November, 2025 | DELAWARE SMALL BUSINESS DEVELOPMENT CENTER
Shop Small, Shop Safe
Avoiding Holiday-Season Cyber Threats
While the holiday season brings happiness and cheer, the uptick in consumerism and stress levels can lead to heightened cyber risks. Attackers exploit increased online shopping, delivery notifications, travel bookings, year-end business operations, and increased distractions. Research shows phishing attempts rise by as much as 400% between normal months and the start of the holiday rush. A separate study found ransomware attempts increase by ~30% over the winter holidays compared to typical months.
On the other side of the register, small businesses often operate with reduced staff or remote arrangements during holidays. One report noted that 85% of organizations with security teams scale back staffing during holidays – that means fewer eyes on alerts, slower response times, and more opportunity for attackers to gain a foothold.
Hackers understand human nature, and the holiday season gives them an advantage. Everyone is busier than usual—handling orders, invoices, and holiday deals—so people click faster and think slower. At the same time, far more activity happens online, from shopping and shipping to donations and travel, which provides a believable cover for fake messages and scams. Staffing also drops as employees take time off, leaving fewer people watching inboxes, bank accounts, and alerts. Even basic maintenance tasks like software updates, backups, and password checks often get delayed. In short, the holidays are when businesses are most distracted, making it easy to catch staff off-guard. This is what makes social engineering that much more effective during the winter season. What can we do to stay alert?
Typical Holiday Attack Scenarios
Let’s walk through some common methods used by attackers during the holiday season:
Fake delivery or shipping notifications: With higher parcel and mail traffic, attackers send emails or texts claiming “Your parcel could not be delivered – click here to confirm address or pay fee.” The link may go to a phishing site, lead to malware installation, or steal credentials.
Holiday deal or gift-card scams: Emails offer unrealistically good deals, free gift cards, or exclusive access, often with a link or attachment that triggers malware or phishing. For example, you open an attached “coupon” or click to “redeem now.” The link gives away your login or installs ransomware.
Donation and charity scams: During a season of giving, fake charities or bogus donation requests appear. According to survey data, 35% of people reported receiving questionable charity donation requests that seemed fake. These requests often imitate branding or other aspects of legitimate charities to seem more believable.
Travel and vacation-themed attacks: Attackers leverage holiday travel planning, booking sites and vacation offers. One study found that over 39,000 new vacation-related domains were registered in May 2025 and 1 in 21 of those domains was flagged as malicious or suspicious.
Ransomware insertion timed for low-staff periods: Alerts from the Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) note that many ransomware attacks are timed for holidays or long weekends when staff are off or less alert, giving attackers an advantage.
Fake tech-support pop-ups or alerts during remote work or holiday travel: Imagine an employee working from home during the holidays receives a pop-up “Your system is infected, call this number now” while checking in using hotel WiFi. The number connects to a scammer who gains remote access and installs malware that spreads later. This scenario becomes increasingly likely during holiday periods when remote work increases.
What You Can Do to Protect Your Business
Make your incident response plan, and check it twice! Here are practical steps that help your business reduce risk during the holiday period:
- Re-alert your team: Before the season kicks in, hold a short refresher for staff on phishing and holiday scam risk. Highlight themed scenarios (e.g., gift-cards, shipping updates, donation requests).
- Keep computers and software updated: Updates can close a window of opportunity for hackers. Do updates before staff leave for vacation. If you can enable auto-updates, save yourself some time!
- Strengthen limited-staff monitoring: If you expect reduced staffing, set up additional monitoring or automated alerts for abnormal activity.
- Back up important data: Consider using an external hard drive and disconnect it after the backup so attackers can’t infiltrate it.
- Slow down and double-check: If a link, invoice, or message feels off even slightly, don’t click. Call or verify through another channel or report it to your appropriate team or cybersecurity leadership.
- Use multi-factor authentication (MFA) and access control: These measures reduce risk if someone falls for a phishing link or fake login page.
- Review third-party/ vendor access: During holidays, external contractors or vendors may have elevated access or use new tools. Confirm their security practices and remove unnecessary privileges.
- Test your incident response plan: Given increased risk during holidays, make sure you know what to do if an alert comes in. Confirm who will act and how even when staff are reduced.
Have a Hack-Proof Holiday
While the holidays should be a time for celebration, they also present greater opportunities for cyber-attacks. Phishing, malware infiltration, ransomware, charity scams and travel-themed fraud all rise during the season. By recognizing the patterns and putting in place basic but consistent safeguards, you help protect your business and keep the focus on success. Criminals know smaller teams can be easier targets, especially during the holidays.
Let this year be one where you stay merry, safe, and cyber-aware. Have a wonderful Shop Small season, and cheers to success in the new year!

DATA ASSURED
Data Assured is Delaware’s Small Business Development Center’s premier cybersecurity and technology program designed to educate and support small businesses.