Every year, the holiday season brings a predictable surge in online activity. But in 2025, the volume of new malicious infrastructure, account compromise activity, and targeted exploitation of e-commerce systems will be significantly higher. Attackers began preparing months in advance, leveraging tools and services that enable them to scale attacks across multiple platforms, geographies, and merchant categories.
For retailers, financial institutions, and any business operating an e-commerce infrastructure, the threat landscape has never been more active. This year’s increase in online shopping, digital payments, and promotional events creates an environment ripe for aggressive exploitation by malicious actors.
Fortinet’s FortiGuard Labs threat team analyzed data from the last three months to identify the most significant patterns shaping the threat landscape for the 2025 holiday season. The findings reveal a clear trend: attackers are moving faster, automating more, and capitalizing fully on holiday shopping.
The rapid expansion of malicious infrastructure with a Christmas theme
One of the key indicators of attackers’ pre-Christmas activity is domain registration. FortiGuard identified more than 18,000 Christmas-themed domains registered in the last three months, including terms such as “Christmas,” “Black Friday,” and “flash sales.” At least 750 of these were identified as malicious. This indicates that many domains are still considered non-malicious, representing a potential risk.
There was a parallel increase among domains imitating major retail brands. Attackers registered more than 19,000 e-commerce-themed domains, of which 2,900 were malicious. Many mimic well-known names, often with slight variations that are easy to overlook when shoppers are moving quickly. These domains facilitate phishing, fraudulent stores, gift card scams, and payment harvesting strategies.
A record volume of stolen account data encourages credential abuse
The report also shows a notable increase in the availability and use of identity theft records. Over the past three months, more than 1.57 million login accounts linked to major e-commerce sites, accessible through these records, were collected on underground markets. These records contain browser-stored passwords, cookies, session tokens, autofill data, and fingerprints.
Criminal markets now include these records with search filters, reputation scores, and automated delivery systems. This significantly lowers the skill barrier for attackers, enabling credential theft, account hijacking, and unauthorized purchases to happen quickly.
Dark markets show a clear increase in listings linked to e-commerce breaches, and the scale reflects the organization of these operations. As the holiday season brings higher transaction volumes and faster purchasing behavior, compromised accounts move quickly on these markets. Stolen sessions with active purchase histories are especially valuable, as they closely resemble legitimate user activity and are much more difficult to detect in real time.
What can you do? Best practices
A few practical steps, implemented in advance, can significantly reduce the risk of fraud, account theft, and payment page compromise. The following best practices highlight what organizations and consumers can do to stay protected from the most common threats during the 2025 holiday shopping season.
Best practices for organizations
• Keep all e-commerce platforms, plugins, and third-party integrations up to date and remove any that are not being used.
• Strengthen HTTPS everywhere, and secure cookie sessions, administrative pages, and payment flows.
• Require multi-factor authentication (MFA) on high-risk administrative accounts and enforce strong password policies.
• Use bot management, rate limiting, and anomaly detection tools to reduce credential abuse.
• Monitor for spoofed domains that attempt to impersonate brands and act quickly to take them down.
• Search for unauthorized code changes and deploy controls to detect tampering with payment pages or skimmers.
• Centralize logging to monitor suspicious administrative actions, session hijacking, or unusual database access.
• Ensure that your fraud, security, and customer service teams follow a shared cyber event escalation path during the holiday season.
Best practices for end users
• Carefully check website URLs before entering login details or payment information.
• Use trusted credit cards or payment processors that offer fraud protection.
• Enable multi-factor authentication for purchases, email, and bank accounts.
• Avoid using public Wi-Fi networks or use a VPN when making purchases or financial transactions.
• Be wary of unsolicited messages or unrealistic promotions, particularly those related to deliveries or discounts.
• Check bank or card statements regularly to detect any unauthorized charges in a timely manner.


