Sony Pixel Power calrec Sony

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers

01/08/2019

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility

Cambridge, MA | July 31, 2019

Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.

The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.

We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.

Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.

Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.

Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.

In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.

Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.

The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.

The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-...
See more stories from akami

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

21/03/2026

Survey: Fans Prefer Sports on Broadcast Over Streaming

Share Copy link Facebook X Linkedin Bluesky Email...

21/03/2026

Graham Promotes Stephanie Slagle to VP, CRO & GM of WDIV Local 4

Share Copy link Facebook X Linkedin Bluesky Email...

21/03/2026

Study: Repurposed Traditional TV Ads for CTV Is a Missed Opportunity

Share Copy link Facebook X Linkedin Bluesky Email...

21/03/2026

Carr Backs Trump Army/Navy Game Executive Order

Share Copy link Facebook X Linkedin Bluesky Email...

21/03/2026

Opponents File Emergency FCC Petition to Block Nexstar/Tegna Merger

Share Copy link Facebook X Linkedin Bluesky Email...

21/03/2026

Eight States Ask for Court to Stop Nexstar/Tegna Merger

Share Copy link Facebook X Linkedin Bluesky Email...

21/03/2026

Cine Gear Connect NY Ramps Up for March 28 - 2026

Cine Gear Connect NY, presented by Universal Production Services, is filling in the slate for a full day of panels, peers, learning the latest, and mixing it up...

21/03/2026

Studio Technologies Debuts New StudioComm System at NAB 2026

Studio Technologies Debuts New StudioComm System at NAB 2026 Brie Clayton March 20, 2026 0 Comments StudioComm Model 794 Central Controller and Model ...

21/03/2026

Restoration Christian Fellowship Captures Worship Music Videos with PYXIS 12K

Restoration Christian Fellowship Captures Worship Music Videos with PYXIS 12K Brie Clayton March 20, 2026 0 Comments PYXIS' open gate provides cre...

20/03/2026

NAB 2026: Net Insight unveils Market-Leading JPEG XS at Scale for Live IP Media Production

Net Insight will introduce a JPEG XS solution for full IP environments at NAB Sh...

20/03/2026

NAB 2026: LTN and Harmonic Expand Partnership to Support FAST Growth and C-Band Migration

LTN has expanded its technology partnership with Harmonic ahead of the FCC's...

20/03/2026

NAB 2026: Solid State Logic to Preview SSL Live V6.2 with New SolidPitch Effect and Major Workflow Enhancements

Solid State Logic will preview SSL Live V6.2 at NAB Show, booth C6907. The softw...

20/03/2026

NAB 2026: Fujifilm Announces Availability of FUJINON UA22x4.8BERD 4K Broadcast Zoom Lens

FUJIFILM North America Corporation's Optical Devices Division has announced ...

20/03/2026

NAB 2026: Fujifilm Announces Development of FUJINON UA16x4BERD, UA30x7.3BERD, and UA94x8.7BESM 4K Broadcast Zooms

FUJIFILM North America Corporation's Optical Devices Division has announced ...

20/03/2026

TrueVisions NOW Chooses Bitmovin's Observability

TrueVisions NOW, a streaming platform in Thailand and part of the TrueVisions Group, has selected Bitmovin's Observability product for real-time video analy...

20/03/2026

Marquee Sports Network Expands Distribution to Hulu + Live TV, Prime Video

Marquee Sports Network has announced distribution agreements with Hulu + Live TV and Prime Video ahead of the 2026 MLB season. Marquee Sports Network is now av...

20/03/2026

NAB 2026: Software-Defined, AI-Powered Workflow Tells the Story of the New FOR-A America

FOR-A will exhibit software-defined and AI-driven solutions at NAB Show 2026, bo...

20/03/2026

TNA Wrestling and Eurosport India Announce New Multi-Year Exclusive Programming Agreement

TNA Wrestling and Eurosport India have entered into a multi-year exclusive progr...

20/03/2026

GameTime Productions Expands Technical Vision for Athletes Unlimited Basketball in Nashville

When Athletes Unlimited brought its professional women's basketball season t...

20/03/2026

Calrec Craft Interview with Senior Broadcast Audio A1 Engineer and Music Director Rick Bernier

In this craft interview, Rick Bernier reflects on a career that has taken him to...

20/03/2026

NAB 2026: IP Innovation, SoftwareBased Media Infrastructure & Dynamic Media Facility Workflows on Display for Lawo

Lawo will announce a new product ahead of NAB Show 2026 in Las Vegas, where it w...

20/03/2026

Ratings Roundup: 2026 World Baseball Classic is Most Watched WBC Telecast EVER with Over 10 Million Viewers

Ratings Roundup is a rundown of recent rating news and is derived from press rel...

20/03/2026

MLB Names Polymarket Exclusive Prediction Market Exchange Partner and Signs Agreement with CFTC to Establish Integrity Framework

Major League Baseball (MLB) has named Polymarket as its Official Prediction Mark...

20/03/2026

How Big Tech AI Will Lead Broadcast Innovation: Lessons from the Enterprise Market

With AI now the industry-wide priority, Big Tech companies are uniquely position...

20/03/2026

SVG GameDay, Ep. 8: Los Angeles Angels' Davin Maske - SoCal Baseball in Anaheim

In-venue and creative video staffers at the professional and collegiate level ha...

20/03/2026

Fanatics Studios, FOX Sports Focus on Cavalcade of Stars in Fanatics Flag Football Classic

Abundant player mics and RF and other ground-level cameras will be used to captu...

20/03/2026

ESPN Ramps Up Production Levels for NCAA Women's Tournament as Popularity, Viewership Skyrocket

Regional site will also receive big boost in production resources, including on-...

20/03/2026

Give Me the Backstory: Get to Know Addison Heimann, the Writer-Director of Touch Me

By Jessica Herndon One of the most exciting things about the Sundance Film Fest...

20/03/2026

Spotify Marks 5 Years of EQUAL With EQUAL: The Podcast' and Global Events

In 2021, we launched EQUAL, a program designed to address an industry reality that persists: Women artists, songwriters, and producers too often face fewer oppo...

20/03/2026

Spotify's BTS Music Quiz Celebrates ARIRANG' and Puts ARMY Knowledge to the Test

BTS' long-awaited fifth studio album, ARIRANG, is finally here. To celebrate...

20/03/2026

Spotify and Kenia Os Bring K de Karma' From Streaming to Stage With Fan-First Experiences

A new era for Kenia Os has arrived, and Spotify marked the moment by putting fan...

20/03/2026

Spotify y Kenia Os llevan K de Karma' del streaming al escenario con experiencias nicas para Top Fans

Una nueva era para Kenia Os ha llegado, y Spotify marc el momento poniendo a lo...

20/03/2026

Sound Magic launch Supreme Drums Orange

Combines sampling & physical modelling Sound Magic have announced the launch of a comprehensive virtual drum instrument that's been designed to cater to...

20/03/2026

Mix Rescue: Ian Shepherd Video

How much difference should mastering make? In our latest Mix Rescue feature, SOS Editor in Chief Sam Inglis revisits a project from back in 2019, carrying o...

20/03/2026

Feast for cycling fans as SBS extends road cycling broadcasts to include all Grand Tours and Monuments

Feast for cycling fans as SBS extends road cycling broadcasts to include all Gra...

20/03/2026

London Calling - When The Industry Convened to Help Streaming Find its MoJo

In this blog, Laura Rognoni reflects on key discussions from the Connected TV World Summit in London, where NAGRAVISION hosted a panel on content discovery and ...

20/03/2026

The Gauge: Poland | February 2026

After a series of increases, February brought the first slowdown in time spent in front of TV sets in a long time. While traditional television was losing viewi...

20/03/2026

Eric Wolff Joins Chyron as Director of Venues Sales, North America

Share Copy link Facebook X Linkedin Bluesky Email...

20/03/2026

Study: Broadcasters Rebuild Live Operations Around IP

Share Copy link Facebook X Linkedin Bluesky Email...

20/03/2026

Matt Conrad Acquires DSC Labs

Share Copy link Facebook X Linkedin Bluesky Email...

20/03/2026

Glensound celebrates its diamond anniversary at NAB Show

60 years of audio innovation, driven by the people who use it...

20/03/2026

FCC Approves Nexstar's Acquisition of Tegna

Share Copy link Facebook X Linkedin Bluesky Email...

20/03/2026

Icesi names Ronald David Reyes as the 2025 recipient of t...

Colombia's Icesi University and WSDG are proud to announce Ronald David Reyes as the recipient of the 2025 WSDG Excellence Scholarship, awarded to an outsta...

20/03/2026

Celebrating the greatest creators - One Battle After Ano...

Avid today celebrated the filmmakers, editors and sound teams that worked with Avid Media Composer and Pro Tools to create the vast majority of this year'...

20/03/2026

MRMC Names CP Communications Its Official U.S. Rental, Sales Partner

Share Copy link Facebook X Linkedin Bluesky Email...