When Singapore fashion retailer Love, Bonito notified customers in July that a website vulnerability had exposed names, birth dates, addresses, order histories, and partial payment information, the disclosure carried an uncomfortable echo. It was the brand’s second publicly disclosed breach.

In 2019, attackers compromised its systems, and Singapore’s Personal Data Protection Commission (PDPC) later fined the company S$24,000 for failing to put reasonable security measures in place. Among the weaknesses cited was an inadequate password policy. The administrator password at the time was “ilovebonito88.”

Love, Bonito responded quickly this time, closing the vulnerability on the same day it was identified, while the root cause of the latest incident has not been disclosed. The broader question is why online retailers across Asia-Pacific keep appearing in breach headlines, and what that pattern reveals about the security controls behind modern storefronts.

A storefront is now a stack of identities

Shoppers see a website, but behind the storefront sits a web of infrastructure: cloud servers, order management systems, payment integrations, marketing platforms, logistics connectors, analytics pipelines, and a growing layer of automation and AI agents.

Every connection between these components runs on a credential, from a human administrator’s login to a service account, API key, or machine certificate.

That last category is expanding quickly. As machine- and AI-driven identities proliferate across enterprise environments, many carry privileged access that is not always subject to the same scrutiny as employee credentials.

In e-commerce, these non-human identities (NHIs) are the connective tissue of the business: the API key that lets the storefront communicate with the payment processor, the service account that synchronizes inventory, or the token that authorizes a chatbot to read customer records. Each is a credential that can be stolen, and many are governed more loosely than employee logins.

Consumer-facing authentication has actually improved. Many platforms now offer passkeys and multi-factor authentication (MFA) to shoppers. The gap is often on the other side of the counter: privileged access to servers, databases, and integrations can still rely on shared passwords and static API keys that rarely expire.

The pattern across APAC

Recent incidents across the region trace similar contours.

In Japan, e-commerce and logistics firm Askul confirmed that roughly 740,000 records were exposed following an October 2025 ransomware attack. The company’s investigation found that attackers likely used stolen credentials for an outsourced partner’s administrator account that had not been protected by MFA. The attackers then moved laterally through its environment, disrupting operations for major retail brands that depended on Askul’s fulfillment network.

Louis Vuitton disclosed in mid-2025 that customers in South Korea and other markets had been affected by a breach. South Korea’s Personal Information Protection Commission later found that malware on an employee device enabled attackers to steal account information used to access a SaaS-based customer management service.

In February 2026, the regulator imposed combined penalties of about 36 billion won, or roughly US$25 million, on the Korean units of Louis Vuitton, Dior, and Tiffany over separate customer-data breaches. Its findings highlighted shortcomings including remote-access authentication controls and access-log monitoring.

The economics driving these attacks are also visible in underground markets.

Threat intelligence firm Cyble recorded 92 instances of compromised network access being offered for sale against Australian and New Zealand organizations in 2025, with retailers accounting for 31 of those cases.

In one incident, a threat actor advertised unauthorized access to the hosting server of a major Australian retail chain. The seller claimed the server contained approximately 250GB of data, including a 30GB customer database. The retailer’s identity was not independently confirmed, and the access was listed for auction with a starting price of just US$1,500.

Even the mobile storefront is contested ground. Kaspersky researchers identified the SparkCat data-stealing Trojan inside multiple apps distributed through official app stores, including ComeCome, a food delivery service operating in Indonesia and the UAE. The affected Android applications had collectively been downloaded more than 242,000 times from Google Play.

Regional data reinforces that these are not isolated cases. Verizon’s 2026 Data Breach Investigations Report found that external actors were behind 99 percent of APAC breaches, while exploitation of vulnerabilities was the leading initial-access vector at 42 percent, ahead of credential abuse at 25 percent.

IBM’s 2026 Cost of a Data Breach research puts the average breach cost for ASEAN organizations at a record US$4.12 million.

Singapore’s Cyber Security Agency, meanwhile, recorded approximately 4,800 reported phishing attempts in 2025 and has warned that AI is allowing threat actors to produce convincing phishing lures at greater speed and scale.

Why retail is structurally exposed

Retail concentrates exactly what cybercriminals want: identity data, payment details, and purchase histories, held in systems built for speed and scale rather than segmentation.

Margins are thin, security teams can be small, and the supplier ecosystem is vast. Every peak sales season can add new plugins, campaigns, and third-party connections that outlive their original purpose but retain their access. The perimeter is only as secure as its least-governed integration.

This is one reason breaches recur. A vulnerability can be patched in a day; an identity governance gap persists until someone deliberately closes it.

When credentials remain unrotated for years, API keys carry standing privileges, and no one can say with confidence which humans, vendors, and machines can reach customer data, the conditions for another incident remain in place.

What retailers should do now

The response does not require an unlimited budget. It requires treating identity as the storefront’s real perimeter.

The starting point is authentication. Retailers should enforce phishing-resistant MFA on administrative and seller consoles and extend that requirement contractually to vendors and outsourced partners.

Privileged access belongs under the same scrutiny. Human administrators should receive time-limited, least-privilege access to production systems, with sessions logged and reviewed, rather than relying on standing credentials that remain active between uses.

NHIs need the same discipline. Organizations should inventory every API key, service account, and machine credential connected to the commerce stack, rotate them on a schedule, restrict them to the minimum privileges required, and revoke them when integrations are retired.

Organizations operating under Japan’s Act on the Protection of Personal Information or South Korea’s Personal Information Protection Act should treat governance of machine identities as part of their broader access-control and personal-data protection responsibilities, particularly where those identities can reach customer information.

Vulnerability management deserves equal weight. Verizon’s 2026 findings show that attackers in APAC exploit unpatched flaws more often than any other initial access method. That makes visibility into exposed systems, timely patching, and clear remediation ownership critical alongside identity controls.

Underpinning all of this is zero trust: verify each access request, whether human or machine, and grant only the privileges each task requires. Applied consistently, this can prevent a single stolen credential from automatically becoming a much larger breach.

Love, Bonito’s second breach reflects a pattern playing out across the region. The question for retailers is not whether they can eliminate every attack attempt, but whether the identity and access controls they put in place today are sufficient to contain the next one.


Takanori Nishiyama is Senior Vice President of APAC Sales and Country Manager, Japan at Keeper Security. He has more than a decade of leadership experience at VMware, where he oversaw the End User Computing business across Asia-Pacific and Japan. He previously held roles at Red Hat and EMC across hardware, software, and SaaS businesses.

Editor’s note: This contributed article has been lightly edited for clarity, length, and style. Where appropriate, TNGlobal may verify, qualify or omit factual claims that cannot be independently corroborated. The views and arguments expressed remain those of the author.

Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archive.

Featured image: Shutter Speed on Unsplash

The critical role of SysAdmins in protecting privileged access