Retail & e-commerce security compliance · IndiaOne incident. Up to 7 clocks.
CERT-In gives you six hours. Your gateway, your marketplace and ONDC start their own clocks — all running at once, and all well inside DPDP’s 72.
Ransomware stops the supply, not the stores.
Your checkout scripts are now a PCI requirement.
Incident receipt
You noticed it · t = 0
- CERT-In6 hours
to CERT-In
- ONDC6 hours
to ONDC
- Payment gateway12–24 hours
to your payment gateway
- Marketplace24 hours
to the marketplace
- NIS224 hours
to the national CSIRT (early warning)
- DPDP72 hours
to the Data Protection Board
- GDPR72 hours
to the EU / UK supervisory authority
All running at once · filing one discharges none of the others
THANK YOU · KEEP THIS FOR YOUR RUNBOOK
The law gives you six hours. Your contracts start their own clocks.
Three lines from the primary texts — a regulator, a network and a marketplace — and filing one discharges none of the others.
“Any entity which notices the cyber security incident, shall report to CERT-In. The obligation of reporting of cyber incident is neither transferrable nor indemnified or dispense with.”
So: Asked about a consumer-facing business and its back-end partner. Your agency’s detection is still your six hours.
ONDC Network Policy · 8.2.2A network participant “must alert ONDC of such Data Breach or cyber security incident within 6 hours of being aware”.
So: Plus a yearly certificate from a CERT-In-empanelled auditor, and audits without notice after a breach.
Amazon Data Protection Policy · 1.6.3Sellers using Amazon’s API must “notify Amazon … within twenty four (24) hours of detecting a Security Incident”.
So: It binds a seller’s own integration too — with MFA, encryption and 30-day data deletion.
Stores, online — or both?
Pick one and the rest of the page follows you. Most large retailers are both.
We run stores
Supermarket, fashion, electronics & pharmacy chains · QSR & franchise networks
What binds you that you may not know
We sell online
Marketplaces · D2C brands · quick commerce · e-commerce apps
Stores: 20,169 Reliance Retail stores · 963 Zudio stores · 500 DMart stores · 2,455 Domino’s India stores. Online: ~$60bn online retail, 2024 · 270M+ online shoppers · 2,443 Blinkit dark stores · 85.5% of payments by volume on UPI. Company filings and results (Reliance Retail Q1 FY27, Trent FY26, Avenue Supermarts 31 March 2026, Jubilant FoodWorks, Eternal Q1 FY27); Bain & Company with Flipkart, March 2025; RBI Payment System Report, H2 2025.
What binds you?
Free · no email · shareableBinds every retailer — before you pick anything
The clocks one incident starts
Regulator
Indicative, based on the published texts as we read them on the dates shown against each obligation. General information, not legal advice — confirm applicability with your counsel.
How retailers actually get breached
9 patterns, each drawn as the attacker walks it. Every incident is sourced.
The help desk resets the attacker’s password
Stores- Caller poses as staff
- Desk resets password + MFA
- Ransomware follows
Attackers impersonated one of the people who work with M&S and tricked a third party into a reset; online orders stopped for weeks. M&S first guided about £300 million off profit before mitigation and insurance.
Press named its service-desk supplier TCS, which says “no TCS systems or users were compromised”.
UK Parliament evidence; BleepingComputer ↗+ 2 more cases: Co-op Group (UK), UK NCSC− fewer
Data on all 6.5 million members was copied; shutting systems down early prevented encryption but still emptied shelves. Reported to have started with help-desk resets.
BleepingComputer ↗After the retail attacks, told every organisation to review how its IT help desk authenticates staff before resetting passwords, especially for admins.
NCSC ↗India: No public Indian case found — the mechanism needs only a help desk and a convincing caller.
Stops itVerify the caller before any resetPhishing-resistant MFA and SSO for staffDetect and report inside six hoursBackups you can restore — offline, and in India for the booksRansomware stops the supply, not the stores
Stores- Foothold, then spread
- ERP and warehouse encrypted
- Supply stops
Its exchange filing said store operations were unaffected. Its Q4 FY25 results then attributed part of a ₹45 crore loss to “a ransomware attack that led to system outages and supply chain disruptions”.
IndiaRetailing ↗+ 2 more cases: Haldiram’s, Mithaas− fewer
An FIR in Noida records servers encrypted and financial, HR and sales data taken; police said the allegations were found true.
Deccan Herald / PTI ↗A second Noida food-retail chain reported ransomware within two weeks: “complete data has become useless for us”.
Tribune / PTI ↗A vendor’s remote access becomes POS malware
Stores- Vendor’s remote access
- Into store systems
- Malware on the tills
POS malware at franchised restaurants, installed using “compromised third-party vendor credentials”; company-operated restaurants were not affected.
Wendy’s 8-K ↗+ 1 more case: Target (US)− fewer
Attackers used an HVAC contractor’s credentials, moved through the network and put malware on POS systems; 40 million cards were taken.
Dark Reading ↗India: No public Indian case found. Indian franchise disclosures do not show franchisor security clauses either.
Stops itControl vendor and franchise access to storesHold franchisees to a minimumLock down POS and back-office machinesSegment the store network and the card environmentUse validated card terminalsAn old key or an open bucket, and the customer database walks out
Online- Old key or misconfiguration
- Into the data store
- Customer data exported
“An old unrecycled AWS access key was exploited”; Juspay said 3.5 crore masked-card records were taken from the payments partner of several large merchants.
A researcher put the figure at about 10 crore; Juspay disputed it.
Business Today ↗+ 3 more cases: RentoMojo, BigBasket, Domino’s India, ABFRL, boAt, Snowflake customers− fewer
Its CEO told customers attackers exploited a cloud misconfiguration; the leaked data included government ID and passport numbers.
MediaNama ↗Customer databases verified by Have I Been Pwned at 2.45 crore, 2.25 crore, 55 lakh and 75 lakh email addresses. None of the companies disclosed how the attackers got in.
MediaNama (BigBasket) ↗About 165 organisations’ data stores were accessed with stolen credentials and no MFA — Advance Auto Parts reported 23 lakh people affected.
Google / Mandiant ↗Customers’ accounts are taken over and spent
Online- Reused password or fake call
- Account taken over
- Wallet or BNPL spent
Delhi Police arrested two men who used fake IVR calls to take over accounts and placed ₹97,197 of orders on one victim’s linked BNPL account.
Siasat ↗+ 2 more cases: Meesho, The North Face (US)− fewer
Its own trust report: 13 lakh bot orders blocked in a year, and nine cases filed for account-takeover fraud.
Outlook Business ↗VF called it a “small-scale credential stuffing attack”; 2,861 customers’ names, addresses and order histories were visible to the attackers.
Maine Attorney General filing ↗A script on the checkout page copies every card
Online- Script injected
- Checkout input copied
- Card data leaves
The UK regulator fined BA £20 million after its payment page was skimmed for about 4.3 lakh customers and staff.
The Register ↗+ 2 more cases: Ticketmaster UK, CosmicSting (Adobe Commerce / Magento)− fewer
India: No public Indian web-skimming case found, 2019–2026 — not the same as “it doesn’t happen here”.
Stops itWatch every script on the checkout pageWeb application and API protection, and DDoSPatch what is exposed firstDecide your PCI scope on purposeRefunds, returns and coupons are farmed
Online- Fake buyers or sellers
- False return claims
- Refunds drained
Filed a ₹1.1 crore complaint with Bengaluru police over false “item missing” refund claims on about 5,529 orders.
Business Today ↗+ 2 more cases: Meesho, Swiggy− fewer
Police arrested a seller and agent who faked buyer accounts and returns to take ₹5.5 crore.
Deccan Herald ↗Its IPO document discloses a former employee who gained access to test systems; an FIR was filed.
Storyboard18 (Swiggy DRHP) ↗A supplier is breached, and your customers or shelves pay
Both- A supplier is breached
- Into your data or operations
- Orders or data hit
The attacker “compromised the servers of a third party that the company works with”; 34.6 lakh email addresses were later verified.
MediaNama ↗+ 3 more cases: Blue Yonder, UNFI (US), Harrods (UK)− fewer
Ransomware in one supply-chain SaaS provider disrupted Starbucks’ staff scheduling and warehouse systems at UK grocers Morrisons and Sainsbury’s.
CyberScoop ↗Whole Foods’ main distributor took systems offline and estimated $350–400 million of lost sales.
UNFI results (SEC) ↗An external supplier was breached: about 4.3 lakh customers’ loyalty and contact records.
The Register ↗Fake stores and apps use your name
Both- Fake store or app
- Shoppers pay or log in
- Money and data lost
CERT-In’s festive-season advisory warns of fake e-commerce sites and cash-on-delivery scams run through fake online stores.
CERT-In ↗+ 1 more case: Meesho− fewer
Its trust report: 130 fake websites and apps and 18,000 fake social-media accounts taken down in a year.
Outlook Business ↗What a breach costs a retailer
- ₹25.5 crBothAverage cost of a data breach in India — the highest IBM has recordedIBM Cost of a Data Breach, India 2026 ↗
- 68%BothShare of retail breaches that involved a third partyVerizon DBIR 2026, retail ↗
- 42%BothShare of retail breaches that began with an exploited vulnerability — the top way inVerizon DBIR 2026, retail ↗
- $1MBothMedian ransom paid by retailers whose data was encrypted — 58% paidSophos State of Ransomware in Retail 2025 ↗
- ₹45 crStoresRaymond Lifestyle’s Q4 FY25 loss — attributed in part to a ransomware attack that disrupted its supply chainIndiaRetailing ↗
- £300mStoresWhat M&S first guided its 2025 attack would take off operating profit, before insurance and mitigationThe Record ↗
- $20mOnlineOnline sales Victoria’s Secret put down to taking its website offline for three days in 2025Victoria’s Secret results (SEC) ↗
- £20mOnlineUK regulator’s fine on British Airways after its payment page was skimmedThe Register ↗
Seen enough to know where you stand?
A 30-minute call. We come with a vendor-neutral shortlist, priced in INR with GST.
What you actually have to do
29 controls. Most bind every retailer — the map shows which are only for stores or only for online.
- Detect and report inside six hours
- Keep 180 days of logs — and a year for personal data
- Phishing-resistant MFA and SSO for staff
- Email security, DMARC and lookalike-site takedown
- Backups you can restore — offline, and in India for the books
- Patch what is exposed first
- Encrypt and tokenise customer data
- Consent, notices and erasure under DPDP
- Know which vendors hold your customers
- Limit what store and support staff can take
- Verify the caller before any reset
- Decide your PCI scope on purpose
- The six-hour runbook
- Read the breach clauses you have signed
- 1Report to CERT-In within six hours
- 2Keep 180 days of logs
- 3Sync clocks to NIC / NPL time
- 4Back up your books daily, in India
- 5Never store card numbers
Send us the security checklist your partner just sent.
Whether you run stores or a checkout, the bar arrives as someone else’s checklist. We turn it into a shortlist.
- 01
You send the checklist you were handed
A gateway’s security review, a marketplace’s data policy, ONDC’s audit, an insurer’s proposal form.
- 02
We map it to the 29 controls
Which items you already meet, and which ones you can’t yet.
- 03
You get a shortlist that closes the gaps
Vendor-neutral, priced in INR with GST, implemented if you want us to.
- 21/29controls our catalogue answers
- 170vendors researched
- 977product pages, limits stated
- 26obligations, sourced
What the market gets wrong — and where we are thin
- “Our e-commerce agency reports the breach, not us.”CERT-In: whoever notices it reports it, and the duty is “neither transferrable nor indemnified”.
- “DPDP is in force now.”Only the Board is. The operational duties start on 13 May 2027; Consent Managers on 13 November 2026.
- “DPDP gives us 72 hours to tell customers.”Customers must be told “without delay”. The 72 hours is the detailed report to the Board.
- “RBI mandates PCI DSS for every merchant.”It reaches you through your payment aggregator, which must check your infrastructure — no rule is aimed at merchants directly.
- “SAQ A means we can ignore checkout scripts.”SAQ A dropped 6.4.3 and 11.6.1 but added a test: your site must be protected against script attacks — by you or your provider.
- “We can store encrypted card numbers.”No entity other than issuers and networks may store card data. You may keep the last four digits and the issuer’s name.
Where our catalogue is thin
We’d rather tell you than let a gap look like a recommendation.- Email security, DMARC and lookalike-site takedownEmail filtering and DMARC are well covered; dedicated brand-takedown services are thin — two products, no Indian takedown specialist yet.
- Consent, notices and erasure under DPDPFour consent and privacy products, no decision guide yet — and no registered DPDP Consent Manager in our catalogue.
- Know which vendors hold your customersGRC suites are covered; dedicated vendor-risk ratings (SecurityScorecard, BitSight) and Indian compliance automation (Sprinto, Scrut) are not in our catalogue yet.
- Segment the store network and the card environmentFirewalls and SD-WAN are well covered; store Wi-Fi and network access control (Meraki, Aruba, Forescout) are thin.
- Web application and API protection, and DDoSStrong products from six vendors, but no decision guide yet; Imperva and India’s Indusface are not in our catalogue.
- Stop bots and account takeoverThin: three dedicated products. HUMAN, Kasada and DataDome are not in our catalogue.
- Watch every script on the checkout pageThin: one dedicated product, plus Cloudflare’s module. Jscrambler, Feroot and c/side are not in our catalogue.
- Secure customer loginsTwo dedicated customer-identity products; Ping Identity and LoginRadius are not in our catalogue.
- Verify sellers, riders and partnersKYC is covered; e-commerce order-fraud scoring (Riskified, Forter, SEON) for refund, coupon and cash-on-delivery abuse is not in our catalogue.
Retail & e-commerce compliance, answered
Short answers, each backed by the source on the obligations page.
If our e-commerce agency or SaaS vendor detects a breach, who reports it to CERT-In?
Whoever notices it. CERT-In's FAQ on its 2022 Directions answers exactly the case of a consumer-facing business and its back-end partner: the duty to report within six hours is neither transferable nor indemnifiable by contract.
How fast must a retailer report a breach to its payment gateway, Amazon or ONDC?
Faster than most expect, and by contract rather than law. Cashfree's merchant terms ask for suspected security events within 12 hours and Razorpay's for breaches within 24; Amazon's seller-API policy wants 24 hours; ONDC's network policy wants 6. CERT-In's own clock is 6 hours. They run in parallel.
Does PCI DSS apply if we use a hosted checkout from Razorpay or Cashfree?
It depends on how the checkout is built. If you redirect shoppers to the gateway's own page, the SAQ A script test does not apply to you. If you embed the gateway's form in an iframe on your page, you are eligible for SAQ A only if your page is protected against script attacks — by you or your provider (PCI SSC FAQ 1588, 2025).
Can we store customers' card numbers for one-click checkout?
No. Since 30 September 2022 the RBI has barred everyone except card issuers and networks from storing card data. A merchant may keep the last four digits and the issuer's name for reconciliation, and use network tokens for saved cards.
When does the DPDP Act start applying to retailers?
The operational duties — notices, security safeguards, breach notification, erasure, children's data — apply from 13 May 2027. Consent Managers start on 13 November 2026. Customers must be told of a breach without delay; the detailed report to the Data Protection Board is due within 72 hours.
What changes for e-commerce on 1 January 2027?
The Consumer Protection (E-Commerce) Amendment Rules 2026 come into force: a yearly dark-pattern self-audit with a certificate displayed on the site, clearly labelled sponsored listings, no manipulated search results, a 30-day prior-price rule for discounts, and — for marketplaces — express consent before using customer data to sell own-brand goods.
Must large e-commerce platforms delete inactive users' data?
Yes, from May 2027, but only e-commerce entities with at least two crore registered users in India, and not marketplace sellers. They must erase a user's data after three years of inactivity, with 48 hours' warning, keeping what is needed for the account and wallet or loyalty balances.
Do retailers need a yearly audit by a CERT-In-empanelled auditor?
Not by law — CERT-In's 2025 audit guidelines are guidance for private companies. But ONDC requires a yearly certificate from an ONDC- or CERT-In-empanelled auditor from its network participants, and payment gateways ask for annual proof of PCI DSS compliance.
Where software is the answer, and where it is not
21 of the 29 controls are answered by software we can shortlist, price in INR with GST, and implement. The other 8 are procedures, design decisions, policies and contracts — and we say so.
Every obligation carries its source and the date we verified it, on the obligations page. Incident accounts are quoted as their sources state them; where a company disputed a link, its own statement is shown. General information, not legal advice — confirm applicability and current status with your counsel.