
Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years
Cambridge, MA | October 21, 2020
Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.
Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.
During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.
Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.
Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.
As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.
Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.
All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.
The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.
For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
Most recent headlines
13/03/2025
(L-R) Stephanie Suganami, Tatanka Means, John Malkovich, Ayo Edebiri, and Juliette Lewis attend the premiere of Opus at Eccles Theatre in Park City. (Photo by...
13/03/2025
Spotify took center stage at the London Book Fair this week, reaffirming our commitment to the audiobook market and showcasing our impact on the publishing indu...
13/03/2025
At Spotify, we work every day to lift up new voices, giving creators the opportunity to live off their art. Through Spotify Audiobooks, our in-house publishing ...
13/03/2025
Every time airborne law enforcement (ALE) teams fly, they expect their equipment to perform. Whether airborne units are conducting support for ground teams, bor...
13/03/2025
Sunday February 9 saw the annual return of the US' biggest television event, the Super Bowl LIX. Jamie McCombs, Fox Sports Audio Consultant / Sr. Audio capt...
13/03/2025
On Sunday March 2, stars across the film industry gathered at the Dolby Theatre in Los Angeles for the 97th Academy Awards. Production Sound Mixer Paul Sandweis...
13/03/2025
WUPPERTAL, Germany Riedel Communications will feature its new StageLink family of smart edge devices, Smart Audio and Mixing Engine (SAME) and Virtual Smart Pan...
13/03/2025
TAG Video Systems and Harmonic Partner to Deliver Enhanced Real-Time Monitoring ...
13/03/2025
DigitalGlue Invites NAB Visitors to Experience New Features in Managed Storage P...
13/03/2025
FOR-A America Theme - Connecting the Present, Building the Future - Comes to Lif...
13/03/2025
CTIA, the wireless industry association, has named former FCC Chairman Aji Pai as its President and Chief Executive Officer, effective April 1. He replaces Mere...
13/03/2025
he National Association of Broadcasters is urging the FCC to end its investigation of that controversial CBS interview with Kamala Harris stating there is no ...
13/03/2025
MIAMI CBS News & Stations continues to expand its use of augmented and virtual reality technologies with the planned launch of an augmented reality/virtual real...
13/03/2025
Srividhya Srinivasan, co-founder and chief customer success & innovation Officer at Amagi, tells TVBEurope how staying ahead of the latest trends is essential f...
13/03/2025
WASHINGTON FCC Chairman Brendan Carr announced that the agency has launched a massive, new deregulatory initiative that could potentially subject virtually all ...
13/03/2025
SUNNYVALE, Calif. SDVI has announced that it has integrated its Rally media supply chain management platform with the Spectra Vail multi-cloud data management s...
13/03/2025
ATLANTA Gray Media has announced that the Federal Communications Commission (FCC) has granted a waiver of its local ownership rules to permit Gray Media to acqu...
13/03/2025
TV Tech: What do you anticipate will be the most significant technology trends at the 2025 NAB Show?...
13/03/2025
Watch Student Naomi Soleils Folk Pop Performance on The Voice The songwriting major sang Stars by Grace Potter and the Nocturnals during the blind auditions.
...
13/03/2025
Roku Debuts NWSL Zone' Within Roku Sports to Spotlight Live Games, Content Feature marks Rokus first women's league-branded zone within service By Bra...
13/03/2025
Pixels, Images, Video, AI - and Us: A Perspective on AI from NDI Inventor Andrew...
13/03/2025
SVG New Sponsor Spotlight: Lighting Design Group's Steve Brill, Dennis Size ...
13/03/2025
IOC, Comcast NBCU Ink $3B Media-Rights Extension for Olympic Games Through 2036;...
13/03/2025
NCAA March Madness Live Returns with Expanded Availability of MultiView Vertical...
13/03/2025
SVG Sit-Down: Cosm's Devin Poolman on What It Takes To Deliver the Immersive...
13/03/2025
Sky Business, Sky's B2B division, providing connectivity and content to busi...
13/03/2025
Rohde & Schwarz launches R&S NRP140TWG(N) thermal power sensor: A new benchmark ...
13/03/2025
We asked the questions, analysed the answers and now we're excited to share the results of the fifth edition of the ICG Marketing Survey.
Our 2025 survey p...
13/03/2025
SAN JOSE, Calif. - March 13, 2025 Harmonic (NASDAQ: HLIT) today announced a breakthrough in video streaming innovation with the launch of new origin capabilitie...
13/03/2025
Haivision Showcases Mission-Critical Video Solutions at SOF Week 2025
Haivision's video wall systems, ISR technology, and DoDIN APL-certified video distri...
13/03/2025
Company Leads the Way with New Software-Based Production Platform, 12G Switcher,...
13/03/2025
A new Apple Immersive concert experience, Metallica, is coming to Apple Vision Pro this Friday, March 14. Filmed in Mexico City during the sold-out second-year ...
13/03/2025
Here is your host, Patrick Kielty!
Shake your Shamrocks, Patrick Kielty will be...
13/03/2025
This St. Patrick's weekend, RT invites you to celebrate all things Irish, showcasing the very best of Irish sport, entertainment and live coverage from the...
13/03/2025
What's next in AI is at GTC 2025. Not only the technology, but the people and ideas that are pushing AI forward - creating new opportunities, novel solution...
13/03/2025
Facebook
Twitter
LinkedIn
By combining T-Mobile's robust network, Thal...
13/03/2025
Bundle up - GeForce NOW is bringing a flurry of Blizzard titles to its ever-expanding library.
Prepare to weather epic gameplay in the cloud, tackling the genr...
13/03/2025
AI is leveling up the world's most beloved games, as the latest advancements...
13/03/2025
PC game modding is massive, with over 5 billion mods downloaded annually. Mods p...
12/03/2025
O Spotify acaba de lan ar o relat rio Loud & Clear deste ano, uma vis o transpar...
12/03/2025
Spotify acaba de presentar el informe Loud & Clear de este a o, una mirada trans...
12/03/2025
Ramadan, a period of profound spiritual significance for Muslims worldwide, is a time for fasting, prayer, reflection, and community. Enrich your experience thi...
12/03/2025
Spotify has just unveiled this year's Loud & Clear report, a transparent loo...
12/03/2025
More than 70% of FAST programming has been produced since 2010, according to new Gracenote report
NEW YORK March 12, 2025 Gracenote, the content data busin...
12/03/2025
GEONA, Nev. Independent digital and linear advertising rep firm Viamedia will adopt cloud-based ShowSeeker Pilot as its primary ad campaign and order management...
12/03/2025
BRUSSELS Mediagenix has announced that Wael Yasin has joined the company as sales director Central Europe....
12/03/2025
LONDON A new study highlights opportunities for shoppable TV and the massive impact online consumer spending is having on the economy, with Omdia predicting tha...
12/03/2025
CUPERTINO, Calif. Interra Systems has announced that Comcast Technology Solutions has integrated recent updates to BATON Version 9 into its operations....
12/03/2025
Nevion announces new 400G addition to its eMerge SDN media fabric offering
Brie Clayton March 12, 2025
0 Comments
High-capacity switch enhances existi...
12/03/2025
DaVinci Resolve Studio Delivers Cinematic Sound for Adam Bol
Brie Clayton March 12, 2025
0 Comments
Feature film relies on DaVinci Resolve Studio for ...