FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

‘Credential stuffing’ attacks on the rise at banks

The automated cyberattacks rely on known password and login combinations

Loraine LawsonbyLoraine Lawson
June 21, 2021
in Strategy
Reading Time: 3 mins read
0
Share on Facebook

Cybersecurity firm Akamai has seen a 45% year-over-year increase in automated “credential stuffing” attacks, which use stolen user names and passwords to specifically target financial institutions.

Image by CanStock

The financial services industry is one of the hardest hit when it comes to this form of attack, said Steve Ragan, a security researcher at Akamai, a cybersecurity and cloud service company based in Cambridge, Mass.

“The financial services industry is actually one of the more frequently targeted verticals that we see,” Ragan said. “When we look at attacks and where criminals are targeting, it’s usually gaming, financial services, streaming media — usually in that order.”

In 2020, Akamai saw 3.4 billion credential stuffing attacks on financial services organizations, according to its May report, “Phishing for Finance.” Credential stuffing is a form of automated attack that uses stolen user names and passwords to try to get into accounts. The results are based on attacks monitored across Akamai’s own global network of 240,000 edge servers, which are positioned as close as possible to end users. For the report, Akamai looked at cybersecurity company WMC Global’s phishing data, plus distributed denial-of service credential abuse, and web attack data collected by Akamai’s sensors throughout the year. Overall, there were 193 billion credential stuffing attacks globally, according to the company. Details on the size of the institutions or dollar amounts of the attacks were not available.

Credential stuffing “is a consistent and large risk to organizations,” agreed Sander Vinberg, a threat researcher with F5 Labs, the research branch of Seattle-based cybersecurity firm F5.

“Financial organizations are very locked down; they don’t have credit card numbers sort of flying around, all their sensitive information is sort of sitting behind multiple layers of protection,” Vinberg said. “That makes a credential stuffing attack a really good vector against the financial organization.”

Credential stuffing relies on automation

Credential stuffing is an automated attack. There are a number of scripts available online that allow criminals to upload lists of usernames and passwords, point these tools to an account login page and run hundreds of name and password combinations against it, hoping to find one that works, Akamai’s Ragan explained.

This particular type of attack is different from a brute force attack, in which the attacker has a username and throws passwords at a login, trying to find a fit. Instead, the logins and passwords are already matched, so the attack relies on people reusing the same login and password across multiple sites.

Read more: RockYou2021 breach makes splash, but looks more like hype than threat

Typically, attackers can buy a log file on the dark web with a list of usernames and passwords for about $5 per 100,000 combinations, Ragan said. However, by the time the files are sold online, they’ve likely already been exploited by a more sophisticated attacker, Vinberg said.

Once a login is successful, the attacker can drain an account or collect the personal information associated with it to sell it for use in identity theft or financial fraud scheme, Ragan said.

Credential stuffing also can target more than customer accounts; banks are at risk of attacks that target their owns backend systems, Vinberg said.

Defending against credential stuffing

Multifactor authentication is the first line of defense, Ragan said. It’s also important to look for rapid changes in the success rate of authentication, Vinberg said. Generally, research shows humans succeed in their login attempts about 66% of the time, Vinberg said. If that drops to 10% — unless there’s some sort of promotional event, chances are there’s a credential stuffing attack running against the login, he said.

Staying aware is crucial.

“The very first start would be: Make sure you’re actually watching your logs, and you have a lot of situational awareness,” Vinberg said. “After that, if you know you are actually seeing coordinated campaigns against your organization, start talking to law enforcement early.”

Tags: cyberattackscybercrimecybersecurityPremium
Previous Post

A $130M crypto quant nets big returns as options boom

Next Post

Mastercard taps upSWOT to provide automated business cash-flow solution

Related Posts

Leveraging codeless architecture to improve successful merger integration
Strategy

COBOL modernization gets AI upgrade, but scale remains elusive

July 21, 2026
A Microsoft data center in Aldie, Virginia, US, on Tuesday, Oct. 28, 2025. Microsoft Corp. is scheduled to release earnings figures on October 29. Photographer: Lexi Critchett/Bloomberg
Strategy

Data centers on track to suck up a fifth of US power use by 2035

July 21, 2026
Strategy

BMO, IBM weigh in on agentic AI-quantum synergy

July 20, 2026
Next Post
Image: Jake Colling/Unsplash

Mastercard taps upSWOT to provide automated business cash-flow solution

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account