Sony Pixel Power calrec Sony

Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded

22/10/2020

Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years

Cambridge, MA | October 21, 2020

Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.

Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.

During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.

Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.

Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.

As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.

Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.

All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.

The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.

For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
LINK: https://www.akamai.com/uk/en/about/news/press/2020-press/state-of-the-...
See more stories from akami

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

06/09/2026

Dolby and MagentaTV Bring Fans Closer to the FIFA World Cup 2026 in Germany with Dolby Vision and Dolby Atmos

June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

26/06/2026

David Kuckhermann brings calabash to Celemony Tonalic

Virtual session musician plug-in gains new percussion options Celemony's latest update for their virtual session musician platform complements the exist...

26/06/2026

Softube unveil the Console 1 Compact

Half-size model joins Console 1 line-up Shortly after the release of their new Flow Studio controller, Softube have announced the launch of another new surf...

26/06/2026

ELT Group and Rohde & Schwarz sign a cooperation agreement to explore commercial opportunities in electromagnetic warfare and defense

ELT Group and Rohde & Schwarz sign a cooperation agreement to explore commercial...

26/06/2026

Prison Wives of TikTok is Locked In for U and U&W

Flicker Productions to produce five-part docu-reality series following women who have fallen for men in prison and have become TikTok sensations, with brands an...

26/06/2026

Automating post-production workflows with Baselight, Daylight, Nara & FilmLight API. New York. 8 July 2026

Catch up on the latest developments across Baselight and Daylight v7, Nara and F...

26/06/2026

DFT installs second Polar HQ at China News Film Confirming Position as China's Leading 8K Film Preservation Partner

26. June 2026 News DFT is pleased to announce that a second Polar HQ film s...

26/06/2026

New documentary Freedom Founder: Thomas McKean and the American Revolution comes to RT

New documentary Freedom Founder: Thomas McKean and the American Revolution airs ...

25/06/2026

Music Production for Women announce Soundlab 2026

Six free workshops across two days Global music education platform Music Production for Women (MPW), have just announced a brand new and highly anticipated ...

25/06/2026

CIOKS launch the DC7 v2

Popular pedalboard PSU gets an upgrade The DC7 v2 is a new and improved version of CIOKS' renowned effects pedal PSU, and is said to be the thinnest, mo...

25/06/2026

Rev Ocean reverb from Arturia

Optimised for lush, enveloping sounds Described as an instantly rewarding reverb , the latest addition to Arturia's range of creative effects plug-ins ...

25/06/2026

Just 48 hours until GearExpo UK!

27 June 2026, Westminster University Harrow Campus GearExpo UK is now upon us, with just two days to go until 150 of the worlds top pro-audio brands and ind...

25/06/2026

cUL/UL Certification and the Anton/Bauer EDEN: The New Safety Standard for Production Power

alt= data-nectar-img-srcset=https://www.antonbauer.com/wp-content/uploads/2026/0...

25/06/2026

Read all about it! The Paper will return for a second season to Sky and streaming service NOW on 10 September

Thursday 25 June 2026 Read all about it! The Paper will return for a second sea...

25/06/2026

How to watch the 2026/27 EFL season on Sky Sports

Thursday 25 June 2026 How to watch the 2026/27 EFL season on Sky Sports Which EFL matches are Sky Sports showing on the 2026/27 opening weekend? Sky Sports w...

25/06/2026

Comedian Joe McGucken hosts new RT podcast series Ramble

Launching today (Thursday 25 June), new RT podcast Ramble with Joe McGucken is a series of curiosity-driven conversations where actor, writer and comedian Joe ...

24/06/2026

NoiseWorks Audio add Mouth De-Click to VoiceAssist

Plus: VoiceAssist Basic now available to UA LUNA users NoiseWorks Audio have just released an update that adds a new Mouth De-Click module to the Advanced t...

24/06/2026

Gator introduce the Frameworks Studio Mic Boom 2000

New heavy-duty mic stand joins range The latest arrival to Gator's Frameworks family introduces a new heavy-duty boom stand that's been designed for...

24/06/2026

Waves V17 now available

Latest major plug-in update goes live Waves have just announced that the latest major update for their hugely popular plug-in range is now officially availa...

24/06/2026

Why Four Bars of Signal Doesn't Always Mean Good Performance

When assessing cellular coverage, many people look at the signal bars displayed on a smartphone, router or modem. More bars are often assumed to mean better per...

24/06/2026

Rohde & Schwarz THORIS sets new standard for counterUAS defense

Rohde & Schwarz THORIS sets new standard for counter UAS defense At Eurosatory 2026, Rohde & Schwarz is unveiling THORIS, a German engineered, sovereign count...

24/06/2026

Rohde & Schwarz expands voice communications modernization program for Egyptian air traffic control

Rohde & Schwarz expands voice communications modernization program for Egyptian ...

24/06/2026

Clear-Com FreeSpeak Cell Successfully Tested by RTL Deutschland in 5G Network at...

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...

24/06/2026

X-Rite Pantone Adds MSI PRO MAX Displays to Pantone Validated Program for Proven Color Fidelity for Real World Colors

X-Rite Pantone Adds MSI PRO MAX Displays to Pantone Validated Program for Proven...

24/06/2026

Dara Briain forms Dara's Dull Appreciation Society for U

24th June 2026, London: Dara Briain will host brand new comedy entertainment series Dara's Dull Appreciation Society (4x40') celebrating members of th...

24/06/2026

Sky reveals wild new trailer and images for Shaun the Sheep: The Beast of Mossy Bottom

Wednesday 24 June 2026 Sky reveals wild new trailer and images for Shaun the Sh...

24/06/2026

Comscore Announces Partnership with Amazon DSP to Expand Content Addressability to Drive Campaign Performance

Comscore Announces Partnership with Amazon DSP to Expand Content Addressability ...

24/06/2026

RT is supporting 21 Arts and Cultural Events all over Ireland this July

From Cork to Limerick to Earagail: RT is supporting 21 Arts and Cultural Events all over Ireland this July RT Supporting the Arts is delighted to spotlight...

23/06/2026

Violet Audio's dMix 128 now shipping

128 channels of signal routing & DSP Announced just before the NAMM Show 2026, Violet Audio's latest digital audio matrix offers 128 channels of signal ...

23/06/2026

Minimal Audio launch Memory Rites

Latest Current expansion created by EPROM Minimal Audio have just launched the latest Current Expansion, Memory Rites. Designed in collaboration with renown...

23/06/2026

Undertone Audio's MPEQ-1 goes virtual

Popular hardware EQ gets official plug-in emulation Undertone Audio have just launched a new plug-in that brings one of their most popular hardware designs ...

23/06/2026

Colorfront Support for AWS CDI Unlocks New Potential for Cloud-Based Visual Effects and Content Creation

December 7, 2022 Colorfront (colorfront.com) - the multi-award-winning develope...

23/06/2026

Colorfront Delivers Even More AI Automation Power and Extends Technology Partnerships with Dolby, Apple

April 23, 2026 NAB 2026, Las Vegas - the Academy and Emmy Award-winning develop...

23/06/2026

UKTV and BBC Entertainment join forces on first joint comedy entertainment co-commission

23rd June 2026, London: UKTV and BBC Entertainment have unveiled a joint co-comm...

23/06/2026

Gugu Mbatha-Raw leads Sky Original supernatural thriller Possession in first teaser

Also starring Jonny Lee Miller, Sheldon Shepherd and Bel Powley, the ambitious f...

23/06/2026

Arqiva response to DCMS Green Paper

The priority now is a clear and credible plan June 23, 2026, Winchester, UK - Arqiva, the UK's leading communications infrastructure provider, welcomes tod...

23/06/2026

RT AND COMMUNITY FOUNDATION IRELAND ANNOUNCE RT TOY SHOW APPEAL GRANT AWARDS 2026

The RT Toy Show Appeal has raised over 31 million since its inception in 2020 ...

22/06/2026

Blade joins CEDAR Audio Icons line-up

New hyper-resolution analyser EQ revealed CEDAR Audio's all-new Icons plug-in series has just gained its newest member, Blade. Described by the compan...

22/06/2026

Sampleson release Aeronaut

Turn any live input into a cinematic soundscape Designed for use in the studio and on stage, Sampleson's latest creation is capable of taking any audio ...

22/06/2026

ADDAC System's new Four Strings Series

Adds guitar strings to Eurorack rigs ADDAC System are renowned for their weird and wonderful synth designs, and their line-up includes plenty of gear that&#...

22/06/2026

NAGRA Venturi - Turning Piracy Intelligence into Measurable Business Impact

In our latest blog, Tim Pearson explores NAGRA Venturi, the new streaming security solution for the AI era from NAGRAVISION. Designed to aggregate and analyze ...

22/06/2026

Official trailer released for Katie Price: Nothing to Hide, coming to Sky and NOW on 8 July

Monday 22 June 2026 Official trailer released for Katie Price: Nothing to Hide,...

21/06/2026

John Walden's Cubase Video Tutorials

New series now live on Udemy Regular SOS contributor and Cubase workshop columnist John Walden has just released a new Cubase video course that is now avail...

21/06/2026

Sky announces immersive documentary series The Wargame

Sunday 21 June 2026 Sky announces immersive documentary series The Wargame The Wargame first looks ZIP (2MB) Sky today confirms the commission of The Wargam...

20/06/2026

IK Multimedia introduce ReSing Doubling

New add-on creates doubles & vocal stacks IK Multimedia's latest ReSing add-on kits the innovative software out with the ability to automatically genera...

19/06/2026

Ninja AB from The Him DSP

Company launch comprehensive mix-comparison tool The Him DSP are a plug-in company founded by The Him, an EDM DJ and producer who has amassed over half a bi...

19/06/2026

Bitwig Studio 6.1 enters beta testing

Major Sampler upgrades introduced The latest version of Bitwig's DAW software has just entered public beta testing, and is available now for all users w...