Sony Pixel Power calrec Sony

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers

01/08/2019

Akamai Threat Research: Phishing and Credential Stuffing Attacks Remain Top Threat to Financial Services Organizations and Customers Latest State of The Internet / Security Report Observes 3.5 Billion Malicious Login Attempts Targeting the Financial Services Sector; Illustrates Akamai's Unique Threat Visibility

Cambridge, MA | July 31, 2019

Newly released data from Akamai's 2019 State of the Internet / Security Financial Services Attack Economy Report has found that 50% of all unique organizations impacted by observed phishing domains were from the financial services sector. The data shows that, in addition to unique phishing attempts, adversaries also leveraged credential stuffing attacks to the tune of 3.5 billion attempts during an 18-month period, putting the personal data and banking information of financial services customers at risk.

The report indicates that between December 2, 2018 and May 4, 2019, nearly 200,000 (197,524 to be exact) phishing domains were discovered, and of those domains, 66% targeted consumers directly. When taking the phishing domains targeting consumers only into consideration, 50% of those targeted companies in the financial services industry.

We've seen a steady rise in credential stuffing attacks over the past year, fed in part by a growth in phishing attacks against consumers, said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. Criminals supplement existing stolen credential data through phishing, and then one way they make money is by hijacking accounts or reselling the lists they create. We're seeing a whole economy developing to target financial services organizations and their consumers.

Once criminals have succeeded in their schemes, they need to process their ill-gotten data and funds. As Akamais report highlights, one method of dealing with this situation centers on bank drops' - packages of data that can be used to fraudulently open accounts at a given financial institution. Bank drops will typically include a persons stolen identity - often called fullz by criminals online, including name, address, date of birth, Social Security details, drivers license information, and credit score. Secure access to the fraudulent accounts comes via remote desktop servers, which are matched to the geographic location of the bank and the fullz.

Financial institutions continue to investigate the ways in which criminals are opening these drop accounts, and are working diligently to stay ahead of the curve. What most businesses don't realize, however, is that criminals are recycling old attack methods.

Akamai's findings revealed that 94% of observed attacks against the financial services sector came from one of four methods: SQL Injection (SQLi), Local File Inclusion (LFI), Cross-Site Scripting (XSS), and OGNL Java Injection (which accounted for more than 8 million attempts during this reporting period). OGNL Java Injection, made famous due to the Apache Struts vulnerability, continues to be used by attackers years after patches have been issued.

In the financial services industry, criminals have also started launching DDoS attacks as a distraction to conduct credential stuffing attacks or to exploit a web-based vulnerability. Over the course of 18 months, Akamai uncovered more than 800 DDoS attacks against the financial services industry alone.

Attackers are targeting financial services organizations at their weak points: the consumer, web applications and availability, because that's what works, said McKeay. Businesses are becoming better at detecting and defending against these attacks, but point defenses are bound to fail. It requires being able to detect, analyze, and defend against an intelligent criminal who's using multiple different types of tools for a business to protect its customers. For more than twenty years, Akamai has been leveraging its unique visibility into the full spectrum of attacks to help protect customers from these types of ever-evolving nefarious activities.

The criminal economy thrives, in part, because they target the financial services industry. By targeting banks for example, criminals attempt to steal sensitive data, and then turn around and use that same data to open fake accounts and lines of credit. Its a continuous cycle of crime. There is a deep level of irony in the fact that criminals are targeting the very industry they need to survive. While financial institutions are becoming better at detecting these attacks, adversaries continue to find success with old tricks, and that's a problem.

The Akamai 2019 State of the Internet / Security Report is available for download here. For additional information where the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global co
LINK: https://www.akamai.com/uk/en/about/news/press/2019-press/state-of-the-...
See more stories from akami

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

30/05/2026

NAB Asks FCC to Shift Regulatory Fee Burden to Big Tech, Broadband

Share Copy link Facebook X Linkedin Bluesky Email...

30/05/2026

NAB Announces 2026 Board Election Results

Share Copy link Facebook X Linkedin Bluesky Email...

30/05/2026

IAB Tech Lab Releases Guidance for Managing AI Crawlers and Bots

Share Copy link Facebook X Linkedin Bluesky Email...

30/05/2026

Zero in on one that says yes (and no)

Zero in on one that says yes (and no) Andy Marken May 29, 2026 0 Comments Hero image courtesy of Deposit Photos For content creators the most difficu...

29/05/2026

InfoComm 2026: NDI Demos NDI 6.3, Hands-On Presentation About Educational Integrations

With InfoComm 2026 just weeks away, NDI is giving attendees plenty of reasons to...

29/05/2026

Bell Media Inks New Long-Term Media Rights Deal for Broadcast, Streaming of the Canadian Football League

Reaffirming a partnership that has defined Canadian sports broadcasting since 19...

29/05/2026

Spring 2026 TV Survey: Vertical Live Matters. The Bigger Story Is Context

Mobile/tablet is No. 2 device for watching TV, suggesting that the sports-production industry needs to take another look at the format Ring Digital's Sprin...

29/05/2026

Germanys Berliner Ensemble Bolsters Backstage Infrastructure With Riedel Stage Systems

Berliner Ensemble, one of Berlin's five major theater companies, has expande...

29/05/2026

InfoComm 2026: Solid State Logic Spotlights TCA Tour, Live V6.2 Software, New SSL Live Trade-in Program

Solid State Logic will showcase its new compact, fly-away TCA Tour audio product...

29/05/2026

Gerald Jerry Pierce, Architect of Modern Digital Cinema, Passes Away at Age 73

Gerald (Jerry) Pierce, a pioneering technologist who helped shape the digital transformation of the motion picture industry, passed away last month on April 12 ...

29/05/2026

CBS Sports Becomes New Home of Barclays Women's Super League Thorough 2029-2030

Paramount+ will be the English-language U.S. home for Barclays Women's Super...

29/05/2026

Calrec Scales ImPulseV to Empower Broadcasters With Greater Choice in Virtualized Workflows

Further strengthening its virtualisation strategy to fully support broadcasters ...

29/05/2026

Switzerlands Canal Alpha Streamlines Playout to Delivery With Harmonic

Swiss broadcaster Canal Alpha has deployed Harmonic's award-winning, software-based XOS Advanced Media Processor to modernize playout operations across cant...

29/05/2026

InfoComm 2026: PTZOptics Showcases Intelligent Video Ecosystem

PTZOptics will showcase a new generation of intelligent video workflows at InfoComm 2026, June 17-19, Las Vegas. Visitors to booth N8227 will see how PTZOptics ...

29/05/2026

Arizona's Family Sports Debuts Direct-to-Consumer Streaming App

Arizona's Family has launched the Arizona's Family Sports (AZFS) streaming app, a new direct-to-consumer destination for live, local sports. The app is ...

29/05/2026

DAZN Brings The Canadian Football Leagues Saturday Night Football to the Masses in New Media Rights Deal

Starting in 2027, DAZN will be the exclusive home of The Canadian Football Leagu...

29/05/2026

Comcast Business Supports Advanced Technology Infrastructure at Levi's Stadium for Fan Experience, Venue Operations

Comcast Business has detailed the advanced network infrastructure it has deploye...

29/05/2026

College Sports-Production Community Gathers in Atlanta for 2026 SVG College Summit

In two-day event, leaders from academia and industry explored solutions to chall...

29/05/2026

TBT Reaches Two-Year Extension With FOX Sports for New-Look $2 Million Tournament

The Basketball Tournament (TBT), now entering their 13th year of competition, ha...

29/05/2026

Roku Expands Premium Subscriptions Experience with FOX One

Roku has launched FOX One as a Premium Subscription on The Roku Channel in the U.S. Roku customers can now subscribe to FOX One using their Roku account for liv...

29/05/2026

CBS Sports UEFA Champions League Today Studio Show Heads Budapest for Final as Transcontinental Popularity Grows

In its sixth year, the broadcaster's coverage has become a global brand and ...

29/05/2026

Ratings Roundup: NBA, NHL Playoffs and Indy 500 Photo Finish Power a Record-Setting Week

Ratings Roundup is a rundown of recent ratings news and is derived from press re...

29/05/2026

Your Summer 2026 Soundtrack? Spotify's Predictions Are In

The days are getting longer, the temperatures are rising, and playlists are filling up for the season. With summer around the corner, Spotify's global edito...

29/05/2026

Akai Pro unveil the MPC Live III Retro

New retro-inspired MPC announced There are few devices that have gained the status held by Akai Pro's MPC range, and in recent years, the company have s...

29/05/2026

Bjooks Beat Gems Kickstarter continues

Save up to 30 on acclaimed titles Following a successful launch at Superbooth 2026, Bjooks have revealed that they will be continuing the Kickstarter campa...

29/05/2026

Genelec update Aural ID

Binaural monitoring application improved Genelec have just released an update that brings some powerful new features to their HRTF-based binaural headphone ...

29/05/2026

IMSTA FESTA 2026

6 June 2026 at SAE Institute, London, UK IMSTA FESTA 2026 is almost upon us, with some of the biggest names in pro-audio set to descend upon SAE Institute i...

29/05/2026

Remembering Gerald Jerry Pierce, Architect of Modern Digital Cinema

Gerald (Jerry) Pierce, a pioneering technologist who helped shape the digital transformation of the motion picture industry, died April 12, 2026, at his home in...

29/05/2026

Roku Unveils Redesigned TV Home Screen

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

Sinclair and AMP Sports to Launch Style of Play' Podcast

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

TV Pharma Ads Are Getting Longer, VAB Says

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

Comparing 5 AI Video Enhancers for Restoring Old Video Quality

Comparing 5 AI Video Enhancers for Restoring Old Video Quality Kate Luvis May 29, 2026 0 Comments Digitizing VHS, MiniDV, and other legacy formats doe...

29/05/2026

Studio Hamburg Builds New Post Pipeline with DaVinci Resolve Studio

Studio Hamburg Builds New Post Pipeline with DaVinci Resolve Studio Brie Clayton May 29, 2026 0 Comments Workflow replaces a patchwork of legacy tools...

29/05/2026

FCC Reminds Broadcasters of Their Public Interest Obligations

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

Roku Unveils New TV Home Screen

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

Sinclair and AMP Sports Announce New 'Style of Play' Podcast

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

Study: YouTube Leads Global Streaming Ad Growth

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

TV Pharma Ads Are Getting Longer, According to VAB

Share Copy link Facebook X Linkedin Bluesky Email...

29/05/2026

At the Intersection of Music and Dance, an Epic Collaboration

At the Intersection of Music and Dance, an Epic Collaboration Boston Conservatory musicians and dancers found creative parallels in their recent performance o...

29/05/2026

Glookast Launches Cinnafilm Tachyon Plugin for Media Producer and Media Services

GLOOKAST LAUNCHES CINNAFILM TACHYON PLUGIN FOR MEDIA PRODUCER AND MEDIA SERVICES This release first appeared here. Visit our Tachyon product page or contact...

29/05/2026

Dolby and rednote Bring More Immersive Storytelling to Video Content with Dolby Atmos

May 29 2026, 09:00 (PDT) Dolby and rednote Bring More Immersive Storytelling to...

29/05/2026

Audiences Are Everywhere. Your Ad Strategy Should Be Too.

Something fundamental has shifted in how people consume media. Audiences aren't abandoning television or radio content; they're just expanding how, wher...

29/05/2026

Rosie Jones's Disability Comedy Extravaganza returns with another new lineup of eight comics

Youtube exclusive special drops today Watch now UKTV today announces another e...

29/05/2026

The Official Trailer of 'Physical 100' Italy, on Netflix From September 11

Back to All News The Official Trailer of Physical 100 Italy, on Netflix From Se...

29/05/2026

Genelec announces V2.1 for Aural ID binaural headphone monitoring application

Genelec announces V2.1 for Aural ID binaural headphone monitoring application posted: 29/05/2026 Aural ID 2.1 enhances binaural monitoring for stereo and ...