ineffective places.

Of available tools to battle security breaches, 91 percent of U.S. retailers said analysis and correlation tools are the most effective and 90 percent said data-in-motion— providing security for an e-mail in transit while it’s being sent, for example—is the second most effective weapon.

However, they indicated that their highest spending increases would go to endpoint/mobile defenses (77 percent), even though
they ranked this as the least effective security method. Only 57 percent of retailers plan to increase the budget for data-at rest (stored data) defense, and only 62 percent for data-in-motion defenses, despite these being more effective.
RELATED CONTENT: JSA: Smash-and-Grab Robberies, Cybercrime Up in 2017
“Traditional endpoint and network security are no longer sufficient, particularly for heavy adopters of public cloud resources such as the U.S. retail sector,” the report said, especially with the expanding use of external cloud services like SaaS (software as a service), PaaS (platform as a service) and IaaS (infrastructure as a service).

Where the Money Should Go

 Thales asserts that tools like discovery/classification and encryption or tokenization are key to protecting against IT security breaches today.

Only 26 percent of U.S. retailers polled said they are implementing encryption in the cloud, compared with 30 percent of global retailers.

Fifty-two percent of U.S. respondents cited a lack of perceived need as the top reason for not devoting more resources to tools like encryption and tokenization, while 47 percent also cited impact on business performance and 46 percent were put off by its complexity.

In a past interview with National Jeweler, Kennedy offered a list of cybersecurity recommendations for jewelers specifically, some of which might involve hiring an IT firm.

They include: proper firewalls, up-to-date anti-virus software, the avoidance of “risky” internet sites and the training of staff on the types of mistakes that often let in hackers.

Staff need to be told, or reminded, not to open or click into unknown or suspicious emails, and to look carefully at emails from known parties for misspellings and other anomalies as emails addressed can be spoofed.

Thales said that retailers should “re-prioritize” their IT security toolsets, focusing on ones that offer service-based deployments, platforms and automation to reduce complexity while adding protection.

It also recommended that retailers go beyond national and international compliance measures and employ security tools like encryption and tokenization. Encryption needs to be applied to all platforms, not just desktop and laptop computers.

Specifically, Thales recommends encrypting the cloud, big data, data located within containers and IoT (interconnected devices with IP addresses).

It’s likely that compliance guidelines will one day mandate these practices, the report said, so retailers can benefit from getting a head start on them, hopefully avoiding data breaches in the process.
Ashley Davisis the senior editor, fashion at National Jeweler, covering all things related to design, style and trends.

The Latest

Gemist new retailer offering
TechnologyMay 01, 2026
Gemist, Saban Onyx Partner on Retailer-Focused Customization Offering

Their partnership combines Gemist’s customization technology with Saban Onyx’s U.S.-based manufacturing capabilities.

Tiffany & Co. Blue Book 2026: Hidden Garden Butterfly Diamond Necklace
CollectionsMay 01, 2026
A ‘Hidden Garden’ Emerges in Tiffany & Co.’s 2026 Blue Book

Our Piece of the Week, the “Butterfly” necklace, showcases a 7.02-carat oval diamond set between diamond, platinum, and 18-karat gold wings.

The Retail Smiths partner and National Jeweler columnist Peter Smith
ColumnistsApr 30, 2026
Peter Smith: A Sleazy Salesman and the Case for Regret Avoidance

Smith uses a comment he overheard in the grocery store to remind retailers that their job is to inspire buying behavior, not just sell.

Antique Jewelry & Watch Show
Brought to you by
Discover Timeless Treasures: A Showcase of Antique Jewelry & Timepieces in Las Vegas

Gain access to the most exclusive and coveted antique pieces from trusted dealers during Las Vegas Jewelry Week.

Claire’s new summer campaign
MajorsApr 30, 2026
Claire’s New Summer Campaign Is a Sensory Wonderland for Gen Alpha

“A Girl SMR at Claire’s” celebrates girlhood through the five senses with stacked jewelry, slime toys, scented accessories, and ASMR.

Weekly QuizApr 30, 2026
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Cartier London Crash Watch
AuctionsApr 30, 2026
Vintage Cartier Watch Crashes Through Records, Selling for $2M

Believed to be one of three made in 1987, the Cartier London Crash was hot at the “Shapes of Cartier” sale at Sotheby’s Hong Kong.

Police cars
CrimeApr 30, 2026
Masked Group Uses Hammers, Pepper Spray in Texas Jewelry Store Robbery

Officials are looking for a group that robbed Marc Robinson Jewelers at an outlet mall in Round Rock, Texas, in broad daylight on April 21.

lvajws image 1.jpg
Brought to you by
Las Vegas Antique Jewelry & Watch Show: Showcasing the Most Collectible Merchandise from Across the Globe

Gain access to the most exclusive and coveted antique pieces from trusted dealers during Las Vegas Jewelry Week.

OAR26_NJ_bulletin_1872x1052_01.jpg
Supplier BulletinApr 30, 2026
OROAREZZO 2026: The B2B Event for Italian Excellence in Goldsmith, Jewelry and Silver Manufacturing

Sponsored by OROAREZZO International Jewelry Exhibition

Tiffany & Co. Mother’s Day email opt out
TechnologyApr 29, 2026
The Thought Process Behind the Mother's Day Email Opt-Out

Some retailers are taking a nuanced approach to marketing what can be a difficult holiday for many.

Dick Abbott
IndependentsApr 29, 2026
Dick Abbott to Retire From The Edge

The Edge has announced its new CEO, as well as a new partnership with an investment firm focused on founder-led software businesses.

The Venetia Diamond Mine in South Africa
SourcingApr 29, 2026
De Beers’ Production Rises, Market Remains ‘Challenged’

De Beers’ diamond production was up 17 percent in Q1, boosted by increased output at its mines in South Africa and Canada.

John Wayne Signet Ring
AuctionsApr 29, 2026
This'll Be the Day You Own John Wayne's Ring

A signet ring belonging to the Western film star of Hollywood’s Golden Age will be up for auction at Elmwood’s next month.

Stock image of money
Policies & IssuesApr 28, 2026
Tariff Refunds: How to File, What to Expect

Importers can submit claims now to receive money back for the IEEPA tariffs they’ve paid, with refunds expected to take up to 90 days.

Gregory's Jewelers storefront
IndependentsApr 28, 2026
This North Carolina Jeweler Is Passing the Torch

The owners of Gregory Jewelers in Morganton, North Carolina, are heading into retirement.

Doug Hucker
SourcingApr 28, 2026
Doug Hucker Retires From ICA

The colored gemstone industry leader is heading into retirement after four years as the association’s CEO.

Natural Diamond Council Chief Marketing Officer Susie Dewey
SourcingApr 28, 2026
NDC Hires Tapestry Exec to Head Global Marketing

Susie Dewey joins the Natural Diamond Council as its new chief marketing officer.

The Ocean Dream diamond
AuctionsApr 27, 2026
12 Years Later, the ‘Ocean Dream’ Diamond Resurfaces at Christie’s

The largest known fancy vivid blue-green diamond could fetch more than $12 million at its second auction appearance.

Smart Age Solutions CEO and National Jeweler columnist Emmanuel Raheb
ColumnistsApr 27, 2026
Stop Treating Mother’s Day Like an Afterthought

Emmanuel Raheb says jewelers need to start marketing early and make it easy for customers to pick a gift for mom.

Longnecker Jewelry storefront
IndependentsApr 27, 2026
Longnecker Jewelry Celebrates 30 Years

In honor of the milestone, the Nebraska jeweler has debuted Leslie & Co., its new in-house jewelry brand.

Jeff Corey
MajorsApr 27, 2026
JBT Re-Elects Jeff Corey as Board Chair

The trade organization, which held its annual elections earlier this year, also added five new board members.

TwentyFour Vault Locket
TechnologyApr 24, 2026
TwentyFour’s Digital-Age Locket Is a Virtual Vault

The “Vault” charm, our Piece of the Week, expands on the memories that can be stored in a locket by connecting to your phone.

Hamptons Jewelry Show exhibitors Maison Mèrenor, Jochen Leën, Studio Javo
Events & AwardsApr 24, 2026
Hamptons Jewelry Show to Return in July

The open-to-the-public luxury jewelry and timepiece show, in its second year, is slated for July 23-26.

Photos from Day’s Jewelers 2025 Mother’s Day campaign
IndependentsApr 23, 2026
Meet the Real Moms of Day’s Jewelers

The jeweler’s Mother’s Day campaign highlights the women who work there—mothers, grandmothers, women who want to be mothers, and dog moms.

National Jeweler - Supplier Bulletin - April 2026 - JMSS Graphic.jpg
Supplier BulletinApr 23, 2026
JM® Shipping Solution: Smarter Shipping for High-Value Goods

Sponsored by Jewelers Mutual

Woman wearing Charles & Colvard lab grown diamond jewelry
Lab-GrownApr 23, 2026
Charles & Colvard May Sell Assets for $1.5M

The proposed agreement follows the moissanite maker’s Chapter 11 bankruptcy protection filing last month.

John Jacob Astor IV’s Titanic pocket watch and a gold pencil case
AuctionsApr 23, 2026
John Jacob Astor IV’s Titanic Pocket Watch Fetches $1M

The Patek Philippe for Tiffany & Co. timepiece Astor brought aboard the ill-fated ship sold for double its estimate at a Freeman’s auction.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy