Sony Pixel Power calrec Sony

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers

01/08/2019

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility

Cambridge, MA | July 31, 2019

Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.

The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.

We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.

Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.

Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.

Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.

In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.

Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.

The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.

The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-...
See more stories from akami

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

06/09/2026

Dolby and MagentaTV Bring Fans Closer to the FIFA World Cup 2026 in Germany with Dolby Vision and Dolby Atmos

June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

25/06/2026

Launching a Career in Broadcast Engineering: Academic Paths and Essential Certifications

Launching a Career in Broadcast Engineering: Academic Paths and Essential Certif...

25/06/2026

SVG Students To Watch: Jude Kieffer, Ball State University

This superstar shooter/storyteller from Central Indiana hopes to make his mark in the blossoming sports-documentary and -features space In the live-sports-vid...

25/06/2026

Presidio and NHL Renew Multiyear North American Technology Partnership

Presidio and the National Hockey League have announced a multiyear renewal of their North American partnership. Presidio will remain an Official Technology Inno...

25/06/2026

Strike Fighter League Hits the Industry as First Professional Air Combat Sport

Strike Fighter League (SFL) is the world's first professional air combat digital sport that combines elite human performance and physical immersion with cut...

25/06/2026

Rise Reveals 2026 Worldwide Mentoring Cohorts to Support Future Industry Leaders

Rise, the award-winning advocacy group for gender diversity in the broadcast and media technology sector, is pleased to announce the global mentoring cohort for...

25/06/2026

MLB Network To Air American Association of Professional Baseball All-Star Game for First Time on July 15

The 2026 American Association of Professional Baseball (AAPB) All-Star Game will...

25/06/2026

Mediaproxy Partners with HVS for U.S. Broadcast Market

Mediaproxy has named Heartland Video Systems (HVS) as its exclusive partner for US television broadcasting. The Wisconsin-based systems integrator will represen...

25/06/2026

Backblaze Inks Five-Year Multi-Exabyte Data Storage Agreement with CoreWeave

Backblaze has formed an agreement with CoreWeave to create The Essential Cloud for AI. Under the multi-exabyte, $335 million agreement, Backblaze will provide...

25/06/2026

Clear-Com FreeSpeak Cell Tested by RTL Deutschland on 5G Network at Nrburgring

Clear-Com has announced the successful deployment and testing of FreeSpeak Cell by RTL Deutschland during a live event production at the N rburgring race circui...

25/06/2026

Mobile TV Group Launches Full-Stack MTVG Production Platform, Powers Angels Broadcast Television

Mobile TV Group (MTVG) has announced the launch of the MTVG Production Platform,...

25/06/2026

Sony Pictures Entertainment Announces $100 Million Investment in Cosm

Sony Pictures Entertainment (SPE) has announced a $100 million strategic investment in Cosm as lead investor in the company's Series C financing round, acqu...

25/06/2026

FOX Sports Renews Concacaf Gold Cup Rights and Adds Nations League Through 2029

FOX Sports and Concacaf have announced a multi-year media rights agreement making FOX Sports the U.S. English-language home of the Concacaf Gold Cup and Concaca...

25/06/2026

InfoComm 2026: Daktronics and Grass Valley Win rAVe Pubs Best Solution for Large Venue or Live Events

Daktronics and Grass Valley have received the rAVe Pubs Best Solution for Large ...

25/06/2026

Music Production for Women announce Soundlab 2026

Six free workshops across two days Global music education platform Music Production for Women (MPW), have just announced a brand new and highly anticipated ...

25/06/2026

CIOKS launch the DC7 v2

Popular pedalboard PSU gets an upgrade The DC7 v2 is a new and improved version of CIOKS' renowned effects pedal PSU, and is said to be the thinnest, mo...

25/06/2026

Rev Ocean reverb from Arturia

Optimised for lush, enveloping sounds Described as an instantly rewarding reverb , the latest addition to Arturia's range of creative effects plug-ins ...

25/06/2026

Just 48 hours until GearExpo UK!

27 June 2026, Westminster University Harrow Campus GearExpo UK is now upon us, with just two days to go until 150 of the worlds top pro-audio brands and ind...

25/06/2026

The Name You Know, The Lineup You'll Love - SBS2 Returns

The Name You Know, The Lineup You'll Love - SBS2 Returns 25 June, 2026 Media releases SBS Viceland rebrands as SBS2 on Friday 21 August, bringing the c...

25/06/2026

Sports and Dramas Drive April Viewing Patterns in Nielsen's Latest Gauge Reports

Cable Gains Share for Second Consecutive Month in Six-Month-High Finish, Boosted...

25/06/2026

cUL/UL Certification and the Anton/Bauer EDEN: The New Safety Standard for Production Power

alt= data-nectar-img-srcset=https://www.antonbauer.com/wp-content/uploads/2026/0...

25/06/2026

Jeopardy!, Wheel of Fortune Tap Clear-Com for Comms Upgrade

Share Copy link Facebook X Linkedin Bluesky Email...

25/06/2026

ESC 2026 - Big Blue Marble cloud-based delivery powers fl...

The Eurovision Song Contest 2026 in Vienna was a significant success for the Austrian public broadcaster ORF. In Austria, more than 1.5 million viewers tuned in...

25/06/2026

WISYCOM DELIVERS NEW LEVELS OF RF EFFICIENCY AND INFRAST...

Wisycom has further strengthened its ecosystem of professional wireless solutions with the MPR60 Wideband IEM/IFB Receiver with expanded multichannel IFB mode, ...

25/06/2026

Ease Live Powers New Interactive Experience for Rally TV...

Ease Live, the interactivity expert, today announced that its graphics overlay platform is powering a new interactive experience on Rally.TV, the official video...

25/06/2026

VFX History: the origin of After Effects

VFX History: the origin of After Effects Graham Quince June 25, 2026 0 Comments Before it was Adobe, it was CoSA. This is the VFX history of Adobe Aft...

25/06/2026

Creative Remote to Open London Offline Facility

Creative Remote, the provider of remote and hybrid offline editing infrastructure, today announced the opening of 41, its new offline edit facility located at 4...

25/06/2026

Rise Announces 2026 Worldwide Mentoring Cohorts Supportin...

Rise, the award-winning advocacy group for gender diversity in the broadcast and media technology sector, is pleased to announce the global mentoring cohort for...

25/06/2026

Emergent Partners with ROCKET to Expand Canadian Operatio...

Emergent, a pioneer in browser-based, AI-enhanced content production environments, today announced a strategic partnership with ROCKET, a premier media-centric ...

25/06/2026

Mobile Television Group Launches MTVG Full-Stack Production Platform

Share Copy link Facebook X Linkedin Bluesky Email...

25/06/2026

NAB Updates FCC on ATSC 3.0 Alerting Advances

Share Copy link Facebook X Linkedin Bluesky Email...

25/06/2026

Tegna Elevates Four Executives to Senior VP

Share Copy link Facebook X Linkedin Bluesky Email...

25/06/2026

Read all about it! The Paper will return for a second season to Sky and streaming service NOW on 10 September

Thursday 25 June 2026 Read all about it! The Paper will return for a second sea...

25/06/2026

How to watch the 2026/27 EFL season on Sky Sports

Thursday 25 June 2026 How to watch the 2026/27 EFL season on Sky Sports Which EFL matches are Sky Sports showing on the 2026/27 opening weekend? Sky Sports w...

25/06/2026

The Ultimate Summer Sale Pairing: Steam Sale Meets GeForce NOW Discounts

Summer savings are heating up. From the Steam Summer Sale to GeForce NOW membership discounts, this week's GFN Thursday delivers double the deals and more w...

25/06/2026

Comedian Joe McGucken hosts new RT podcast series Ramble

Launching today (Thursday 25 June), new RT podcast Ramble with Joe McGucken is a series of curiosity-driven conversations where actor, writer and comedian Joe ...

25/06/2026

June 24, 2026

Immune molecule may drive excessive drinking in alcohol use disorder Scripps Research scientists showed that blocking an immune molecule tied to inflammation r...

24/06/2026

NoiseWorks Audio add Mouth De-Click to VoiceAssist

Plus: VoiceAssist Basic now available to UA LUNA users NoiseWorks Audio have just released an update that adds a new Mouth De-Click module to the Advanced t...

24/06/2026

Gator introduce the Frameworks Studio Mic Boom 2000

New heavy-duty mic stand joins range The latest arrival to Gator's Frameworks family introduces a new heavy-duty boom stand that's been designed for...

24/06/2026

Waves V17 now available

Latest major plug-in update goes live Waves have just announced that the latest major update for their hugely popular plug-in range is now officially availa...

24/06/2026

Why Four Bars of Signal Doesn't Always Mean Good Performance

When assessing cellular coverage, many people look at the signal bars displayed on a smartphone, router or modem. More bars are often assumed to mean better per...

24/06/2026

Rohde & Schwarz THORIS sets new standard for counterUAS defense

Rohde & Schwarz THORIS sets new standard for counter UAS defense At Eurosatory 2026, Rohde & Schwarz is unveiling THORIS, a German engineered, sovereign count...

24/06/2026

Rohde & Schwarz expands voice communications modernization program for Egyptian air traffic control

Rohde & Schwarz expands voice communications modernization program for Egyptian ...

24/06/2026

Clear-Com FreeSpeak Cell Successfully Tested by RTL Deutschland in 5G Network at...

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...

24/06/2026

Nielsen's Q1 2026 Ad Supported Gauge

Streaming sets record high of 46.6% of ad supported TV viewing, driven by Super Bowl and Winter Olympics; overall share of ad supported TV remains steady NEW Y...

24/06/2026

FCC Flooded with Nearly 28K Comments Regarding Its Probe of 'The View'

Share Copy link Facebook X Linkedin Bluesky Email...

24/06/2026

Hearst Television Brings Ad Addressability to Local Broadcast TV

Share Copy link Facebook X Linkedin Bluesky Email...