Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers
01/08/2019
Cambridge, MA | July 31, 2019
Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.
The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.
We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.
Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.
Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.
Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.
In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.
Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.
The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.
The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: | https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-... |
See more stories from akami |
Most recent headlines
09/12/2024
Dalet Named an IDC Innovator in Media and Entertainment
Dalet, a leading technology and service provider for media-rich organizations, today announced that it has been named an IDC Innovator in the IDC Innovators: ...
23/11/2024
Heartwarming Out of My Mind Highlights the Importance of Disability Advocacy
PARK CITY, UTAH - JANUARY 19: (L-R) Judith Light, Rosemarie Dewitt, Luke Kirby, Michael Chernus, Phoebe-Rae Taylor, Sharon M. Draper, Amber Sealey, and Courtney...
23/11/2024
TCLtv+ Adds 23 CBS Fast Channels
LOS ANGELES/NEW YORK TCL's streaming service TCLtv+ has struck a content deal with Paramount Streaming that will add 23 CBS FAST channels to its lineup....
23/11/2024
Viamedia Signs Ad Rep Deals with 7 More Service Providers
LEXINGTON, Ky. The independent advertising rep firm Viamedia has further expanded its sales network with news that it has agreements to manage advertising sale...
23/11/2024
The Trade Desk Jumps Into Streaming TV With Ventura OS
VENTURA, Calif. Programmatic ad giant The Trade Desk is pushing into the streaming technology business with a new operating system called Ventura....
23/11/2024
Writers Guild, 3 PBS Stations Reach Tentative Agreement for New Contract
BOSTON, LOS ANGELES AND NEW YORK The Writers Guild of America has announced that it has reached a tentative agreement with management at PBS member stations WGB...
23/11/2024
Supreme Court to Consider Legality of FCC's Universal Service Fund
WASHINGTON, D.C. The U.S. Supreme Court has agreed to hear an appeal in a case that alleges the FCC does not have the authority to decide how funds from the Uni...
22/11/2024
Michelle Satter to Be Honored at 2025 Sundance Film Festival Gala Celebrating Sundance Institute Presented by Google TV
Sean Wang, Julian Brave NoiseCat, and Emily Kassie to Receive Annual Vanguard Aw...
22/11/2024
Spotify Inks a New Partnership With Bloomsbury To Offer A Greater Assortment of Audiobooks
Our library continues to grow. In 2022, we announced the addition of audiobooks ...
22/11/2024
SBS wins Australian Podcast Publisher of the Year for third year running
SBS wins Australian Podcast Publisher of the Year for third year running 22 November, 2024 Media releases An outstanding slate of multilingual, multicultur...
22/11/2024
Film Lighting: a Cinematic Guide w/ Free Lighting Plots
Home Applications Film Lighting: a Cinematic Guide w/ Free Lighting Plots Your Guide to Film Lighting In this guide, we'll explore the history of fil...
22/11/2024
Fox, Hulu Renew Content Deal
Fox Entertainment and Hulu have renewed a multi-year content distribution agreement that will keep in-season streaming rights for Fox's programming slate on...
22/11/2024
Academy Award-Winning Film Studio Caviar Signs Director Duo MAMA
Academy Award-Winning Film Studio Caviar Signs Director Duo MAMA Brie Clayton November 22, 2024 0 Comments Academy Award-winning independent film stud...
22/11/2024
A Creative Alliance for Black Friday: Independent Software Makers Unite for Photographers
A Creative Alliance for Black Friday: Independent Software Makers Unite for Phot...
22/11/2024
Partial Bold Text using After Effects expressions UPDATED
Partial Bold Text using After Effects expressions UPDATED Graham Quince November 22, 2024 0 Comments Now with an improved expression for Per Word Se...
22/11/2024
John Lawson Steps Down as AWARN Executive Director
WASHINGTON John Lawson, longtime broadcast alerting advocate and founder of the AWARN Alliance, said he is stepping down as its executive director to work full-...
22/11/2024
Red, white and Blue Lucy UK media tech provider reaches across the Pond
Entering the American market follows a period of significant growth for the company By Matthew Corrigan Published: November 22, 2024 Entering the American...
22/11/2024
Warner Bros. Discovery Introduces Shop With Max and Moments
NEW YORK Warner Bros. Discovery Advertising Sales has incorporated Kerv's AI-enhanced technology into its ad-tech platform and launched two new ad offerings...
22/11/2024
EDO, Vizio Ink New Multiyear Smart-TV Data Licensing Pact
NEW YORK Vizio's Inscape, a smart-TV data provider, and EDO said they have extended their longstanding data partnership....
22/11/2024
New Pixotope Reveal Enables AR, Virtual Production Without Green Screens
OSLO, Norway Live augmented reality and virtual production specialist Pixotope Technologies has launched Pixotope Reveal, an AI-powered background segmentation ...
22/11/2024
Nominations Open for 2025 NAB Technology Awards
The National Association of Broadcasters has opened nominations for the 2025 NAB Technology Awards, recognizing excellence in broadcast engineering, digital lea...
22/11/2024
Thanksgiving TV Sports Ad-Spend Binge To Hit $624 Million
In between helpings of turkey and other Thanksgiving Day fare, viewers will see companies dishing up hefty portions of ads on sports programming, with the natio...
22/11/2024
8 Channels Added to MyFree DirecTV Streaming Lineup
Following the recent launch of the MyFree DirecTV free-ad supported package of 70-plus streaming channels, DirecTV has launched eight new channels catering to s...
22/11/2024
Viant, Disney Advertising Expand CTV Ad Collaboration
IRVINE, Calif. Viant Technology said it has expanded its agreement with Disney Advertising that's focused on making premium connected TV, video and display ...
22/11/2024
Xumo To Make Ad Inventory Available Programmatically With PubMatic
PHILADELPHIA and REDWOOD CITY, Calif. Xumo, the streaming platform joint venture of Comcast and Charter Communications, has reached an agreement to make its pre...
22/11/2024
Mediaocean To Acquire Innovid, Will Merge It With Flashtalking
NEW YORK Privately-held ad tech giant Mediaocean has inked a definitive agreement to acquire Innovid, an independent software platform for advertising creation,...
22/11/2024
Viz University introduces new Viz Artist certifications aimed at upskilling designers of all levels
Viz University introduces new Viz Artist certifications aimed at upskilling desi...
22/11/2024
NBC Sports President Rick Cordella on How Comcast's NBCU Cable-Net Spinoff Will Impact Sports Ops
NBC Sports President Rick Cordella on How Comcast's NBCU Cable-Net Spinoff W...
22/11/2024
NWSL Championship 2024: CBS Sports Caps Off First Year of In-House Broadcasts With Saturday's Final in Kansas City
NWSL Championship 2024: CBS Sports Caps Off First Year of In-House Broadcasts Wi...
22/11/2024
Premier League To Establish In-House Media-Operations Business for 2026-27 Season
Premier League To Establish In-House Media-Operations Business for 2026-27 Seaso...
22/11/2024
SailGP Season 5 Set to Be Most Expansive Yet'
SailGP Season 5 set to be most expansive yet' By George Bevir Friday, November 22, 2024 - 10:34 Print This Story SailGP: The New Zealand Sail Grand P...
22/11/2024
SailGP Season 5: New Broadcasters, New Requirements
SailGP Season 5: New broadcasters, new requirements By George Bevir Friday, November 22, 2024 - 10:34 Print This Story The Germany SailGP team in action a...
22/11/2024
SailGP Season 5: AI Cameras to Get Viewers Closer to the Action
SailGP Season 5: AI cameras to get viewers closer to the action By George Bevir Friday, November 22, 2024 - 10:33 Print This Story Getting viewers closer ...
22/11/2024
SailGP Season 5: Getting Umpires Onscreen and More Studio-Based Content
SailGP Season 5: Getting umpires onscreen and more studio-based content By George Bevir Friday, November 22, 2024 - 10:33 Print This Story Australia SailG...
22/11/2024
SailGP Season 5: Enhanced LiveLine Graphics Bring Augmented Reality to Chase Boats
SailGP Season 5: Enhanced LiveLine graphics bring augmented reality to chase boa...
22/11/2024
Full House: Inside Production of the European Curling Championships
Full house: Inside production of the European Curling Championships By Kevin Hilton Thursday, November 21, 2024 - 12:40 Print This Story Curling star Anna...
22/11/2024
NBC Sports President Rick Cordella on How Comcast's NBCU Cable Net Spinoff Will Impact Sports Ops
NBC Sports President Rick Cordella on How Comcast's NBCU Cable Net Spinoff W...
22/11/2024
Sky and Peacock's Original hit drama series The Day of the Jackal scores a second season renewal
Sky and Peacock's Original hit drama series The Day of the Jackal scores a s...
22/11/2024
Rugged Rugby: Conquer or Die' Premieres December 10: A Battle for Supremacy Begins
Back to All News Rugged Rugby: Conquer or Die' Premieres December 10: A Ba...
22/11/2024
Standards Pavilion elevates the role of standards in advancing climate action at COP29
Friday 22 November, Baku, Azerbaijan: As COP29 wraps up in Azerbaijan, the Stand...
22/11/2024
Let's Make Toy Show Day Official
Let's Make Toy Show Day Official The Late Late Toy Show | Friday December 6th | 9:35PM Watch Below The Late Late Toy Show is fast approaching and kids al...
22/11/2024
COOPANS, the Alliance Managing Europe's Largest Air Traffic Volume, Upgrades its Air Traffic Control (ATC) System with Thales
Facebook Twitter LinkedIn COOPANS is a leading international cooperation b...
22/11/2024
Press release
Facebook Twitter LinkedIn Thales confirms that the Parquet National Financier (PNF) in France and the Serious Fraud Office (SFO) in the United Kingdom hav...
22/11/2024
RT General Election 2024: Critical Election Period
The broadcasting regulator, Coimisi n na Me n has removed the traditional broadcast Moratorium for television and radio. In the past, this applied from 14:00 ...
21/11/2024
Neneh Cherry Takes Us on a Musical Journey Inspired by Her Memoir, A Thousand Threads'
Neneh Cherry, a musical trailblazer for more than three decades, is full of stor...
21/11/2024
6 Spotify Audiobook Features That Level Up Your Listening Experience
Since launching our audiobooks offering, we've continuously upped our game on designing a user experience that provides seamless and engaging listening. You...
21/11/2024
SEP 2024 / PAG launches new MPL150 Battery at IBC24
1ST SEPTEMBER 2024 PAG Ltd. UK, the creator of innovative, high-end portable power systems for the film and television industry, has announced the introduction...
21/11/2024
SEP 2024 / PAG Introduces new Cinergy Battery
1ST SEPTEMBER 2024 PAG Ltd. UK, the creator of innovative, high-end, portable power systems for the film and television industry, has announced the introductio...
21/11/2024
Celebrating The Best Of The Best
The HPA Awards exist to honor and recognize the accomplishments of the talented HPA community and to support their efforts with increased awareness and celebrat...
21/11/2024
L3Harris Co-Founder, Chair and CEO Chris Kubasik: Arsenal of Democracy 2.0 Will Require New Ways of Doing Business
He writes in POLITICO: When it comes to protecting our country, innovation and s...