Cequence Security assisted the Ulta Beauty CTI team to mitigate a persistent, high-volume inventory API scraping attack. While the goal of the attack was initially uncertain, potential motivations included enabling real-world shoplifting opportunities by mapping popular inventory. The attack was executed across a third-party local-inventory search API, and mitigating it saved Ulta Beauty significantly across infrastructure and inventory costs.
Working together, the Ulta Beauty CTI and the CQ Prime threat research team put policies in place that have successfully blocked 85.9M total requests since April 1st resulting in $80,000 saved in infrastructure and loss prevention. Cequence was deployed fully on AWS with multiple availability zones and Auto Scaling groups enabling Ulta Beauty to scale up and down automatically as needed. At the height of the attack, policies were blocking upwards of 17M requests as shown in the following chart.
The rapid response and teamwork in blocking this attack resulted in a win for Ulta Beauty to the tune of $80,000 and a win for the local-inventory search API vendor, which no longer needed to bear the increased infrastructure costs. It’s also a win for the CQ Prime threat research team who mobilized quickly to identify the attack, motives, and behaviors and respond with appropriate blocking policies.