Skip to content
BreachPathAttack Path LibraryStart

Data theft in the Retail sector

How a data theft attack could realistically chain together in a Retail organisation, from initial access to business impact — and exactly what you should test to break the chain.

AdvancedCustom web applications

Web application flaw to cloud credentials

A flaw in an internet-facing custom application is used to reach the workload's identity, harvest cloud credentials, and pivot into the wider cloud account where production data lives.

A flawThe workloadCloud permissionsProduction data
Data theftIntellectual-property theft
IntermediateAWS

AWS access key to data exfiltration

A leaked long-lived AWS access key is used to enumerate the account, escalate through permissive IAM, and read and exfiltrate data from cloud storage and databases.

A leakedPermissions areData is
Data theft
AdvancedOn-premises Active Directory

Supplier account to internal network

A compromised supplier's access is used to enter the organisation through a trusted connection, then to move from the supplier's limited footprint toward internal systems and data.

A supplier'sThe trustedInternal systems
Data theftRansomware
IntermediateSaaS (generic)

SaaS administrator compromise

A phished SaaS administrator identity is used to weaken tenant security settings, establish persistence via integrations, and access or export the customer and business data the platform holds.

A SaaSSecurity isCustomer and
Account takeoverData theft
IntermediateGoogle Workspace

Google Workspace account to data theft

A phished Google Workspace identity is turned into durable access through a third-party app grant, then used to search Drive and Gmail for sensitive material and export it.

A WorkspaceA third-partySensitive data
Data theftAccount takeover
IntermediateCustom web applications

Web skimming to payment fraud

A weakness in an e-commerce site or one of its third-party scripts is used to capture customers' payment details at checkout, which are then used or sold for fraud.

The checkoutPayment detailsStolen card
Payment / invoice fraudData theft
FoundationalSaaS (generic)

SaaS API token to data theft

A leaked API token for a business SaaS platform is used to access its API directly, enumerate what the token can reach, and export data at scale — bypassing the login and its MFA entirely.

A leakedThe token'sData is
Data theft

Why chaining matters here

A scanner might flag each weakness in this environment in isolation. What determines whether data theft is actually achievable is whether those weaknesses — together with identities, trust relationships and gaps in monitoring — can be linked into a working path. That is what a red-team engagement validates, and what these chains are designed to help you scope.