
Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility
Cambridge, MA | July 31, 2019
Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.
The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.
We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.
Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.
Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.
Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.
In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.
Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.
The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.
The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
Most recent headlines
12/03/2025
CHICAGO Jeff Lilly has been named WGN-TV director of technology effective March 17, 2025, according to Ric Harris, WGN-TV vice president and general manager....
12/03/2025
MOUNTAIN VIEW, Calif. A new study from LG Ad Solutions indicates that consumers want more features that would allow them to shop for products on the connected T...
12/03/2025
BOTHELL, Wash. The Alliance for IP Media Solutions (AIMS), Advanced Media Workflow Association (AMWA) and the Video Services Forum (VSF) will once again present...
12/03/2025
PHILADELPHIA Comcast announced that it has upgraded Xfinity Internet speeds for more than 20 million customers for no additional cost....
12/03/2025
Create with Maxon: Cinema 4D Fundamentals Workshop - March 12-14
Brie Clayton March 11, 2025
0 Comments
Makin' Waffles with Elly Wade
During Marc...
11/03/2025
By Lucy Spicer
One of the most exciting things about the Sundance Film Festival...
11/03/2025
Salsa is making a comeback, captivating new listeners with its infectious energy...
11/03/2025
For many people, music can serve as a reflection of their roots and upbringing. ...
11/03/2025
The solution delivers reliable, scalable and secure connectivity for critical pu...
11/03/2025
SAN JOSE, Calif. Harmonic has announced that Weigel Broadcasting has deployed Harmonics VOS Media Software, which offers playout-to-delivery capabilities, inclu...
11/03/2025
NEW BERN, N.C. Wheatstone will introduce a Linux audio driver for its WheatNet IP audio network during the 2025 NAB Show, April 5-9, at the Las Vegas Convention...
11/03/2025
NEW YORK A new study finds that as TV viewership for women's sports surged by 131% in 2024, the programming also saw a 56% year-over-year increase in ad im...
11/03/2025
Powerful switcher for news studio
FOR-A, a cutting-edge video broadcast technology company backed by more than 50 years experience, has installed its HVS-1200 ...
11/03/2025
Intinor, Sweden's leading developer of high-quality video over the internet, is unveiling significant advancements to its Direkt series at NAB 2025. With a ...
11/03/2025
Glensound, a leader in high-quality audio systems, is bringing yet more innovation to NAB Show 2025 (Booth N2270, Las Vegas Convention Center, 6-9 April). Well-...
11/03/2025
Whittier, Calif.-based Anaconda Street Productions (ASP) is a leading film and television production company known for creating captivating content that resonat...
11/03/2025
DNAV, a full-service systems integrator, consultant, and manufacturer's representative of leading broadcast, AV, lighting, and display equipment, announces ...
11/03/2025
MNC Software Inc., a global leader in network solutions, is pleased to announce the appointment of Darren Frearson as its new Chief Executive Officer, effective...
11/03/2025
Polar Graphics, a UK leading distributor for the broadcast, post and pro-AV industries, has signed a licensing agreement with XenData to include its XenData Arc...
11/03/2025
Chyron PAINT 9.9 Delivers Sharper Visuals and Smoother Workflows for Sports Tele...
11/03/2025
Alice in Wonderlight Filmed with URSA Mini Pro 12K OLPF
Brie Clayton March 11, 2025
0 Comments
Play captured in 8K60p as part of national initiative t...
11/03/2025
Twisting in the Wind - An Apple Motion Tutorial
Simon Ubsdell March 11, 2025
0 Comments
Another very simple text-based project that uses an unusual co...
11/03/2025
The secret to looking inside a Project in Premiere Pro
Colin Smith March 11, 2025
0 Comments
This tutorial demonstrates the incredible capabilities of...
11/03/2025
New Book Explores How the Quiet Storm Shaped Modern R&B In The Quiet Storm, Berklee Online alumnus Amani Roberts explores how the radio format defined America...
11/03/2025
Slapshot aims to make VFX available for a range of users including independent editors, colourists, content creators and established visual effects companies
B...
11/03/2025
Aiming to attract international film production, the 16 million complex is scheduled to open next year
By Matthew Corrigan
Published: March 11, 2025
Aimi...
11/03/2025
Kamil Pietrzyk, support and projects manager at CueScript, tells TVBEurope how an interest in electronics and IT prompted a career in the broadcast industry
By...
11/03/2025
Underwater DoP Ian Seabrook on Last Breath Credit: Jon Borg / 2024 FOCUS FEATURES LLC
Canadian/British Director of Photography, Ian Seabrook is one of the ...
11/03/2025
Originally opened in the early 1960s as Moonglow Records, The Sound Factory name was coined by Producer David Hassinger, who purchased the studio in 1969. A lit...
11/03/2025
BCNEXXT, a trailblazer in virtualized, cloud-native systems for Linear, VoD, and OTT publishing, proudly marks a decade of redefining broadcast playout. This mi...
11/03/2025
Experience Commerce, an integrated marketing agency within the Cheil Network, has been appointed as the official digital partner for Parle Candy Culture, reinfo...
11/03/2025
PORTSMOUTH, N.H. A new survey highlights how far major streaming platforms have come in terms of offering sports, with findings that show the number of people ...
11/03/2025
TYSONS, Va. Tegna Inc. has announced today that John Trevi o has been named president and general manager at WKYC, the NBC affiliate serving Cleveland, Ohio, ef...
11/03/2025
BOSTON Brightcove has announced that Canela Media is using Brightcove's technologies to power its streaming operations....
11/03/2025
CESSON-SEVIGNE, France Chunghwa Telecom, the leading telecommunications operator in Taiwan, has selected Broadpeak to provide solutions for its streaming servic...
11/03/2025
Leader sets US debut of LPX500 Waveform Monitor for NAB 2025
Brie Clayton March 10, 2025
0 Comments
Test & measurement innovator, Leader Instruments C...
11/03/2025
The Berklee Institute of Jazz and Gender Justice Presents the Grand Gathering The Signature Series concert will feature performances by all nine of the instit...
11/03/2025
Abu Dhabi, UAE and Carlsbad, California 12 March 2025 Space42, (ADX: SPACE42...
11/03/2025
March 11th, 2025 Tribeca Enterprises, SIC, and the Lisbon City Council Announce...
11/03/2025
Drones, Flycam To Highlight 60+-Camera Coverage of THE PLAYERS This Weekend 60+ cameras, NEP's PGA TOUR fleet, 25 talent will be deployed at TPC Sawgrass B...
11/03/2025
The Art of 9:16: How Corporate Content Producers Have Embraced Vertical Video Leaders from the corporate space share their advice and success stories By SVG St...
11/03/2025
SVG Rewind: NFL's Tim Tubito on Elevating Gameday Activations of Super Bowl ...
11/03/2025
New Sponsor Spotlight: Ventuz's David Paniego on the Increasing Synergy Betw...
11/03/2025
Best Snow Day Ever: NESN, Bruins Roll Out NHL's Latest Animated Data-Visuali...
11/03/2025
To view this content, please enable our use of cookies. To do so, click Privacy ...
11/03/2025
Back to All News
Netflix Reveals Official Trailer for The Ladys CompanionPlay Video
Play Video
Entertainment
11 March 2025
GlobalSpain
Link copied to clip...
11/03/2025
Back to All News
Geeta Gandbhir's The Perfect Neighbor to Release on Netfli...
11/03/2025
The ROI of AI: New research on how AI is transforming B2B sales Published on Mar 11, 2025 Categories: Research, Data and insights
LinkedIn Corporate Commun...
11/03/2025
SAN JOSE, Calif. - March 11, 2025 - Harmonic (NASDAQ: HLIT) today announced that...
11/03/2025
Powerful new switcher for news studio...