Sony Pixel Power calrec Sony

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers

01/08/2019

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility

Cambridge, MA | July 31, 2019

Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.

The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.

We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.

Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.

Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.

Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.

In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.

Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.

The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.

The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-...
See more stories from akami

Most recent headlines

19/12/2025

Queensland Performing Arts Centre Elevates Live Stream Ex...

Performing arts centres across the globe have doubled down on live production infrastructure in recent years. For venues like the Queensland Performing Arts Cen...

19/12/2025

FCC's Brendan Carr Stands Up for His Policies at Senate Hearing

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Nexstar Brand Studio Launches with 'My American Story Campaign'

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Nashville To Host 2026 AES Show

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

NAB Launches Effort to Keep Live Sports on Broadcast Channels

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

FCC Votes to Adopt New Rules for LPTV Stations

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Hearst Television Ups Mike Kronenfeld to VP, National Sales

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Ricardo Coke-Thomas Named Chair of Theater for Boston Conservatory at Berklee

Ricardo Coke-Thomas Named Chair of Theater for Boston Conservatory at Berklee The distinguished theater educator, director, and performer will join the Conser...

19/12/2025

RT is turning up the volume at the 2026 Stripe Young Scientist & Technology Exhibition

RT is proud to return to the RDS to support the 2026 Stripe Young Scientist & T...

19/12/2025

December 18, 2025

Nanoparticle vaccine strategy could protect against Ebola and other deadly filoviruses Scripps Research scientists turn nanoparticles into virus showcases to ...

18/12/2025

SVG Campus Shot Callers: Kurt Sutton, Director of Broadcast Operations, Clemson University

SVG Campus Shot Callers: Kurt Sutton, Director of Broadcast Operations, Clemson ...

18/12/2025

Follow the Money Episode 2: Inside the Sports Media Biz with Sam McCleery and Steve Hellmuth

Follow the Money Episode 2: Inside the Sports Media Biz with Sam McCleery and St...

18/12/2025

SVG Sit-Down: Google Cloud's Anshul Kapoor on the Future of Generative Production' in Live Sports

SVG Sit-Down: Google Cloud's Anshul Kapoor on the Future of Generative Prod...

18/12/2025

The 2025 SVG Summit Draws Record Crowd for 20th-Annual Sports-Production Industry Homecoming in NYC

The 2025 SVG Summit Draws Record Crowd for 20th-Annual Sports-Production Industr...

18/12/2025

SBS's sports schedule sizzles in January with Dakar Rally, Kooyong Classic and Mapei Cadel Evans Great Ocean Road Race

SBS's sports schedule sizzles in January with Dakar Rally, Kooyong Classic a...

18/12/2025

Montreal's Bell Centre elevates fan experience with Argo S

Canada's largest indoor arena has transformed its live production capabilities with a full ST 2110 infrastructure and Calrec's compact Argo S console. S...

18/12/2025

The Gauge: Mexico November 2025

During November, streaming's share of TV viewing in Mexico settled at 24.2%, an increase of 0.5 share points from the previous month. Disclaimer: YUMI TV,...

18/12/2025

The Gauge: Poland | November 2025

November continued the upward trend in television viewership. The significantly colder weather and a rich programming lineup encouraged viewers to spend more ti...

18/12/2025

Gracenote helps TV platforms go beyond the game and deliver more connected, visually rich sports hub experiences

As viewers turn to sports highlights, recaps and documentary programming, expand...

18/12/2025

NAB Once Again Urges FCC to Eliminate Ownership Rules

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

Carr Stands Up for His Policies in Senate Hearing

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

The HELM and ARRI announce strategic partnership to redef...

The HELM, a global expert in cinematic live broadcast and high-end production workflows, has entered a strategic partnership with ARRI, the renowned designer an...

18/12/2025

Cadena Melodia Upgrades to DHD SX2 Audio Production Conso...

Cadena Melod a de Colombia (Cadena Melod a), a long-established Colombian radio network, has chosen DHD audio SX2 production consoles for integration into the m...

18/12/2025

Czech TV Elevates Video Streaming with Harmonic

Harmonic (NASDAQ: HLIT) today announced that Czech Television (Czech TV), the public broadcaster of the Czech Republic, has teamed up with Harmonic to modernize...

18/12/2025

Broadcast Solutions Group acquires PMT Professional Motio...

Broadcast Solutions Group, a leading system integrator and provider of innovative solutions for the broadcast and media industry, has announced the acquisition ...

18/12/2025

Keepit named a Leader in IDC MarketScape for Worldwide Sa...

Keepit, the SaaS data protection company, announced today that it has been named a Leader in the IDC MarketScape: Worldwide SaaS Data Protection 2025-2026 Vendo...

18/12/2025

Limecraft 2025 Version 8 adds User Controlled Notificatio...

Limecraft today announced the release of Limecraft 2025.8, the eighth and final major platform update of the year. This release strengthens daily workflows acro...

18/12/2025

creativespace Expands Footprint in the House of Worship M...

DigitalGlue is very grateful, especially at this time of the year, that its creative.space platform has expanded its footprint within the House of Worship marke...

18/12/2025

TAG Video Systems Celebrates Multiple APAC Award Wins for...

TAG Video Systems is proud to share that the company has recently received multiple industry recognitions across the Asia-Pacific region, reflecting its ongoing...

18/12/2025

NDI and Zoom team up to bring seamless connectivity to me...

NDI, the leading video connectivity standard for AV-over-IP, and Zoom, the AI-first collaboration platform, announce a strategic collaboration to integrate the ...

18/12/2025

YES and Synamedia extended deal backs Partner TV launch

Leading video software provider, Synamedia, today announced that it is extending its long-standing relationship with YES, the pay-TV subsidiary of the largest I...

18/12/2025

Riedel Builds Global Communication and Commentary Network...

Riedel Communications today announced it provided a fully integrated communications and commentary solution for the 15th National Games of China, supporting 56 ...

18/12/2025

Clear-Com Arcadia Central Station Links Toledo Walleye an...

When both the Toledo Walleye and Toledo Mud Hens play at home on the same night, communication between their respective production teams is essential. To stream...

18/12/2025

TMT Insights Focus Platform Recognized with TV Tech Best...

TMT Insights' new upstream media supply chain platform, Focus, was selected as a winner in the 2025 Media & Entertainment: Best in Market Awards in the TV T...

18/12/2025

Clear-Com Named Official Intercom Partner for NAMMs 125th...

Clear-Com is proud to announce its continued role as the official intercom supplier for the Yamaha Grand Plaza Stage at The 2026 NAMM Show, taking place Januar...

18/12/2025

CES: NBCU Unveils New Cross-Platform Ad Tech Solutions, Capabilities

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

2026 NAB Show Opens Registration, Unveils Major Program Enhancements

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

YouTube Wins Global Rights to Stream the Oscars

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

PGA TOUR Studios Teams up with SES for Hybrid Content Distribution

Long-term agreement includes the SES SCORE platform and hybrid distribution worldwide to deliver more than 5,000 hours of golf tournaments annually featuring th...

18/12/2025

NVIDIA, US Government to Boost AI Infrastructure and R&D Investments Through Landmark Genesis Mission

NVIDIA will join the U.S. Department of Energy's (DOE) Genesis Mission as a ...

18/12/2025

Master Clock Management with Segment Rulesets in WO Automation for Radio

Talk formats require careful clock management and system tools to ensure audio content aligns as intended. WO Automation for Radio's Segment Rulesets provid...

18/12/2025

Reflecting on 2025: A Year of Transformation and Growth

By Toni Coonce, CEO, WideOrbit As 2025 comes to a close, I find myself reflecting on how much WideOrbit has evolved, not only in products and solutions but also...

18/12/2025

VEON Upgraded to Nasdaq Global Select Market, Enhancing Investor Visibility

18 Dec 2025 VEON Upgraded to Nasdaq Global Select Market, Enhancing Investor Visibility Dubai, December 18, 2025 - VEON Ltd. (Nasdaq: VEON), a global digital o...

18/12/2025

Tribeca X Launches Inaugural Advisory Council, Teases 2026 Awards Jury, and Announces New Global Programming

December 18th, 2025 Tribeca X Launches Inaugural Advisory Council, Teases 202...

18/12/2025

Tribeca Becomes First Major Film Festival to Open Submissions to Social Media Creators

December 18th, 2025 As Tribeca Celebrates Its 25th Anniversary, Festival Expa...

18/12/2025

Sky Sports remains the exclusive home of the Masters Tournament, with more live coverage than ever before

Thursday 18 December 2025 Sky Sports remains the exclusive home of the Masters ...

18/12/2025

Teaser for Can This Love Be Translated' Previews a Heartwarming Romance To Open 2026

Back to All News Teaser for Can This Love Be Translated' Previews a Heartw...

18/12/2025

2025-11-18

Using the additive process of 3D printing, layer after layer gets printed until an object is as close to the final shape needed as possible. Historically, machi...

18/12/2025

RT Supporting the Arts 2025 Review | January 2026 Events

In 2025, RT proudly supported 185 arts and cultural events across the island of Ireland, reflecting significant growth since the scheme was re-launched in 2014...

18/12/2025

The RT Sport Young Sportsperson of the Year Nominees 2025 Revealed

RT Sports Awards 2025 live on RT One and RT Player at 8:05pm on Saturday 20 December On Saturday 20 December live on RT One and RT Player at the earlier t...