
Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility
Cambridge, MA | July 31, 2019
Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.
The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.
We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.
Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.
Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.
Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.
In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.
Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.
The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.
The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
28/03/2026
Now features DiGiCo console integration
Harrison's live recording and virtual soundcheck software has just reached its third major version, which among ...
28/03/2026
MPE-capable chamber strings library announced
Alongside their collection of Kontakt instruments, Sonora Cinematic have been steadily introducing a series of...
28/03/2026
Globecast, the leading provider of broadcast, media and entertainment managed services, will showcase its reimagined approach to media operations at the 2026 NA...
28/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
In-venue and creative video staffers at the professional and collegiate level ha...
27/03/2026
Comcast Business deployed network infrastructure for the 2026 PLAYERS Championsh...
27/03/2026
Czech production company CS live has equipped its newest outside broadcast van w...
27/03/2026
Edith Cowan University (ECU) in Perth, Western Australia has developed new broad...
27/03/2026
Deltatre has announced that CEO Andrea Marini will step down after five years in...
27/03/2026
DAZN has announced plans to launch DAZN Inflight, a live sports service for airline and maritime passengers, slated for 2027. Aviv Giladi, President of DAZN Par...
27/03/2026
Grass Valley has announced the completion of a live production deployment with NVP, a European media company specializing in live sports production, for LALIGA ...
27/03/2026
The Masters and Prime Video will debut Inside Amen Corner, a dedicated feed that...
27/03/2026
ESPN and the World Series of Poker (WSOP) have reached a multi-year agreement to bring the WSOP Main Event back to ESPN platforms. Coverage will include a three...
27/03/2026
USSI Global has opened its Media Transport Solutions Lab on its Melbourne campus. The engineering center provides a platform-agnostic environment for testing al...
27/03/2026
From 14-camera coverage to official review from Variant Systems Group, Sellitto ...
27/03/2026
The United Football League (UFL) has named Sportable its Official Connected Ball and Player Tracking Partner. Sportable's connected football and wearable pl...
27/03/2026
Ratings Roundup is a rundown of recent rating news and is derived from press rel...
27/03/2026
The Atlanta Braves and FuboTV have announced a multiyear distribution agreement to carry BravesVision on Fubo's live TV streaming platform beginning Opening...
27/03/2026
Besides restructuring for Season 3, the league worked with FOX and ESPN over the...
27/03/2026
The Atlanta Braves open their 2026 MLB season tonight against the Kansas City Ro...
27/03/2026
With new teams and new venues to adapt to, the spring-football league's part...
27/03/2026
By Lucy Spicer
One of the most exciting things about the Sundance Film Festival...
27/03/2026
New Classic, Amplitude & FlexRange units introduced
GIK Acoustics have just introduced a trio of new bass trap designs that bring improved low-end absorptio...
27/03/2026
Offers personalised Dolby Atmos headphone monitoring
Sonarworks have put their calibration expertise to work on a new mobile app that allows users to create...
27/03/2026
NITV to broadcast farewell to Rhoda Roberts AO with special coverage and week-lo...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
Marshall Electronics Showcases New Feature-Rich CV320 and CV520 IP and 3G-SDI PO...
27/03/2026
Sony Electronics Inc. Elevates Professional Video Workflows with Powerful Update...
27/03/2026
GatesAir Extends AirWatch365 Managed Service with Edge Gateway Site Appliance
Brie Clayton March 27, 2026
0 Comments
NAB marks global launch of servic...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
27/03/2026
At NAB Show 2026, Net Insight will showcase the next evolution of Nimbra Edge, its orchestration and control layer designed to manage live media services across...
27/03/2026
Harmonic (NASDAQ: HLIT) today announced powerful new innovations that further elevate the company's sports streaming solution. The advanced capabilities enh...
27/03/2026
Bitmovin, the leading provider of video streaming solutions, today announced significant new capabilities for Player Web X, its next-generation web video player...
27/03/2026
Riedel Communications today announced that Czech-based production company CS live has equipped its newest outside broadcast (OB) van with an integrated Riedel i...
27/03/2026
130 Industry Experts Confirmed as Show Celebrates its 10th Anniversary
MPTS, the UK's largest and most influential event for the media, production and tech...
27/03/2026
Grass Valley today announced the successful completion of a major live production deployment with NVP, a leading European media company specializing in live spo...
27/03/2026
Showcases resilient solutions for satellite-to-IP migration, REMI and hybrid live production
Appear ASA (Appear, OSE:APR), a global leader in live production t...
27/03/2026
San Francisco, California, March 2026 - Microsoft Ignite, a major annual conference hosted by Microsoft for developers, IT professionals, partners and business ...
27/03/2026
Clear-Com is proud to highlight its support for worship teams through professional communication solutions, with the deployment of its EQUIP wireless system a...
27/03/2026
Orban Collaborates with Sage on Virtualized EAS Technology Demo
Brie Clayton March 26, 2026
0 Comments
Sage Alerting Systems (SAS), in cooperation wit...