Summary is AI-generated, newsdesk-reviewed
  • 64% of retailers face mass fake account creation; high vulnerability to credential stuffing.
  • 73% of e-commerce sites allow disposable emails, raising security risks this Black Friday.
  • AI-driven fraud poses extensive risks; urgent security upgrades needed before holiday sales.

As the retail sector embraces agentic commerce, AI agents are increasingly facilitating tasks like browsing and purchasing on behalf of users. However, these advancements pose security challenges, as malicious actors exploit similar technologies for fraudulent activities.

This Black Friday, the primary concern is not just the proliferation of bots but discerning genuine agent-driven transactions from harmful automated interactions.

Identity verification in an automated era

Retailers need to be vigilant as paths for account creation and login are exploited by helpful AI agents

Automated interactions complicate identity verification at the account level, where the distinction between legitimate users and malicious entities is crucial. With rising automation, retailers need to be vigilant as paths for account creation and login are exploited both by helpful AI agents and harmful bots. 

According to a 2025 assessment, 64% of retailers remain at risk of fake account creation, and over half face account takeover threats due to insufficient login protection.

Security holes in retail platforms

Persistent vulnerabilities have resulted in increased incidences of stolen accounts and drained gift cards, putting real shoppers at a disadvantage during peak shopping times such as the holiday season.

DataDome Advanced Threat Research tested security measures at 11 major e-commerce sites and found significant vulnerabilities to bot-driven account abuses.

Fake account creation and login protection

DataDome's findings highlighted the ease of fake account creation, with 64% of retailers at risk

DataDome's findings highlighted the ease of fake account creation, with 64% of retailers at risk. Additionally, 73% of platforms accept disposable emails, facilitating the creation of unlimited fake accounts. Only 27% effectively block bot-driven account creation, while 36% lack multi-factor authentication (MFA), leaving them vulnerable.

Concerns also extend to login protection, with 82% of retailers permitting automated login attempts without challenge and 64% lacking account lockout controls, making them susceptible to credential stuffing attacks.

Potential risks and implications

Mass fake account creation remains a major threat as the holiday shopping season approaches. Attackers utilise disposable emails and other techniques to generate numerous accounts, bypassing verification processes.

These accounts are then used to exploit purchase limits and promotions. Credential stuffing poses another significant risk, with attackers quietly testing stolen credentials at scale. As AI agents become adept at mimicking human interactions, the risk of account takeovers increases.

Gartner predicts that 90% of organisations permitting credential sharing with AI agents will experience a tripling of account takeover incidents by 2028. Retailers face the challenge of balancing user convenience with robust security measures to protect against such fraud.

Strategic recommendations

Deploying a robust bot control solution can also help identify and block refined, malicious traffic

Urgent action is needed before Black Friday. Retailers can strengthen security by blocking disposable email domains, implementing email normalisation to prevent multiple account abuses, and enforcing account lockouts after repeated failed login attempts.

Deploying a robust bot management solution can also help identify and block sophisticated, malicious traffic.

Industry-wide vulnerability

The e-commerce industry exhibits concerning levels of vulnerability to automated account abuses, with 64% of platforms not meeting basic security standards. In some cases, 18% of retailers lack even the most fundamental protections.

As Black Friday 2025 approaches, the potential for widespread fraud looms large, with risks ranging from fake accounts to large-scale account takeovers.

However, by addressing critical vulnerabilities within a short timeframe, retailers can safeguard their revenue and maintain consumer trust, staying ahead of AI-driven threats in this crucial sales period.

Learn why leading casinos are upgrading to smarter, faster, and more compliant systems

In case you missed it

What are emerging applications for physical security in transportation?
What are emerging applications for physical security in transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher & Fortified enhance perimeter security solutions
Gallagher & Fortified enhance perimeter security solutions

Global security manufacturer - Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years...

Genetec: Data sovereignty in physical security
Genetec: Data sovereignty in physical security

Genetec Inc., the global pioneer in enterprise physical security software, highlights why data sovereignty has become a central concern for physical security leaders as more survei...