Sony Pixel Power calrec Sony

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers

01/08/2019

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility

Cambridge, MA | July 31, 2019

Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.

The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.

We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.

Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.

Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.

Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.

In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.

Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.

The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.

The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-...
See more stories from akami

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

05/06/2026

Nielsen, Mediaocean Announce New Integration to Power The Next Phase of Data-Driven Linear, Advanced Audience Measurement

MRI-Simmons and S&P Global Mobility are expanding advanced audience capabilities...

05/06/2026

Latest Nielsen data reveals insurance advertising climbs as Australians weigh cost, cover and loyalty

New Nielsen data shows insurance ad spend grew 11%, while consumers remain highl...

05/06/2026

Nielsen Adds New Audience Data Partnerships

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

ASG Promotes Joe Marchitto to Western Regional CTO

ASG Promotes Joe Marchitto to Western Regional CTO Brie Clayton June 5, 2026 0 Comments Appointment to Support Engineering Alignment and Client Experi...

05/06/2026

Stargate Studios Colombia Uses DaVinci Resolve Studio for Vertical Microdramas

Stargate Studios Colombia Uses DaVinci Resolve Studio for Vertical Microdramas Brie Clayton June 5, 2026 0 Comments End to end post in one platform al...

05/06/2026

People Need to Come First When We Use AI

People Need to Come First When We Use AI Andy Marken June 5, 2026 0 Comments It's just surviving. Life's very existence requires destruction....

05/06/2026

Fahad Haider Joins NESN as VP, Operations and Engineering

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

GatesAir Opens New Brazil Office to Back DTV+ Rollout

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

Supreme Court Upholds FCC's Authority to Levy Fines

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

Montclair State University Will Run NJ PBS

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

Merkhet's Sam Matheny Urges Congress to Expedite BPS Deployment

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

Sinclair Launches NextGen TV Campaign in Columbus, Ohio

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

NAB Releases New Keep the Game On' Spot

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

NCTC, ACAC Going to Disney World for Independent Show

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

Nielsen Announces New Integrations for Improved Measurement

Share Copy link Facebook X Linkedin Bluesky Email...

05/06/2026

Frequency Launches In-Scene Advertising to Accelerate Str...

Frequency, the engine powering many of the world's leading streaming television channels, today announced the launch of In-Scene Advertising, a new monetiza...

05/06/2026

Berklee Study Reveals Video Has Become Essential to Music Careers

Berklee Study Reveals Video Has Become Essential to Music Careers Survey findings show social platforms have become the primary source of music for video cont...

05/06/2026

RT Radio 1 Folk Awards 2026 Date Announcement

RT Radio 1 Folk Awards to take place on Tuesday 10th November 2026, Vicar Street, Dublin Moya Brennan, D nal Lunny, Mary Black and Christy Moore among previou...

04/06/2026

Sony's New PTZ Cameras Deliver 4K 60p; New STARVIS Sensor Meets Low-Light Demands

Sony Electronics is introducing the SRG-AS10, a 4K 60p-compatible PTZ auto-frami...

04/06/2026

SVG Students To Watch: Alex Albert, Texas A&M University

This recent grad from Spring, TX, led creative-video output for the Aggies' men's basketball team last season and has been producing video and creating ...

04/06/2026

USGA Brings AI Recaps, 3D Range Tracking, and Predictive Shot Tracing to U.S. Womens Open

For the first time at a women's golf major, every player in the field will r...

04/06/2026

Panasonic PT-RQ45 Projectors Power Lille Video Mapping Festival Opera House Installation

Three Panasonic PT-RQ45 40,000-lumen 3-Chip DLP projectors made their first live...

04/06/2026

Bitmovin and Akamai Support NRJ Groups Deployment of Akamai Adaptive Media Player 2

Bitmovin and Akamai have announced a collaboration with NRJ Group, a French mult...

04/06/2026

Telestream to Exhibit at InfoComm 2026 with Live Production and Media Workflow Demonstrations

Telestream will exhibit at InfoComm 2026 (Booth N7952), demonstrating media work...

04/06/2026

Sony Announces RIALTO 65 Image Sensor Block for VENICE 2, Targeting 2027 Release

Sony has announced the development of RIALTO 65, a 65mm format image sensor block for the VENICE 2 digital cinema camera, targeting release in the first half of...

04/06/2026

KOKUSAI DENKI Electric America to Exhibit 4K and Remote Production Solutions at InfoComm 2026

KOKUSAI DENKI Electric America will exhibit at InfoComm 2026 (Booth N8025, June ...

04/06/2026

Bell Media to Carry All 104 FIFA World Cup 2026 Matches Across TSN, RDS, and Streaming Platforms

Bell Media's TSN and RDS are the exclusive Canadian broadcasters of FIFA Wor...

04/06/2026

MASV Case Study: How MASV Reduced Miami HEAT's Road Game Video Transfer Times by 85%

The Challenge: Receiving Heavy Media Files From Road Games Quickly and ReliablyT...

04/06/2026

MASV Outlines Seven-Step Sports Analytics Workflow, Highlights File Transfer as Key Bottleneck

MASV, a managed file transfer platform used in broadcast and live sports product...

04/06/2026

NESN Appoints Fahad Haider as Vice President of Operations and Engineering

NESN has announced the appointment of Fahad Haider as Vice President of Operations and Engineering. Haider returns to NESN, where he previously served as Vice P...

04/06/2026

Sports Broadcaster, Executive, and Author David J. Halberstam Dies

David J. Halberstam, who spent almost 50 years in sports as a broadcaster and an executive, died June 2 after a years-long battle with brain cancer. Over his l...

04/06/2026

Grass Valleys Ben Dolinky on Offering Teachable Technology to College Students Across the Country

Although collegiate production programs are tasked with delivering high-quality ...

04/06/2026

Prime Video Caps First NBA Season With Sports Emmy Win, Carries In-House Production Into WNBA Campaign

California studio, two production trucks, global distribution system are combine...

04/06/2026

TikTok and Sundance Collab Launch Micro-Series Storytelling Program

New global program empowers and supports storytellers through scriptwriting course and access to industry experts TikTok and Sundance Institute today announce...

04/06/2026

Celemony announce Tonalic ARA support for Cubase & Nuendo

Steinberg DAWs now boast in-depth Tonalic integration Celemony's innovative virtual session musician plug-in has just received an update that brings ARA...

04/06/2026

GearExpo UK: Microphone Update

Get Hands-On With Over 20 Mic Brands GearExpo UK is fast approaching, and if you've been looking for a chance to check out some new mics, then you'r...

04/06/2026

Positive Grid launch Reactor amp range

Combos feature new Amplifier Intelligence engine Positive Grid's latest release sees the company introduce two new combo amplifiers that promise to offe...

04/06/2026

Is Your Job Making You Work this June?

Is Your Job Making You Work this June? 4 June, 2026 Media releases SBS Launches the World Cup Watchers' Rights Association to Stand Up For Australians&...

04/06/2026

Statement regarding unauthorised use of SBS logos on third party social content

Statement regarding unauthorised use of SBS logos on third party social content 4 June, 2026 Media releases SBS has become aware of social media posts in c...

04/06/2026

TiVo: TV Viewing Hits Post-Pandemic Peak

Share Copy link Facebook X Linkedin Bluesky Email...

04/06/2026

Bitmovin and Akamai Support NRJ Group to Deploy Next Gene...

Bitmovin, a leading provider of video streaming infrastructure, and Akamai, the cybersecurity and cloud computing company that powers and protects business onli...

04/06/2026

American Underground Opens at American Tobacco Campus, Completing a 16-Year Full-Circle Story

American Underground (AU), the Startup Hub of the South and a community of mor...

04/06/2026

Nielsen: Thunder Rolls as NBA's Most-Watched Team

Share Copy link Facebook X Linkedin Bluesky Email...

04/06/2026

AI Drives Lenovo's 2026 FIFA World Cup Broadcast Plans

Share Copy link Facebook X Linkedin Bluesky Email...

04/06/2026

ATSC Conference Looks Beyond Traditional TV for 3.0 Success

Share Copy link Facebook X Linkedin Bluesky Email...

04/06/2026

ATSC Awards Highest Technical Honor to Julia Kenyon

Share Copy link Facebook X Linkedin Bluesky Email...