Sony Pixel Power calrec Sony

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers

01/08/2019

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility

Cambridge, MA | July 31, 2019

Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.

The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.

We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.

Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.

Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.

Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.

In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.

Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.

The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.

The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-...
See more stories from akami

Most recent headlines

20/12/2025

Atomos Updates Ninja TX GO-Ninja TX With ProRes RAW and C...

Atomos announced the immediate availability of a new firmware update for its Ninja TX GO and Ninja TX monitor-recorders, unlocking ProRes RAW recording from the...

20/12/2025

CJP Broadcast Completes Digitisation of European Gymnasti...

CJP Broadcast has completed the digitisation of the European Gymnastics tape archive, converting 328 tapes containing more than forty years of recorded material...

20/12/2025

Bitmovin Launches Stream Lab MCP Server

Bitmovin, the leading provider of video streaming solutions, today announced the launch of the Stream Lab MCP Server, to give AI agents and large language model...

20/12/2025

Gracenote Unveils New Immersive Features for Sports Hubs

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

20/12/2025

Morgan Murphy Media Promotes Jill Shiroma to VP of Digital Strategy

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

20/12/2025

Samsung Makes GameBreaks Ad Format Available Programmatically

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

20/12/2025

FCC Extends Deadline for Comments on Upper C-Band Proposals

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

20/12/2025

Scripps Sports Inks Deals for Soccer and Professional Cheerleading

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

20/12/2025

Atomos Unveils Firmware Update For Ninja TX and TX GO

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

20/12/2025

Barack Obama Includes Laufey on His 2025 Favorite Music List

Barack Obama Includes Laufey on His 2025 Favorite Music List The former presidents roundup of books, music, and movies includes a song from the Berklee alums ...

20/12/2025

December 19, 2025

Study reveals a key hormonal circuit in the kidneys Scripps Research scientists identify the protein that helps kidney cells regulate renin, providing foundatio...

19/12/2025

With Playout Release 2025.4, ToolsOnAir continues to push professional playout workflows forward on macOS.

With Playout Release 2025.4, ToolsOnAir continues to push professional playout w...

19/12/2025

SVG Sit-Down: Diversified's Jared Timmins on AI for Broadcast Sports and Creating the Smart Venue'

SVG Sit-Down: Diversified's Jared Timmins on AI for Broadcast Sports and Cre...

19/12/2025

2025 SVG Summit Audio Recap: Say What?

2025 SVG Summit Audio Recap: Say What?The Audio Production and Distribution Workshop at the SVG Summit 20 took on issues including speech intelligibility, Next-...

19/12/2025

Gamified Fun: Channel 5 on its NFL Big Game Night Ambitions with Hungry Bear Media

Gamified fun: Channel 5 on its NFL Big Game Night ambitions with Hungry Bear Med...

19/12/2025

College Football Playoff Preview: For ESPN, Round 1 is a Fantastic Yet Familiar Saturday of Production

College Football Playoff Preview: For ESPN, Round 1 is a Fantastic Yet Familia...

19/12/2025

AWS's Jason Dvorkin on Developing Partnerships With the NBA and PGA Tour, Embracing the Use of Agentic AI

AWS's Jason Dvorkin on Developing Partnerships With the NBA and PGA Tour, Em...

19/12/2025

Netflix Kicks Off Packed Sports Week with Paul-Joshua Fight Before Shifting to NFL Christmas Doubleheader

Netflix Kicks Off Packed Sports Week with Paul-Joshua Fight Before Shifting to N...

19/12/2025

SVG New Sponsor Spotlight: Presidio's Nareev Shah on the Role of Its Captivate and Resonate Platforms in Sports Production

SVG New Sponsor Spotlight: Presidio's Nareev Shah on the Role of Its Captiva...

19/12/2025

US Marine Corps Increases Affordable Mass Demonstrations with Successful Red Wolf Low-Altitude Live Fire

Mounted to the pylon of an AH-1Z Viper helicopter, a Red Wolf vehicle successful...

19/12/2025

Space Development Agency Awards L3Harris $843 Million Contract for Tracking Layer Satellites

L3Harris technology for the SDA Tranche 3 Tracking Layer program will provide in...

19/12/2025

Nielsen and XR Announce Platform Integration to Make it Easier for Brands and Agencies to Deliver Ads Powered by Nielsen Measurement

Partnership brings Nielsen ONE measurement activation directly into XR's adv...

19/12/2025

Motion Impossible Initiates Campaign for SMPTE Robotics Standard

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Gracenote Unveils New Features for Sports Hubs

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Berklee Announces Spring 2026 Signature Series

Berklee Announces Spring 2026 Signature Series This season's highlights include the Gospel Extravaganza, the 40th International Folk Festival, special gue...

19/12/2025

Queensland Performing Arts Centre Elevates Live Stream Ex...

Performing arts centres across the globe have doubled down on live production infrastructure in recent years. For venues like the Queensland Performing Arts Cen...

19/12/2025

FCC's Brendan Carr Stands Up for His Policies at Senate Hearing

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Nexstar Brand Studio Launches with 'My American Story Campaign'

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Nashville To Host 2026 AES Show

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

NAB Launches Effort to Keep Live Sports on Broadcast Channels

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

FCC Votes to Adopt New Rules for LPTV Stations

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Hearst Television Ups Mike Kronenfeld to VP, National Sales

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

19/12/2025

Ricardo Coke-Thomas Named Chair of Theater for Boston Conservatory at Berklee

Ricardo Coke-Thomas Named Chair of Theater for Boston Conservatory at Berklee The distinguished theater educator, director, and performer will join the Conser...

19/12/2025

'Salvador' Arrives to Netflix on February 6

Back to All News Salvador Arrives to Netflix on February 6 Entertainment 19 December 2025 GlobalSpain Link copied to clipboard WHEN THERE IS NOTHING LEFT ...

19/12/2025

Your YearEnd Maintenance Checklist

As the year comes to a close, it's the perfect time to give your WO Automation for Radio system a quick tune up. At the top of your year end checklist is on...

19/12/2025

VEON's Mobilink Microfinance Bank Launches Islamic Banking Operations in Pakistan

19 Dec 2025 VEON's Mobilink Microfinance Bank Launches Islamic Banking Oper...

19/12/2025

Wrapping up a year of connection and clarity!

Wrapping up a year of connection and clarity! 19 Dec Written By Suzanne Costello As 2025 comes to a close, we want to take a moment to thank our incredib...

19/12/2025

Kelly Reilly and Rafe Spall lead Sky Original Under Salt Marsh as the full trailer is unveiled

The six-part drama, set in a close-knit Welsh town fractured by an unspeakable c...

19/12/2025

Rohde & Schwarz drives the future of mobility at CES 2026

Rohde & Schwarz drives the future of mobility at CES 2026 At the 2026 Consumer Electronics Show in Las Vegas, Rohde & Schwarz will present a powerful lineup o...

19/12/2025

Salvador arrives to Netflix on February 6

Back to All News Salvador arrives to Netflix on February 6 Entertainment 19 December 2025 GlobalSpain Link copied to clipboard WHEN THERE IS NOTHING LEFT ...

19/12/2025

Last Samurai Standing' Renewed for Season 2 - A Global Sensation Proudly Made in Japan

Back to All News Last Samurai Standing' Renewed for Season 2 - A Global Se...

19/12/2025

RT is turning up the volume at the 2026 Stripe Young Scientist & Technology Exhibition

RT is proud to return to the RDS to support the 2026 Stripe Young Scientist & T...

19/12/2025

December 18, 2025

Nanoparticle vaccine strategy could protect against Ebola and other deadly filoviruses Scripps Research scientists turn nanoparticles into virus showcases to ...

18/12/2025

SVG Campus Shot Callers: Kurt Sutton, Director of Broadcast Operations, Clemson University

SVG Campus Shot Callers: Kurt Sutton, Director of Broadcast Operations, Clemson ...

18/12/2025

Follow the Money Episode 2: Inside the Sports Media Biz with Sam McCleery and Steve Hellmuth

Follow the Money Episode 2: Inside the Sports Media Biz with Sam McCleery and St...

18/12/2025

SVG Sit-Down: Google Cloud's Anshul Kapoor on the Future of Generative Production' in Live Sports

SVG Sit-Down: Google Cloud's Anshul Kapoor on the Future of Generative Prod...

18/12/2025

The 2025 SVG Summit Draws Record Crowd for 20th-Annual Sports-Production Industry Homecoming in NYC

The 2025 SVG Summit Draws Record Crowd for 20th-Annual Sports-Production Industr...

18/12/2025

SBS's sports schedule sizzles in January with Dakar Rally, Kooyong Classic and Mapei Cadel Evans Great Ocean Road Race

SBS's sports schedule sizzles in January with Dakar Rally, Kooyong Classic a...

18/12/2025

Montreal's Bell Centre elevates fan experience with Argo S

Canada's largest indoor arena has transformed its live production capabilities with a full ST 2110 infrastructure and Calrec's compact Argo S console. S...

18/12/2025

The Gauge: Mexico November 2025

During November, streaming's share of TV viewing in Mexico settled at 24.2%, an increase of 0.5 share points from the previous month. Disclaimer: YUMI TV,...