Retail & e-commerce security compliance · IndiaOne incident. Up to 7 clocks.

CERT-In gives you six hours. Your gateway, your marketplace and ONDC start their own clocks — all running at once, and all well inside DPDP’s 72.

Stores

Ransomware stops the supply, not the stores.

Online

Your checkout scripts are now a PCI requirement.

Incident receipt

You noticed it · t = 0

  • CERT-In6 hours

    to CERT-In

  • ONDC6 hours

    to ONDC

  • Payment gateway12–24 hours

    to your payment gateway

  • Marketplace24 hours

    to the marketplace

  • NIS224 hours

    to the national CSIRT (early warning)

  • DPDP72 hours

    to the Data Protection Board

  • GDPR72 hours

    to the EU / UK supervisory authority

Clocks started7

All running at once · filing one discharges none of the others

THANK YOU · KEEP THIS FOR YOUR RUNBOOK

Two kinds of retailer

Stores, online — or both?

Pick one and the rest of the page follows you. Most large retailers are both.

Stores: 20,169 Reliance Retail stores · 963 Zudio stores · 500 DMart stores · 2,455 Domino’s India stores. Online: ~$60bn online retail, 2024 · 270M+ online shoppers · 2,443 Blinkit dark stores · 85.5% of payments by volume on UPI. Company filings and results (Reliance Retail Q1 FY27, Trent FY26, Avenue Supermarts 31 March 2026, Jubilant FoodWorks, Eternal Q1 FY27); Bain & Company with Flipkart, March 2025; RBI Payment System Report, H2 2025.

What binds you?

Free · no email · shareable
  1. 1Where do you sell? — Pick everything that is true
  2. 2How do customers pay? — Most retailers tick more than one
  3. 3Anything else true? — These change the answer

Binds every retailer — before you pick anything

5obligations
2reporting clocks
10controls

The clocks one incident starts

CERT-In · 6 hoursDPDP · 72 hours
Get a shortlist for this profile →

Indicative, based on the published texts as we read them on the dates shown against each obligation. General information, not legal advice — confirm applicability with your counsel.

Threat patterns

How retailers actually get breached

9 patterns, each drawn as the attacker walks it. Every incident is sourced.

The help desk resets the attacker’s password

Stores
  1. Caller poses as staff
  2. Desk resets password + MFA
  3. Ransomware follows
Marks & Spencer (UK)April 2025

Attackers impersonated one of the people who work with M&S and tricked a third party into a reset; online orders stopped for weeks. M&S first guided about £300 million off profit before mitigation and insurance.

Press named its service-desk supplier TCS, which says “no TCS systems or users were compromised”.

UK Parliament evidence; BleepingComputer ↗
+ 2 more cases: Co-op Group (UK), UK NCSC
Co-op Group (UK)April 2025

Data on all 6.5 million members was copied; shutting systems down early prevented encryption but still emptied shelves. Reported to have started with help-desk resets.

BleepingComputer ↗
UK NCSCMay 2025

After the retail attacks, told every organisation to review how its IT help desk authenticates staff before resetting passwords, especially for admins.

NCSC ↗

Ransomware stops the supply, not the stores

Stores
  1. Foothold, then spread
  2. ERP and warehouse encrypted
  3. Supply stops
Raymond LifestyleFebruary 2025

Its exchange filing said store operations were unaffected. Its Q4 FY25 results then attributed part of a ₹45 crore loss to “a ransomware attack that led to system outages and supply chain disruptions”.

IndiaRetailing ↗
+ 2 more cases: Haldiram’s, Mithaas
Haldiram’sOctober 2020

An FIR in Noida records servers encrypted and financial, HR and sales data taken; police said the allegations were found true.

Deccan Herald / PTI ↗
MithaasOctober 2020

A second Noida food-retail chain reported ransomware within two weeks: “complete data has become useless for us”.

Tribune / PTI ↗

A vendor’s remote access becomes POS malware

Stores
  1. Vendor’s remote access
  2. Into store systems
  3. Malware on the tills
Wendy’s (US)2015–16

POS malware at franchised restaurants, installed using “compromised third-party vendor credentials”; company-operated restaurants were not affected.

Wendy’s 8-K ↗
+ 1 more case: Target (US)
Target (US)2013

Attackers used an HVAC contractor’s credentials, moved through the network and put malware on POS systems; 40 million cards were taken.

Dark Reading ↗

An old key or an open bucket, and the customer database walks out

Online
  1. Old key or misconfiguration
  2. Into the data store
  3. Customer data exported
JuspayAugust 2020

“An old unrecycled AWS access key was exploited”; Juspay said 3.5 crore masked-card records were taken from the payments partner of several large merchants.

A researcher put the figure at about 10 crore; Juspay disputed it.

Business Today ↗
+ 3 more cases: RentoMojo, BigBasket, Domino’s India, ABFRL, boAt, Snowflake customers
RentoMojoApril 2023

Its CEO told customers attackers exploited a cloud misconfiguration; the leaked data included government ID and passport numbers.

MediaNama ↗
BigBasket, Domino’s India, ABFRL, boAt2020–2024

Customer databases verified by Have I Been Pwned at 2.45 crore, 2.25 crore, 55 lakh and 75 lakh email addresses. None of the companies disclosed how the attackers got in.

MediaNama (BigBasket) ↗
Snowflake customers2024

About 165 organisations’ data stores were accessed with stolen credentials and no MFA — Advance Auto Parts reported 23 lakh people affected.

Google / Mandiant ↗

Customers’ accounts are taken over and spent

Online
  1. Reused password or fake call
  2. Account taken over
  3. Wallet or BNPL spent
Swiggy customersFebruary 2024

Delhi Police arrested two men who used fake IVR calls to take over accounts and placed ₹97,197 of orders on one victim’s linked BNPL account.

Siasat ↗
+ 2 more cases: Meesho, The North Face (US)
Meesho2024

Its own trust report: 13 lakh bot orders blocked in a year, and nine cases filed for account-takeover fraud.

Outlook Business ↗
The North Face (US)April 2025

VF called it a “small-scale credential stuffing attack”; 2,861 customers’ names, addresses and order histories were visible to the attackers.

Maine Attorney General filing ↗

A script on the checkout page copies every card

Online
  1. Script injected
  2. Checkout input copied
  3. Card data leaves
British Airways (UK)2018; fined 2020

The UK regulator fined BA £20 million after its payment page was skimmed for about 4.3 lakh customers and staff.

The Register ↗
+ 2 more cases: Ticketmaster UK, CosmicSting (Adobe Commerce / Magento)
Ticketmaster UKFined 2020

Fined £1.25 million over a third-party chatbot script on its payment page.

SCL ↗
CosmicSting (Adobe Commerce / Magento)2024

Sansec counted 4,275 online stores hacked through one vulnerability — about 5% of all Adobe Commerce and Magento stores.

Sansec ↗

India: No public Indian web-skimming case found, 2019–2026 — not the same as “it doesn’t happen here”.

Stops itWatch every script on the checkout pageWeb application and API protection, and DDoSPatch what is exposed firstDecide your PCI scope on purpose

Refunds, returns and coupons are farmed

Online
  1. Fake buyers or sellers
  2. False return claims
  3. Refunds drained
Myntra2024

Filed a ₹1.1 crore complaint with Bengaluru police over false “item missing” refund claims on about 5,529 orders.

Business Today ↗
+ 2 more cases: Meesho, Swiggy
Meesho2024

Police arrested a seller and agent who faked buyer accounts and returns to take ₹5.5 crore.

Deccan Herald ↗
SwiggyFebruary 2023

Its IPO document discloses a former employee who gained access to test systems; an FIR was filed.

Storyboard18 (Swiggy DRHP) ↗

A supplier is breached, and your customers or shelves pay

Both
  1. A supplier is breached
  2. Into your data or operations
  3. Orders or data hit
DunzoJuly 2020

The attacker “compromised the servers of a third party that the company works with”; 34.6 lakh email addresses were later verified.

MediaNama ↗
+ 3 more cases: Blue Yonder, UNFI (US), Harrods (UK)
Blue YonderNovember 2024

Ransomware in one supply-chain SaaS provider disrupted Starbucks’ staff scheduling and warehouse systems at UK grocers Morrisons and Sainsbury’s.

CyberScoop ↗
UNFI (US)June 2025

Whole Foods’ main distributor took systems offline and estimated $350–400 million of lost sales.

UNFI results (SEC) ↗
Harrods (UK)September 2025

An external supplier was breached: about 4.3 lakh customers’ loyalty and contact records.

The Register ↗

Fake stores and apps use your name

Both
  1. Fake store or app
  2. Shoppers pay or log in
  3. Money and data lost
CERT-In advisory CIAD-2024-0050October 2024

CERT-In’s festive-season advisory warns of fake e-commerce sites and cash-on-delivery scams run through fake online stores.

CERT-In ↗
+ 1 more case: Meesho
Meesho2024

Its trust report: 130 fake websites and apps and 18,000 fake social-media accounts taken down in a year.

Outlook Business ↗
The bill

What a breach costs a retailer

Seen enough to know where you stand?

A 30-minute call. We come with a vendor-neutral shortlist, priced in INR with GST.

The control map

What you actually have to do

29 controls. Most bind every retailer — the map shows which are only for stores or only for online.

Can’t be bought (8)Every control in detail →
Whatever your size

Five things that bind a single-store retailer too

Cover these five first →
  1. 1Report to CERT-In within six hours
  2. 2Keep 180 days of logs
  3. 3Sync clocks to NIC / NPL time
  4. 4Back up your books daily, in India
  5. 5Never store card numbers
How we help

Send us the security checklist your partner just sent.

Whether you run stores or a checkout, the bar arrives as someone else’s checklist. We turn it into a shortlist.

  1. 01

    You send the checklist you were handed

    A gateway’s security review, a marketplace’s data policy, ONDC’s audit, an insurer’s proposal form.

  2. 02

    We map it to the 29 controls

    Which items you already meet, and which ones you can’t yet.

  3. 03

    You get a shortlist that closes the gaps

    Vendor-neutral, priced in INR with GST, implemented if you want us to.

  • 21/29controls our catalogue answers
  • 170vendors researched
  • 977product pages, limits stated
  • 26obligations, sourced
Map my checklist →
Myths & gaps

What the market gets wrong — and where we are thin

  • “Our e-commerce agency reports the breach, not us.”
    CERT-In: whoever notices it reports it, and the duty is “neither transferrable nor indemnified”.
  • “DPDP is in force now.”
    Only the Board is. The operational duties start on 13 May 2027; Consent Managers on 13 November 2026.
  • “DPDP gives us 72 hours to tell customers.”
    Customers must be told “without delay”. The 72 hours is the detailed report to the Board.
  • “RBI mandates PCI DSS for every merchant.”
    It reaches you through your payment aggregator, which must check your infrastructure — no rule is aimed at merchants directly.
  • “SAQ A means we can ignore checkout scripts.”
    SAQ A dropped 6.4.3 and 11.6.1 but added a test: your site must be protected against script attacks — by you or your provider.
  • “We can store encrypted card numbers.”
    No entity other than issuers and networks may store card data. You may keep the last four digits and the issuer’s name.
All 14 myths, each checked →

Where our catalogue is thin

We’d rather tell you than let a gap look like a recommendation.
Questions people ask

Retail & e-commerce compliance, answered

Short answers, each backed by the source on the obligations page.

If our e-commerce agency or SaaS vendor detects a breach, who reports it to CERT-In?

Whoever notices it. CERT-In's FAQ on its 2022 Directions answers exactly the case of a consumer-facing business and its back-end partner: the duty to report within six hours is neither transferable nor indemnifiable by contract.

How fast must a retailer report a breach to its payment gateway, Amazon or ONDC?

Faster than most expect, and by contract rather than law. Cashfree's merchant terms ask for suspected security events within 12 hours and Razorpay's for breaches within 24; Amazon's seller-API policy wants 24 hours; ONDC's network policy wants 6. CERT-In's own clock is 6 hours. They run in parallel.

Does PCI DSS apply if we use a hosted checkout from Razorpay or Cashfree?

It depends on how the checkout is built. If you redirect shoppers to the gateway's own page, the SAQ A script test does not apply to you. If you embed the gateway's form in an iframe on your page, you are eligible for SAQ A only if your page is protected against script attacks — by you or your provider (PCI SSC FAQ 1588, 2025).

Can we store customers' card numbers for one-click checkout?

No. Since 30 September 2022 the RBI has barred everyone except card issuers and networks from storing card data. A merchant may keep the last four digits and the issuer's name for reconciliation, and use network tokens for saved cards.

When does the DPDP Act start applying to retailers?

The operational duties — notices, security safeguards, breach notification, erasure, children's data — apply from 13 May 2027. Consent Managers start on 13 November 2026. Customers must be told of a breach without delay; the detailed report to the Data Protection Board is due within 72 hours.

What changes for e-commerce on 1 January 2027?

The Consumer Protection (E-Commerce) Amendment Rules 2026 come into force: a yearly dark-pattern self-audit with a certificate displayed on the site, clearly labelled sponsored listings, no manipulated search results, a 30-day prior-price rule for discounts, and — for marketplaces — express consent before using customer data to sell own-brand goods.

Must large e-commerce platforms delete inactive users' data?

Yes, from May 2027, but only e-commerce entities with at least two crore registered users in India, and not marketplace sellers. They must erase a user's data after three years of inactivity, with 48 hours' warning, keeping what is needed for the account and wallet or loyalty balances.

Do retailers need a yearly audit by a CERT-In-empanelled auditor?

Not by law — CERT-In's 2025 audit guidelines are guidance for private companies. But ONDC requires a yearly certificate from an ONDC- or CERT-In-empanelled auditor from its network participants, and payment gateways ask for annual proof of PCI DSS compliance.

Where software is the answer, and where it is not

21 of the 29 controls are answered by software we can shortlist, price in INR with GST, and implement. The other 8 are procedures, design decisions, policies and contracts — and we say so.

Every obligation carries its source and the date we verified it, on the obligations page. Incident accounts are quoted as their sources state them; where a company disputed a link, its own statement is shown. General information, not legal advice — confirm applicability and current status with your counsel.