Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers
01/08/2019
Cambridge, MA | July 31, 2019
Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.
The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.
We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.
Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.
Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.
Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.
In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.
Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.
The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.
The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: | https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-... |
See more stories from akami |
Most recent headlines
04/02/2025
Spotify Reports Fourth Quarter 2024 Earnings
Today, we announced our fourth quarter 2024 earnings, closing Q4 stronger than ever by outperforming across key metrics and celebrating our first full year of p...
04/02/2025
Spotify rapporterar intkter fr fjrde kvartalet 2024
Idag rapporterar vi int kter f r fj rde kvartalet 2024. Vi avslutade Q4 starkare n n gonsin genom att vertr ffa f rv ntningarna p v ra nyckeltal och kan d rm...
04/02/2025
SGL Carbon opts for green electricity at its German sites
As a technology-based company and one of the worlds leading companies in the development and production of carbon-based solutions, SGL Carbon opts for innovativ...
04/02/2025
ST Engineering iDirect Names Sridhar Kuppanna as Chief Technology Officer
Ground segment technology innovator appoints new CTO to execute bold technological vision Herndon, Va., February 4, 2025 ST Engineering iDirect, global leade...
04/02/2025
L3Harris Signs Multi-Year Pilot Training Agreement With Thai Airways
L3Harris has signed a two-year agreement with Thai Airways International to provide training service on its A320 Full Flight Simulator (FFS). This significant a...
04/02/2025
US Air Force Completes First Flight of L3Harris Viper Shield Electronic Warfare System
L3Harris' all-digital electronic warfare suite, Viper Shield , completed its...
04/02/2025
Radio Botswana chooses Calrec's IP-native Type R mixing system
The shift from analogue to IP was driven by a desire for greater flexibility in our operations. IP simplifies connectivity, reduces the physical footprint of th...
04/02/2025
Simplifying Gray Media News Operations with Calrec's Type R
Streamline, standardise and save: how Gray Media has simplified news operations At TVNewsCheck's News Tech Forum 2024, Gray Media's Peter Gogas and Calr...
04/02/2025
Bending Spoons closes $233 million acquisition of Brightcove
Boston, MA-February 4, 2025 | Bending Spoons, the Italy-based technology company, completed its previously announced acquisition of US-based streaming technolog...
04/02/2025
PARAMOUNT AND NIELSEN SIGN MULTI-YEAR MEASUREMENT AND ANALYTICS DEAL ACROSS PARAMOUNT'S LEADING BROADCAST, CABLE AND STREAMING PLATFORMS
Nielsen Reports Major Recent Ratings Milestones for CBS and Paramount Series N...
04/02/2025
Grup Mediapro to Collaborate with Google Cloud on Gen AI
BARCELONA Grup Mediapro and Google Cloud have expanded their collaboration to create an innovation lab focused on generative AI to develop solutions for the med...
04/02/2025
EditShare Receives SOCE 2 Type II Certification
WATERTOWN, Mass. EditShare this week said it has received SOC 2 Type II certification, an independently audited evaluation of an organization's information ...
04/02/2025
Executive Creative Director Halle Petro Named Partner of Sonic Union
Executive Creative Director Halle Petro Named Partner of Sonic Union Brie Clayton February 4, 2025 0 Comments Sonic Union is excited to announce Execu...
04/02/2025
Blackmagic Design Announces Blackmagic Camera for Android 2.0 Update
Blackmagic Design Announces Blackmagic Camera for Android 2.0 Update Brie Clayton February 4, 2025 0 Comments New update adds support for Xiaomi Pad 6...
04/02/2025
CETA Software Launches Artist Access: The Time-Tracking Tool for Creative Teams
CETA Software Launches Artist Access: The Time-Tracking Tool for Creative Teams Brie Clayton February 4, 2025 0 Comments CETA Software, creators of p...
04/02/2025
OWC Announces General Availability Launch of OWC Dock Ejector 2.0
OWC Announces General Availability Launch of OWC Dock Ejector 2.0 Brie Clayton February 4, 2025 0 Comments The Ultimate Tool for Efficiently and Safel...
04/02/2025
Colourist Claudio Del Bravo on grading Queer
Explaining the process to TVBEurope, Del Bravo said the films look was inspired by the Technicolor three-strip' process, evoking the rich colours of early ...
04/02/2025
Paramount, Nielsen Sign Multiyear Measurement and Analytics Deal
NEW YORK Paramount Global and Nielsen have inked a new, multiyear deal that will provide measurement for all of the company's platforms, including national ...
04/02/2025
2d Animated Short Concerning a Project for Schools
2d Animated Short Concerning a Project for Schools Brie Clayton February 3, 2025 0 Comments 2d animated short concerning a project for schools Febru...
04/02/2025
Step by step guide to using 3D Models in After Effects
Step by step guide to using 3D Models in After Effects Graham Quince February 3, 2025 0 Comments Since 2024, Adobe After Effects has had native suppor...
04/02/2025
Powerful Premiere Automation with new Excalibur Update
Powerful Premiere Automation with new Excalibur Update Colin Smith February 3, 2025 0 Comments This tutorial takes you through the new update for auto...
04/02/2025
Cinematography of A Complete Unknown: Shooting 12,800 iso Sony Venice 2 to create a 1960's era film
Cinematography of A Complete Unknown: Shooting 12,800 iso Sony Venice 2 to creat...
04/02/2025
DIY to DA: Ela Minus Breaks Through
DIY to D A: Ela Minus Breaks Through The electronic artist and producer tells Rolling Stone about her new album, D A, and how shes forged a career outside the...
04/02/2025
The Future of Football? Technology and Entertainment Merge in the Kings World Cup Nations
The future of football? Technology and entertainment merge in the Kings World Cu...
04/02/2025
Virtual Production and AR Graphics: Demystifying the Tools, Technologies, and Trends
Virtual Production and AR Graphics: Demystifying the Tools, Technologies, and Tr...
04/02/2025
SVG All-Stars: Russell Fink, Senior Director, Programming and Content Analytics, SNY
SVG All-Stars: Russell Fink, Senior Director, Programming and Content Analytics,...
04/02/2025
SVG New Sponsor Spotlight: farmerswife's Jodi Clifford on Organizing Your Productions Like a Professional
SVG New Sponsor Spotlight: farmerswife's Jodi Clifford on Organizing Your Pr...
04/02/2025
EA Acquires TRACAB Technologies as It Looks to Move Beyond Games
EA Acquires TRACAB Technologies as It Looks to Move Beyond Games EA believes TRACABs sports tracking/analysis technology will help to make the EA SPORTS App the...
04/02/2025
Kingdom Come: Alamiya Media on Bringing the Supercoppa Italiana and Supercopa de Espaa to Saudi Arabia
Kingdom come: Alamiya Media on bringing the Supercoppa Italiana and Supercopa de...
04/02/2025
Alamiya Media at 50: Preparing for Rapid Change, an International Broadcast Center and the FIFA World Cup
Alamiya Media at 50: Preparing for rapid change, an international broadcast cent...
04/02/2025
An update on our TV and broadband prices
An update on our TV and broadband pricesTuesday 4 February 2025 An update on our TV and broadband prices Devesh Raj, Chief Operating Officer, Sky This April,...
04/02/2025
Sky extends partnership with the PDC to remain the home of darts until 2030
Sky extends partnership with the PDC to remain the home of darts until 2030Tuesday 4 February 2025 Following another record-breaking PDC World Darts Championsh...
04/02/2025
Frankfurt is the world's first airport to regularly use walk-through scanners from Rohde & Schwarz for passengers
Frankfurt is the world's first airport to regularly use walk-through scanner...
04/02/2025
Riedel Unveils Next Generation of StageLink Edge Devices
Wuppertal February 4, 2025 Riedel Unveils Next Generation of StageLink Edge DevicesRiedel Communications today announced the launch of its StageLink family of...
04/02/2025
Clara Galle, Claudia Salas and Paula Usero Star in 'That Night,' the New Netflix Series Based on the Bestselling Novel by Gillian McAllister
Back to All News Clara Galle, Claudia Salas and Paula Usero Star in That Night,...
04/02/2025
Fox Corporation Reports Second Quarter Fiscal 2025 Financial Results
Fox Corporation Reports Second Quarter Fiscal 2025 Financial Results NEW YORK, NY, February 4, 2025 - Fox Corporation (Nasdaq: FOXA, FOX; FOX or the Compan...
04/02/2025
Introducing our fully digital, true diversity wideband wireless mic solution
DPA Microphones is moving into the wireless market with the release of its new N-Series Digital Wireless System at ISE 2025 (Stand 7P600). A fully digital, true...
04/02/2025
2025-02-04
CUPERTINO, CALIFORNIA Apple today introduced Apple Invites, a new app for iPhone that helps users create custom invitations to gather friends and family for any...
04/02/2025
ABS appoints Sameer Karimbhai as New General Counsel
ABS appoints Sameer Karimbhai as New General Counsel...
04/02/2025
Thales Alenia Space signs a contract with Mohammed Bin Rashid Space Centre to develop the Emirates Airlock Module, a critical element of Lunar Gateway
Facebook Twitter LinkedIn Thales Alenia Space strengthens its cooperation with the UAE as a key partner in future space missions Cannes, February 4th, 20...
04/02/2025
RT Internship Programme 2025 - Applications Now Open
We're thrilled to announce that applications for the 2025 RT Internship Programme are now open....
04/02/2025
Jack Woolley tops the Dancing with the Stars leaderboard in Dedicated Dance Week
Jack Woolley topped the leaderboard in what was an emotional night on Dancing with the Stars, as the remaining nine couples took to the floor for Dedicated Danc...
03/02/2025
Spotify's This Is Taylor Swift' Immersive Experience Connects Swifties Across Asia to Their Favorite Anthem
If you're one of the many Swifties living in Asia, you're in for a treat...
03/02/2025
5 Spotify Hacks Every Free User Needs To Know
Whether you're discovering your new favorite song or queuing up the latest episode of the hottest podcasts, Spotify is always innovating to deliver the best...
03/02/2025
SBS boosts commitment to Indigenous leadership and innovation with Executive team update
SBS boosts commitment to Indigenous leadership and innovation with Executive tea...
03/02/2025
L3Harris Technology Enhances US Torpedo Capability
The L3Harris IPLCS is a fiber-optic tether connecting a torpedo to the origin vessel, providing data in real time. Credit: L3Harris...
03/02/2025
VidTrans 2025 to Focus on Security, Dynamic Media Production
BOTHELL, Wash. Video Services Forum (VSF) today announced that the VidTrans 2025 conference and exposition will take place Feb. 25-27 at the Marina del Rey Marr...
03/02/2025
Legislation Proposed to Require Refunds During TV Blackouts
WASHINGTON Last week Rep. Pat Ryan (D-N.Y.) and Sen. Chris Murphy (D-Conn.) introduced the Stop Sports Blackouts Act to make cable and satellite companies ref...
03/02/2025
New Vendors Gain Amazon Prime Video Preferred Certification
Amazon Prime Video has added more companies to its Preferred Vendor Services Program....
03/02/2025
Grand Slam Track Inks Media Rights Deal with The CW, NBC Sports
BURBANK, Calif. The CW, NBC Sports and Grand Slam Track, a new global track competition, have announced a media rights deal that makes The CW the exclusive U.S....