
Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility
Cambridge, MA | July 31, 2019
Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.
The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.
We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.
Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.
Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.
Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.
In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.
Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.
The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.
The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
23/03/2026
The Professional Fighters League (PFL) has renewed its multi-year partnership wi...
23/03/2026
The Snow League has named Google Cloud as its Official Cloud and AI Partner. The...
23/03/2026
Chyron has appointed Eric Wolff as Director of Venues Sales, North America. Wolff previously served as Director of Broadcast Operations & Media Production for T...
23/03/2026
Chicago Sports Network (CHSN) and Weigel Broadcasting's WCIU (The U, ch. 26.1) will simulcast 10 Chicago White Sox games during the 2026 season, the compani...
23/03/2026
Cosm has appointed Jon Werbeck as Vice President, Head of Sponsorships. He will report to Corey Breton, Head of Venues, and will focus on corporate sponsorship ...
23/03/2026
CP Communications has announced a partnership with Mark Roberts Motion Control (...
23/03/2026
NAB Show 2026, taking place April 18-22 (exhibits April 19-22) at the Las Vegas ...
23/03/2026
Bay FC and free streaming platform Victory have announced a partnership through...
23/03/2026
Gemini AI models will surface hidden context around pitches, matchups, rare stat...
23/03/2026
Behind The Mic provides a roundup of recent news regarding on-air talent, includ...
23/03/2026
Growing from broadcast engineer to strategic planner, this Ithaca College grad h...
23/03/2026
16 Science-Focused Nonfiction Projects Selected for Funding
LOS ANGELES, CA, March 23, 2026 - The nonprofit Sundance Institute and Sandbox Films announced toda...
23/03/2026
It's been 20 years since Miley Cyrus introduced the world to Hannah Montana,...
23/03/2026
Made entirely from real natural recordings
Aimed at sound designers and editors working in film, TV and game audio, the latest release from BOOM Library com...
23/03/2026
Transcribe sheets, tabs or MIDI from audio files
Klang.io have announced the launch of a new AI-powered software tool that's capable of detecting multip...
23/03/2026
An auxiliary target has been affixed to the Interim Cryogenic Propulsion Stage f...
23/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/03/2026
Pro8mm, the Super 8 experts, provided cameras, Super 8 movie film, and scanning services for Bruno Mars' Risk It All music video. The debut single from Br...
23/03/2026
Matthews, introduces their first aluminum grid clamp collection, engineered for the rigging needs of film, television and live production. Combining light weigh...
23/03/2026
Monday 23 March 2026
Hacks, the multi-Emmy -winning Sky Exclusive comedy, retur...
23/03/2026
Back to All News
Too Hot to Handle: Italy Reignites for a Second Season With th...
23/03/2026
Autonomous agents mark a new inflection point in AI. Systems are no longer limited to generating responses or reasoning through tasks. They can take action: Age...
23/03/2026
RT is sad today to learn of the death of legendary RT Sport broadcaster Michael Lyster, who died this morning aged 71 years.
Kevin Bakhurst, Director-General...
23/03/2026
RT Documentary On One has scooped its first ever dedicated music award. At the 2026 Icelandic Music Awards, composer lfur Eldj rn won Release of the Year in t...
23/03/2026
Inside Sport, Liveline, Morning Ireland and 2FM DRIVE will all be in Prague to bring fans to the heart of the action
Every Moment, Every GenerationRT | FIFA W...
22/03/2026
Free updates now available
VSL have just released some free updates that add some existing features to a selection of libraries in their expansive Synchron ...
22/03/2026
Back to All News
Live-Action Sins of Kujo' Premieres April 2: Main Trailer and Key Art Debut
Entertainment
22 March 2026
GlobalJapan
Link copied to cl...
21/03/2026
Presented to War Child UK's HELP(2) project
The MPG (Music Producers Guild) have announced the launch of the MPG Impact Award, a brand-new honour that w...
21/03/2026
Microtuning support for Arabic, Persian & Turkish scales
The latest release from Best Service brings together a selection of string, wind and percussion ins...
21/03/2026
New campaign from NAATI and SBS CulturalConnect highlights how we all deserve t...
21/03/2026
Statement regarding Rhoda Roberts AO
21 March, 2026
Media releases
SBS is deeply saddened by the passing of Widjabul Wia-bal woman from the Bundjalung Na...
21/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
21/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
21/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
21/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
21/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
21/03/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
21/03/2026
Cine Gear Connect NY, presented by Universal Production Services, is filling in the slate for a full day of panels, peers, learning the latest, and mixing it up...
21/03/2026
Studio Technologies Debuts New StudioComm System at NAB 2026
Brie Clayton March 20, 2026
0 Comments
StudioComm Model 794 Central Controller and Model ...
21/03/2026
Restoration Christian Fellowship Captures Worship Music Videos with PYXIS 12K
Brie Clayton March 20, 2026
0 Comments
PYXIS' open gate provides cre...
20/03/2026
Net Insight will introduce a JPEG XS solution for full IP environments at NAB Sh...
20/03/2026
LTN has expanded its technology partnership with Harmonic ahead of the FCC's...
20/03/2026
Solid State Logic will preview SSL Live V6.2 at NAB Show, booth C6907. The softw...
20/03/2026
FUJIFILM North America Corporation's Optical Devices Division has announced ...