Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsCequence Security data, as reported by BetaNews on March 28, 2025, attributed 66.5% of the malicious traffic in the company’s platform data to retailers. That is a vendor-telemetry figure—not a measure of all malicious traffic on the internet, all attacks against retailers, or a verified industry-wide share. The report’s reference to the PCI DSS 4.0 deadline is now historical: the transition dates it discusses have passed.
What percentage of malicious traffic targets retailers?
The figure is 66.5% in Cequence Security platform data, according to BetaNews’s March 28, 2025 report. The source does not establish the platform’s sample period, geography, full methodology, or whether the data were independently audited. Treat the number as a description of the traffic Cequence observed, not as a statistical estimate for the retail industry or the internet as a whole.
BetaNews also reported these Cequence platform totals. They are blocked attempts reported by the vendor, not estimates of all global attack activity:
- More than 300 million account-takeover attempts blocked during the preceding year.
- 822 million product-search and pricing-abuse attempts blocked.
- More than 22 million fraudulent loyalty attempts blocked.
- More than 69 million attempts to test stolen payment-card details blocked.
- Among non-account-takeover bot-driven attacks, 89% focused on product-pricing scraping.
The figures illustrate the variety of automated abuse a retailer may encounter—credential attacks, loyalty fraud, card testing, and scraping—but they do not show how common each activity is across all retailers.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
What attacks can target retail websites and APIs?
Retailers rely on websites and APIs for sign-in, product searches, pricing, loyalty accounts, and checkout. Automated requests can abuse those functions in ways that affect both security and business operations. The reported examples include:
- Account takeover: attempts to use stolen or reused credentials to access customer accounts.
- Card testing: attempts to check whether stolen payment-card details work, often by submitting transactions.
- Loyalty fraud: attempts to access or misuse rewards accounts and balances.
- Product and price scraping: automated collection of catalog, availability, or pricing information.
Blocking suspicious traffic is only one part of the response. Retailers should evaluate whether their controls cover both web applications and APIs, detect automated abuse as well as business-logic attacks, and integrate with the systems that handle identity, checkout, and monitoring. These are assessment questions, not a ranking of products or proof that any one tool prevents every attack.
What does PCI DSS require, and who determines compliance?
The PCI Security Standards Council describes PCI DSS as a global baseline of technical and operational requirements intended to protect payment account data. Its audience includes merchants and other entities that store, process, or transmit cardholder data or sensitive authentication data, as well as entities that can affect the security of the cardholder data environment. See the Council’s official PCI DSS resource.
PCI DSS is an industry standard, not legislation. Whether an entity must comply or validate compliance is determined by the organizations that administer compliance programs, such as payment brands or acquirers. Retailers should confirm their applicable requirements and validation route with their acquirer or relevant compliance program.
Rank #3
What changed with PCI DSS 4.0, and is the deadline still ahead?
No. The transition dates cited in the 2025 coverage have passed, so the old “ahead of the deadline” framing should not be read as a current countdown. Cequence’s April 4, 2025 article says PCI DSS v4.0.1 was published in June 2024, v4.0 was retired on December 31, 2024, and v4.0.1 took full effect on April 1, 2025. Those timeline details come from a vendor-authored article, Cequence’s explanation of PCI DSS 4.0.1 and API security. For present-day requirements, consult the PCI SSC document library and official FAQs rather than relying on an older deadline summary.
Cequence’s article discusses Requirement 6.4.2 and an automated technical solution for continual detection and prevention of web-based attacks, including API-related considerations. That is Cequence’s interpretation in a vendor-authored article; the requirement should be checked against the applicable PCI DSS text and assessment guidance. Buying API security or bot-management software on its own does not make a retailer PCI DSS compliant.
Rank #4
How should a retailer act on the threat data?
Use the reported attack categories to guide a review of controls, not as a substitute for a scoped assessment. A practical review can ask:
- Do protections cover the retailer’s web applications and APIs, including sign-in, loyalty, search, and payment-related flows?
- Can monitoring distinguish abusive automation from legitimate customer activity while accounting for business-logic abuse?
- Do the controls fit the retailer’s architecture and integrate with relevant identity, payment, and incident-response processes?
- How does each control map to the assessed PCI DSS scope and the retailer’s validation obligations?
The PCI SSC lists Qualified Security Assessors (QSAs), which are qualified to perform PCI DSS assessments, and Approved Scanning Vendors (ASVs), which perform external vulnerability scanning. Confirm with the acquirer or compliance program which validation steps apply; the right route depends on the entity and its obligations.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




