18 Months, 61 Billion Credential-Stuffing Attacks

Stu Sjouwerman | Sep 18, 2019
iStock-1137591166

Akamai observed 61 billion credential stuffing attacks between January 2018 and June 2019, according to Computer Business Review. In a new report on Internet security, Akamai researchers say these attacks have grown more efficient and accessible due to low-cost automation tools that can evade detection.

35% of these attacks were focused on the tech, video media, and entertainment sectors. The researchers say these three industries are highly targeted because they offer a wealth of personal and corporate data.

Akamai explains that attackers have crafted applications that streamline and automate credential stuffing so that even low-skill criminals can launch these attacks. The tools include evasion capabilities that can defeat security mechanisms designed to thwart brute forcing. Some of these tools are free, and others sell for around $20.

Credential stuffing is a type of brute force attack in which an attacker tries to log into a victim’s account using millions of usernames and passwords that have been leaked in data breaches. Since most people unfortunately reuse passwords, this method is much more efficient than trying to guess every combination of characters. Computer Business Review notes that there are at least eight billion email addresses and 555 million passwords available online, and that number continues to rise with each data breach.

Credential stuffing attacks depend for their success on lax security practices. People can defend themselves by implementing two-factor authentication and using unique, complex passwords. New-school security awareness training can enable your employees to be mindful of their security posture.

Are your user’s passwords ... P@ssw0rd?

Identify which users are using easily guessable or brute-forceable credentials before cybercriminals do. 

Get Your Weak Password Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.