Retail & Hospitality ISAC

@rhisac.org

A retail and hospitality-focused cyber intelligence community https://rhisac.org/

Registration is open for the RH-ISAC workshop in Vancouver on 14 October! Hosted by Earls Kitchen + Bar and in collaboration with the Retail Council of Canada, this full-day event brings together cybersecurity practitioners from across the industry. rh-isac-workshop-vancouver-2026.eventbrite.com

RH-ISAC Workshop Vancouver: Hosted by Earls Kitchen + Bar

Join consumer-facing cybersecurity teams at the RH-ISAC Workshop in Vancouver, BC hosted by Earl's Kitchen + Bar

rh-isac-workshop-vancouver-2026.eventbrite.com

Calling all retail and hospitality CISOs in Europe! Join the Retail & Hospitality ISAC for a CISO Forum event on 23-24 September in Paris, hosted by Kering at their headquarters, housed in a 17th-century architectural landmark. ✅ Register: rh-isac-cisoforum-paris-2026.eventbrite.com

RH-ISAC CISO Forum EMEA: Hosted by Kering

Join top retail and hospitality CISOs at Kering headquarters in Paris on 24 September and dinner before the meeting on 23 September.

rh-isac-cisoforum-paris-2026.eventbrite.com

Join RH-ISAC Associate Member Doppel on 25 August to learn how security leaders from the San Francisco 49ers and New York Giants are preparing to protect their teams, athletes, executives, brands, and fans from emerging AI-enabled threats.

Preparing the SF 49ers and NY Giants for the 2026 Season: Defending Against AI-Powered Social Engineering | Doppel

Hear security leaders at the San Francisco 49ers and New York Giants discuss how teams can protect their brand from AI-powered social engineering.

doppel.com

Join us on 14 August for a briefing on how AI-driven bots, crawlers, and autonomous agents are changing the threat landscape. We'll also discuss the exposure of nearly 50,000 valid FortiGate firewall credentials and what your team should do now to reduce risk. Register: rhisac.org/event/threat...

Retail & Hospitality Threat Landscape Briefing - RH-ISAC

Join RH-ISAC for a monthly threat briefing webinar series about the latest intel on observed incidents and emerging threats relevant to the retail and hospitality community.

rhisac.org

If an AI agent issues refunds, approves purchases or changes access permissions, can your team answer who is accountable and reconstruct every action it took? New blog from @sentinelone.com explores why AI agents should be governed like identities, not treated like tools: rhisac.org/ai/the-missi...

The Missing Owner: Why Every AI Agent Needs Governance, Not Just Guardrails - RH-ISAC

Overnight, a retailer's support agent issues hundreds of refunds. At a hospitality group, a guest-services agent comps dozens of rooms across the portfolio

rhisac.org

New report details Russian Loader-as-a-Service designed to support ClickFix campaigns. The service enables operators to configure malicious lure pages that instruct victims to copy and execute commands from fake verification prompts. rhisac.org/threat-intel... #cybersecurity #ClickFix

DOUBLECUP ClickFix Loader Delivers CountLoader and DeviceManager RATs - RH-ISAC

A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.

rhisac.org

Calling all gaming and casino cybersecurity pros! In conjunction with the Global Gaming Expo in Las Vegas, RH-ISAC is hosting a Gaming Workshop! 🗓️ 1 Oct | 12 p.m. - 5 p.m. 📍 Wynn Las Vegas 💲 No cost to attend ✅ Register:

RH-ISAC Gaming Workshop Las Vegas

A day of discussions & presentations on building secure products for the gaming industry with fellow cybersecurity practitioners in Vegas!

rh-isac-workshop-las-vegas-2026.eventbrite.com

On 14 Aug, join RH-ISAC and Akamai for a threat briefing on the new wave of automated traffic emerging in the frontier AI era, from AI crawlers and autonomous agents to the surge in bot and crawler activity driving infrastructure strain. Register:

Retail & Hospitality Threat Landscape Briefing - RH-ISAC

Join RH-ISAC for a monthly threat briefing webinar series about the latest intel on observed incidents and emerging threats relevant to the retail and hospitality community.

rhisac.org

A new report detailed a typosquatted NuGet package, Newtonsoftt.Json.Net, that impersonated the legitimate Newtonsoft.Json library. The malicious package delivered a trojanized JSON library designed specifically to manipulate game results. rhisac.org/threat-intel... #ThreatIntel #Cybersecurity

NuGet Typosquatting Package Targets Digitain Betting Platform - RH-ISAC

A JFrog report published on 21 July 2026 detailed a typosquatted NuGet package, Newtonsoftt.Json.Net, that impersonated the legitimate Newtonsoft.Json

rhisac.org

Join RH-ISAC's Regional Workshop on 25 September, hosted by Kering, for a day of peer-driven discussions, professional development, and networking with cybersecurity practitioners. 📍 Paris, France 📅 25 September 2026 ✅ Register: rh-isac-workshop-paris-2026.eventbrite.com

RH-ISAC Workshop Paris: Hosted by Kering

Join consumer-facing cybersecurity teams at the RH-ISAC Workshop in Paris, hosted by Kering

rh-isac-workshop-paris-2026.eventbrite.com

Check out the Human Risk Blueprint from Doppel to learn how security teams can identify, measure, and reduce employee risk with real-world threat intelligence, phishing simulations, and targeted security awareness programs that strengthen defense against social engineering:

The Human Risk Management Blueprint | Doppel

Stop measuring passive compliance. Start actively modifying human risk. Learn how to shift to Human Risk Management in 5 straightforward phases, so you can neutralize AI-native threats with AI-native resilience.

doppel.com

Account takeover attacks are evolving. Residential proxy networks allow threat actors to distribute login attempts across thousands of legitimate-looking IP addresses, reducing the effectiveness of traditional perimeter defenses. Read insights from Accertify:

Residential Proxy Networks Are Enabling Account Takeover That Perimeter Controls Cannot See - RH-ISAC

Accertify, a fraud decisioning platform provider, has identified a sustained shift in account takeover (ATO) infrastructure: attackers are moving away from

rhisac.org

As cybercriminals use generative AI to exploit the customer-first culture of retail and hospitality, organizations that adopt dynamic behavioral risk management in place of static compliance training reduce both their risk exposure and the impact when an attack lands. rhisac.org/risk-managem...

Protecting Retail and Hospitality Front Lines From Conversational AI Threats - RH-ISAC

The retail and hospitality sectors operate on high-velocity human interaction, making their front lines a major target for sophisticated social engineering

rhisac.org

Researchers linked the financially motivated campaign dubbed “FortiBleed” to the Ransom and Lynx ransomware operations, marking the first confirmed instance connecting mass FortiGate credential theft to actual ransomware deployment. rhisac.org/threat-intel...

FortiBleed Credential Theft Campaign Attributed to INC and Lynx Ransomware Groups - RH-ISAC

On 02 July 2026, SOCRadar researchers linked the financially-motivated campaign dubbed "FortiBleed" to the Ransom and Lynx ransomware operations, marking the

rhisac.org