You Have Not Suffered A Data Breach But How Do You Prevent Credential-Stuffing Attacks?

Stu Sjouwerman | Dec 5, 2019

Weak Password Test_1200x675-1Frequent data breaches and the widespread availability of automated tools to take advantage of the compromised information have greatly increased the efficiency of credential stuffing attacks, according to Sumit Agarwal, COO of Shape Security and former US Deputy Assistant Secretary of Defense.

In an interview with TechRepublic, Agarwal explained that credential stuffing is the use of stolen credentials to launch automated attacks against login forms. There are billions of stolen credentials for sale on the dark web. Since most people reuse passwords, the attackers have a good chance of finding another account that uses that same credentials.

Agarwal noted that all organizations can be vulnerable to credential stuffing, since they have no control over which passwords their employees use on other platforms.

“The most remarkable aspect of credential stuffing is that a given business does not have to be breached itself to suffer from credential stuffing,” Agarwal said. “The vulnerability is simply having a login form and having users.”

Agarwal said the first thing organizations need to do is realize they’re probably already facing credential stuffing attacks. They should therefore be monitoring accounts for brute forcing attacks and unusual login patterns. Organizations should also encourage their employees to use password managers rather than using the same password across many different accounts. New-school security awareness training can teach your employees about the ways they can be targeted by attackers and how to defend themselves and their organization.

TechRepublic has the story: https://www.techrepublic.com/article/how-credential-stuffing-attacks-work-and-how-to-prevent-them/

Are your user’s passwords ... P@ssw0rd?

Identify which users are using easily guessable or brute-forceable credentials before cybercriminals do. 

Get Your Weak Password Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.