Cybersecurity firm Akamai has seen a 45% year-over-year increase in automated “credential stuffing” attacks, which use stolen user names and passwords to specifically target financial institutions.

The financial services industry is one of the hardest hit when it comes to this form of attack, said Steve Ragan, a security researcher at Akamai, a cybersecurity and cloud service company based in Cambridge, Mass.
“The financial services industry is actually one of the more frequently targeted verticals that we see,” Ragan said. “When we look at attacks and where criminals are targeting, it’s usually gaming, financial services, streaming media — usually in that order.”
In 2020, Akamai saw 3.4 billion credential stuffing attacks on financial services organizations, according to its May report, “Phishing for Finance.” Credential stuffing is a form of automated attack that uses stolen user names and passwords to try to get into accounts. The results are based on attacks monitored across Akamai’s own global network of 240,000 edge servers, which are positioned as close as possible to end users. For the report, Akamai looked at cybersecurity company WMC Global’s phishing data, plus distributed denial-of service credential abuse, and web attack data collected by Akamai’s sensors throughout the year. Overall, there were 193 billion credential stuffing attacks globally, according to the company. Details on the size of the institutions or dollar amounts of the attacks were not available.
Credential stuffing “is a consistent and large risk to organizations,” agreed Sander Vinberg, a threat researcher with F5 Labs, the research branch of Seattle-based cybersecurity firm F5.
“Financial organizations are very locked down; they don’t have credit card numbers sort of flying around, all their sensitive information is sort of sitting behind multiple layers of protection,” Vinberg said. “That makes a credential stuffing attack a really good vector against the financial organization.”
Credential stuffing relies on automation
Credential stuffing is an automated attack. There are a number of scripts available online that allow criminals to upload lists of usernames and passwords, point these tools to an account login page and run hundreds of name and password combinations against it, hoping to find one that works, Akamai’s Ragan explained.
This particular type of attack is different from a brute force attack, in which the attacker has a username and throws passwords at a login, trying to find a fit. Instead, the logins and passwords are already matched, so the attack relies on people reusing the same login and password across multiple sites.
Read more: RockYou2021 breach makes splash, but looks more like hype than threat
Typically, attackers can buy a log file on the dark web with a list of usernames and passwords for about $5 per 100,000 combinations, Ragan said. However, by the time the files are sold online, they’ve likely already been exploited by a more sophisticated attacker, Vinberg said.
Once a login is successful, the attacker can drain an account or collect the personal information associated with it to sell it for use in identity theft or financial fraud scheme, Ragan said.
Credential stuffing also can target more than customer accounts; banks are at risk of attacks that target their owns backend systems, Vinberg said.
Defending against credential stuffing
Multifactor authentication is the first line of defense, Ragan said. It’s also important to look for rapid changes in the success rate of authentication, Vinberg said. Generally, research shows humans succeed in their login attempts about 66% of the time, Vinberg said. If that drops to 10% — unless there’s some sort of promotional event, chances are there’s a credential stuffing attack running against the login, he said.
Staying aware is crucial.
“The very first start would be: Make sure you’re actually watching your logs, and you have a lot of situational awareness,” Vinberg said. “After that, if you know you are actually seeing coordinated campaigns against your organization, start talking to law enforcement early.”






