Reflections: How to Stay Safe from Cybercrime This Season

A look at common attacks during the year’s busiest shopping period, and smart countermeasures you can take to protect your data.
Jennifer Mulvihill portrait image

When jewelers think about holiday security preparation, their minds may go first to the sales floor: distraction thefts, grab-and-runs, and shoplifting during the busiest weeks of the year. Those risks are real and well-documented. But while retailers are watching the showcases, another category of criminals is watching the inbox, the website and the shipping process – and these criminals never even have to walk through the door.

The holiday season is peak season for cybercrime against jewelers for the same reasons it is peak season for physical crime: transaction volume surges, seasonal and part-time staff are on the floor, everyone is moving quickly, and the shipping pipeline is full of high-value packages. Retail cyberattacks rose 56% globally in 2025, driven largely by phishing and AI-assisted scams, and roughly 60% of all breaches involve a human element – an individual clicking, answering or trusting when they should not.

Why jewelers are a prime target 

Cybercriminals target jewelers because of the data we hold – quite literally, our crown jewels. Customer records reveal not only personally identifiable information, but wealth status and spending habits: purchase histories, appraisal records, custom order details, and financing information. On the dark web, a single record from a luxury client may sell for $25 or more, and a full identification package – name, Social Security number, government ID, address – can command $100 to $200. A hacked database of wealthy clients can sell for thousands of dollars.

Criminals also understand that jewelers depend on trust and discretion, making them more likely to pay to keep customer information private. Many jewelers are family-owned small businesses without dedicated IT staff. Nearly half of small businesses reported a ransomware attack in the past year, and only 8% of those that paid a ransom actually recovered all of their data.

Understanding the threats 

▪ Social engineering is the umbrella term for attacks that manipulate people rather than technology. Instead of breaking through a firewall or smashing a showcase, the attacker persuades an employee to open the door – by impersonating a bank, a vendor, a shipping company, or even a colleague. Phishing, the most common form of this attack, is a fraudulent message designed to induce the recipient to click a malicious link, open an infected attachment, or surrender credentials. It now arrives through every channel: email, phone calls (“vishing”), text messages (“smishing”), and QR codes (“quishing”). Holiday-themed variants are especially dangerous; fraudulent “delivery update” texts are engineered to get people to click during a season when everyone is genuinely expecting – and looking forward to – the delivery of packages, and a busy December inbox gets skimmed, not read carefully.

Ransomware is another type of attack that is both frequent and severe: malicious software that encrypts a business’s systems and data, rendering them inaccessible until the business pays a ransom, usually in the form of cryptocurrency. In practice, an attack often begins with a successful phishing message or stolen credentials; the intruder may then move quietly through the network for weeks before locking systems. Increasingly, attackers also exfiltrate, or leak, data first and threaten to publish it on the dark web – a tactic known as double extortion – which is particularly devastating in a trust-dependent business. The reputational damage to luxury brands is measurable and can result in lost sales. A ransomware event typically looks like this: Point-of-sale terminals freeze, files become unreadable, a ransom note appears on screens, and the e-commerce site goes dark, often during the highest-revenue weeks of the year.

Distributed denial of service (DDoS) attacks take a different approach: Rather than stealing data, attackers flood a website with artificial traffic from thousands of compromised devices – now with augmentation from AI – until it slows or crashes entirely. For a jeweler, a DDoS attack during the holiday rush means legitimate customers cannot browse, purchase, or reach the store online.

Shipping fraud is a holiday hazard that sits at the intersection of the website and the shipping department – the crossover between a cyberattack and physical harm. Criminals use stolen customer identities and payment credentials to place legitimate-looking orders, then log into the account afterward to change the delivery address or intercept the package in transit. Others exploit the chargeback process, disputing charges on merchandise they’ve received and kept. During the holiday shipping crush, these schemes hide easily amid the volume.

Best practices: Building a culture of prevention 

Cybersecurity does not necessarily require a large budget; it requires a plan and a culture. Six practices form the foundation:

1. Train continuously – in store and online. Because the majority of breaches involve a human element, employees are both the greatest vulnerability and the strongest defense. Conduct in-store training so staff can recognize suspicious behavior at the counter and on the phone, and enroll every employee – including seasonal hires, before they touch your systems – in an online security awareness platform with simulated phishing exercises.

2. Implement multi-factor authentication (MFA) on every email, banking and business account. MFA requires a second form of verification beyond a password, meaning stolen credentials alone are no longer enough to grant access, and attacks cannot be launched solely with stolen passwords.

3. Maintain regular backups of critical data, storing them offline or in a secure cloud environment, and test them periodically. Reliable backups are the single most effective defense against ransomware, allowing a business to restore operations without having to pay a criminal.

4. Enforce strong password policies: unique, complex passwords for every account, no password reuse across systems, and prompt deactivation of credentials when employees – both seasonal and permanent – have left the company.

5. Secure the online-ordering and shipping process. Require address verification service (AVS) and card verification value (CVV) matching. Set the payment processor to decline mismatches, and flag orders where billing and shipping addresses differ. Scrutinize expedited shipping requests and unusual email domains, require a signature on delivery above a set dollar threshold, photograph merchandise with a timestamp before it ships, insure your shipments, and consider smart tags for high-value packages.

6. Develop partnerships with state, local and federal law enforcement before an incident occurs. Knowing whom to call – and having an existing relationship – dramatically shortens response time. Report every incident. Reporting protects not only your business, but the industry as a whole.

The average retail data breach now costs $3.5 million – a loss no showcase alarm can prevent. This holiday season, protect your showcases and your firewalls alike. Your inventory is no longer only in the safe; it is in your data, and criminals know it.

Jennifer Mulvihill is president of the Jewelers Security Alliance (JSA).

Main image: Jennifer Mulvihill. (Jewelers Security Alliance)

Thank You for Reading RAPAPORT Magazine

Reflections: How to Stay Safe from Cybercrime This Season

More From RAPAPORT Magazine

Featured