
Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility
Cambridge, MA | July 31, 2019
Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.
The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.
We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.
Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.
Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.
Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.
In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.
Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.
The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.
The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
Most recent headlines
06/10/2025
France T l visions, France's leading broadcaster, has received the 2025 EBU ...
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
07/08/2025
July 8 2025, 22:30 (PDT) Tata Motors & Dolby Bring Dolby Atmos to Harrier.ev, R...
12/07/2025
Ryan Coogler accepting the 2013 Vanguard Award. Photo by Alberto E. Rodriguez.
Editor's Note: In honor of Fruitvale Station s 12th anniversary, we're d...
12/07/2025
Key Code Education, the professional training division of Key Code Media, proudly announces a major update to its Adobe Premiere Pro Engineering and Advanced Op...
12/07/2025
Key Code Education, a leader in instructor-led post production training for over...
12/07/2025
As the death toll continues to mount, with at least 120 killed and more than 170 people still missing on July 10 from devastating Texas floods, a number of broa...
12/07/2025
EL SEGUNDO, Calif., and MIAMI -DirecTV and TelevisaUnivision have signed a deal that will make the ad-supported premium subscription tier of ViX, ViX Premium wi...
11/07/2025
PARK CITY, UTAH, July 11, 2025 - The nonprofit Sundance Institute announced today the 11 producers chosen for its annual Producers Labs, returning to Ucross Fou...
11/07/2025
If you've ever wondered what might be playing in Clark Kent's headphones...
11/07/2025
L3Harris Technologies President of Intelligence, Surveillance and Reconnaissance Jason Lambert and General Manager of L3Harris Waco facility Sean Ling held a ce...
11/07/2025
ARLINGTON, Va. WETA, the flagship public media station in the national capital area, has launched WETA+, a new streaming service tailored for the local Washingt...
11/07/2025
The Federal Communications Commission has emerged as one of the central players in the broadcast TV landscape in 2025, with its deregulatory policies sparking h...
11/07/2025
Calrec will introduce usability, customization and system enhancements across its entire range of Argo consoles during IBC2025, Sept. 12-15, at the RAI Amsterda...
11/07/2025
LONDON Encompass Digital Media said it will support live and on-demand viewing of the 2025 FIFA Club World Cup across multiple global regions for sports enterta...
11/07/2025
Two-thirds of broadcast engineers reaped the benefits of a pay raise within the last year....
11/07/2025
CARY, N.C. SmallHD has launched the Quantum 27, a new 26.5-inch Quantum-Dot OLED monitor designed to deliver postproduction image quality in a compact, set-frie...
11/07/2025
The Federal Communications Commission's Enforcement Bureau and Tegna have entered into a consent decree that will settle an investigation into the accidenta...
11/07/2025
WASHINGTON Following news in early July that Paramount had settled President Donald Trump's lawsuit, Sens. Edward J. Markey (D-Mass.) and Ben Ray Luj n (D-N...
11/07/2025
Model/Actriz Performs Lead Single Cinderella on The Late Show with Stephen Colbe...
11/07/2025
Behind the Mic: Amazon Prime Preps for First Season of NBA Action; MSG Networks ...
11/07/2025
SVG New Sponsor Spotlight: Suite Studios' Craig Hering on Adapting to Client...
11/07/2025
2025 SVG Content Management Forum Breaks Down AI's Impact, Continued Transit...
11/07/2025
A Journey HOME: University of Nebraska's HuskerVision Goes IP Leaders from the HuskerVision and Lawo share their IP learnings By SVG Staff
Friday, July 1...
11/07/2025
CMSI, Remote Picture Labs, Ace ESPN's Cloud-Based Editing Efforts for Wimble...
11/07/2025
Netflix Enters the Live-Boxing-Production Ring for Round 2 With Historic Taylor-...
11/07/2025
Back to All News
Too Hot to Handle: Italy Is Coming on July 18 Only on Netflix
Entertainment
11 July 2025
GlobalItaly
Link copied to clipboard
July 11, 20...
11/07/2025
Back to All News
Netflix Will Release Death Inc. Seasons 1, 2 and 3
Entertainment
11 July 2025
GlobalSpain
Link copied to clipboard
Season 1
Season 2
Se...
11/07/2025
AI and Multimedia Authenticity Standards Collaboration launches two papers to guide the future of AI integration, today at the AI for Good Global Summit
The...
11/07/2025
Ceramics - the humble mix of earth, fire and artistry - have been part of a global conversation for millennia.
From Tang Dynasty trade routes to Renaissance pa...
10/07/2025
The current holder of the prestigious Thomson Foundation Young Journalist of the Year Award has been forced to stop reporting over fears for her safety in Afgha...
10/07/2025
Spotify is turning up the volume on Australian music with a multipronged initiative designed to highlight the dominance of Australian artists on the global stag...
10/07/2025
This is not a drill: Oasis is back on the road-marking its first live performanc...
10/07/2025
The music industry depends on fresh ideas, bold voices, and emerging talent. Yet across the U.K., too many young musicians lack the space to develop their craft...
10/07/2025
NEW YORK - July 10, 2025 - Nielsen, the global leader in audience measurement, data and analytics, today announced that it appointed Richard Pacheco as head of ...
10/07/2025
Local newscasts don't exist in a vacuum. News directors and station management constantly evaluate what's working, what isn't and perhaps most impor...
10/07/2025
Lawo has announced that Stuttgart Media University (Hochschule der Medien, HdM) has comprehensively modernized its central recording studio after selecting an I...
10/07/2025
The Society of Motion Picture and Television Engineers (SMPTE) has opened early-bird registration for the Media Technology Summit, which will take place in a ne...
10/07/2025
NASHVILLE, Tenn. TNDV Television has launched Aspiration 35, a new version of its 40-foot Aspiration truck reimagined for cinematic multicamera productions....
10/07/2025
BURBANK, Calif. Key Code Education, a provider of instructor-led postproduction training, is growing its curriculum with new programs for beginner and intermedi...
10/07/2025
HACKENSACK, N.J. Actus Digital will demonstrate how broadcasters can transform compliance monitoring from a necessary expense into a strategic revenue driver at...
10/07/2025
The Federal Register has published a summary of the Federal Communications Commission's Public Notice seeking comments on its ownership rules that lists a d...
10/07/2025
Back to All News
Netflix Presents the Official Trailer for SuperestarPlay Video
Play Video
Entertainment
10 July 2025
GlobalSpain
Link copied to clipboard...
10/07/2025
In the race to understand our planet's changing climate, speed and accuracy are everything. But today's most widely used climate simulators often strugg...
10/07/2025
As one of the world's largest emerging markets, Indonesia is making strides toward its Golden 2045 Vision - an initiative tapping digital technologies and...
10/07/2025
10 Jul 2025
VEON and Cohen Circle Secure Investor Commitments for Kyivstar Listing Kyiv, New York, Dubai, and Philadelphia - July 10, 2025 - VEON Ltd. (Nasdaq:...
10/07/2025
5G for all? What the DFL's use of Easy5G and RefCam could mean for events in...
10/07/2025
Save the Date: PGA TOUR Studios Welcomes SVG Remote Production Summit on Oct 14-...
10/07/2025
Cloud on the Road: How Remote-Production-Service Providers Are Adapting to a New...
10/07/2025
Seattle Kraken's Ryan Schaber on the NHL Team Taking Live Game Productions I...