How a leading retail company protects customers and the market from cyberattacks with the LUMINAR solution

Illustration

In the face of a growing number of cyberattacks targeting the retail sector, one major retail company has adopted an advanced threat intelligence solution – LUMINAR by Cognyte. Thanks to this, it effectively protects its customers’ data and online transactions, while actively supporting the security of the entire supply chain, strengthening the market’s resilience to cyber threats.

Challenge: Increasing threats to customer and employee data.

One of the largest European retail chains, employing over 45,000 people, faced an intensification of cyberattacks. Particularly concerning were:

    Customer payment card data leaks – being sold on Dark Web forums.
    Disclosure of corporate email addresses – used in phishing campaigns.
    Lack of visibility in underground communication channels – where cybercriminals plan attacks and exchange tools.
Illustration

Solution: Cognyte LUMINAR – Threat Intelligence in the Service of Security

To effectively counter threats, the company implemented the Cognyte LUMINAR platform, which enables:

  • Detection of payment card data leaks

    LUMINAR automatically monitors Dark Web forums and identifies offers to sell card numbers linked to the company’s customers. This enables a rapid response and collaboration with payment operators to block compromised data.

  • Identification of corporate email leaks

    The platform analyzes databases published in underground sources and detects employee email addresses, enabling the implementation of additional security measures and reducing phishing risk.

  • User iconUser icon for website, application, printing, document, poster design, etc.

    Profiling APT groups and cybercriminals

    LUMINAR identifies the tactics, techniques, and procedures (TTPs) used by attacking groups, enabling security teams to anticipate potential attack vectors.

  • Early warning of planned attacks

    Analyzing communication on forums and encrypted channels allows detection of attack preparations before they are carried out.

  • CTI reports for SOC teams and executive management

    LUMINAR generates reports with threat analysis and recommended actions, supporting both operational and strategic decision-making.

Illustration

Examples of integration use cases

  • Payment card data leak

    ● LUMINAR detects offers to sell customers’ cards on the Dark Web.● SIEM correlates this data with transaction logs – identifying attempts to use compromised cards in real time.

  • Employee email leak

    ● LUMINAR identifies email addresses in leak databases.● SIEM monitors login attempts and sends alerts if it detects suspicious activity from these accounts.

  • User iconUser icon for website, application, printing, document, poster design, etc.

    APT group profiling

    ● LUMINAR provides information on the TTPs of attacking groups.● SIEM uses this data to create correlation rules that automatically detect similar patterns in the client environment.

Extended functionality: SIEM integration

To further enhance operational efficiency, the company integrated LUMINAR with the SIEM system. Thanks to this integration:

    CTI data from LUMINAR is automatically imported into the SIEM and correlated with system logs.
    Alerts about card or email leaks are enriched with threat intelligence context, enabling faster and more precise responses.
    SIEM uses TTP data from LUMINAR to create correlation rules that automatically detect similar patterns in the client environment.

Integration with SIEM does not change LUMINAR’s role as the primary source of threat intelligence – it serves as a layer of automation and response, translating intelligence data into concrete operational actions.

Results: Faster responses and new capabilities

Within just a few months of implementation, LUMINAR began delivering tangible benefits:

    Payment card data leaks were identified and preventive actions were taken.
    The publication of corporate emails was detected, and employee accounts were secured.
    Planned attacks on e-commerce and POS systems were uncovered.
    SOC efficiency was increased through the integration of CTI data with the SIEM.

Summary: Intelligent synergy of CTI and SIEM

The integration of Cognyte LUMINAR with SIEM allowed the company not only to detect threats but also to understand and neutralize them in real time. This is an example of how a modern, intelligence- and automation-based approach to security can protect customers, employees, and brand reputation in the retail sector.


Cognyte

Cognyte is a global leader in investigative analytics software, providing government institutions and other organizations with actionable intelligence for a safer world.

Learn more about the Luminar solution

To schedule individual demonstrations, partner training, or pilot projects, please contact us: