Sony Pixel Power calrec Sony

Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded

22/10/2020

Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years

Cambridge, MA | October 21, 2020

Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.

Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.

During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.

Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.

Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.

As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.

Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.

All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.

The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.

For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
LINK: https://www.akamai.com/uk/en/about/news/press/2020-press/state-of-the-...
See more stories from akami

Europe Stories

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

14/03/2026

HISONG announce the AirStudio S1

Combines mic, USB interface & wireless IEMs Following a successful Kickstarter campaign, HISONG have announced that their innovative AirStudio S1 device is ...

13/03/2026

A New Era of Personalization: Shape Your Taste Profile on Spotify

Spotify has always been built around your taste. More than 80% of listeners say personalization is what they love most about us. Now we're taking that even ...

13/03/2026

Spotify Debuts Legends Club for Popular German-Language Podcasts With Kaulitz Hills'

The new Spotify Legends Club has opened its doors. Its members: select German-sp...

13/03/2026

Klevgrand release OneShot2

Pushing drum sampler technology into new territories The latest version of Klevgrand's software drum sampler has just arrived, boasting a newly designe...

13/03/2026

IK Multimedia update ARC On-Ear

Expanded headphone support & engine improvements IK Multimedia's recently introduced ARC On-Ear system brings the power of their monitoring-correction s...

13/03/2026

UVI introduce Mosaiq 26

Extra sound collections, more presets & new Keys category UVI's rhythm and pattern instrument has just received a major update that introduces four new ...

13/03/2026

VEON Delivers Record Digital Growth: 4Q25 Digital Revenues Grow 84% to 20.1% of Total, Driving 17% Revenue and 29% EBITDA Growth in 4Q25

13 Mar 2026 VEON Delivers Record Digital Growth: 4Q25 Digital Revenues Grow 84%...

13/03/2026

Sky Adds Blood on Snow to Original Film Slate in Acquisition Headlined by Benedict Cumberbatch and Aaron TaylorJohnson

Friday 13 March 2026 Sky Adds Blood on Snow to Original Film Slate in Acquisiti...

13/03/2026

RT announces Rick O'Shea as new presenter on RT Radio 1's Arena

RT has announced today that Rick O'Shea is the new presenter of Arena RT Radio 1's flagship weeknight arts and culture programme. Rick has been pres...

13/03/2026

Lights! Camera! Action! The 98th Oscars set to air live as RT backs the Irish nominees

Lights! Camera! Action! The 98th Oscars set to air live as RT backs the Irish n...

12/03/2026

Milano Cortina 2026: Yospace helps ad-funded rights-holders claim advertising gold

Staines-upon-Thames, UK, 11th March, 2026 - Yospace, the trusted leader in Dyna...

12/03/2026

Mon Laferte Leads All-Women Spotify Session as EQUAL Celebrations Kick Off in Latin America

In Latin America, women are shaping music and defining its future. To kick off t...

12/03/2026

Mon Laferte lidera la edicin EQUAL de Spotify Sessions, mientras comienzan las celebraciones de EQUAL en Latinoamrica

En Am rica Latina, las mujeres est n moldeando la m sica y definiendo su futuro....

12/03/2026

As Spotify Turns 20, the Most Global and Diverse Music Industry in History Has Taken Shape

Let's turn back the clock 20 years: The music landscape was a world away fro...

12/03/2026

Bad Bunny Brings the Sounds of Puerto Rico to Tokyo for Spotify's Billions Club Live

Bad Bunny is no stranger to Spotify's Billions Club. In fact, he has a whopp...

12/03/2026

At the London Book Fair, Spotify Shares Our Vision for the Future of Reading

Spotify was at the London Book Fair this week, joining conversations across the publishing industry about how people can make reading part of their daily lives....

12/03/2026

Ohlhorst Digital & Tokyo Dawn Labs launch Ancora

Mastering tool improves mono compatibility Tokyo Dawn Labs' Ohlhorst Digital range is a series of mastering-focused plug-ins developed by Jan Ohlhorst, ...

12/03/2026

Lewitt partner with Elgato

Wave FX processor integrated into four products Lewitt have teamed up with Elgato to create a new processor for the company's Wave Next product range, i...

12/03/2026

Mix Notes iOS App by David Thomas

Free tool for annotating audio files Mix Notes is a new, free iOS App that provides users with a simple way to annotate their audio files. It's been cre...

12/03/2026

Duck 2 from Devious Machines

Side-chain ducking tool gets an upgrade Devious Machines' popular side-chaining and envelope-shaping tool has just been kitted out with an improved enve...

12/03/2026

MPG Awards 2026: Shortlist announced

Ceremony to take place on 16 April 2026 The MPG (Music Producers Guild) have revealed the full shortlist for this year's MPG Awards, which will be takin...

12/03/2026

Overloud introduce Gem Comp160

Emulates three classic dbx 160 variants The latest arrival to Overloud's Gem Series plug-in range faithfully recreates not one, but three versions of th...

12/03/2026

Grainferno from Baby Audio

New granular soft synth announced Said to be their most advanced software synthesizer to date, Baby Audio's latest release has been built on a new granu...

12/03/2026

Bitwig Studio 6 launches

Latest version now live! Edit 11 March 2026 - Bitwig Studio 6 is now live, and available for all to download! The latest version of Bitwig's DAW softwa...

12/03/2026

Stereo Miking: The Sound On Sound Guide

Latest free eBook now available! Designed for recording engineers, audio-technology students and technically minded musicians, our latest free eBook deliver...

12/03/2026

Rohde & Schwarz Cybersecurity expands SITLine network encryptor portfolio - more bandwidth, higher port density, future-proof architecture

Rohde & Schwarz Cybersecurity expands SITLine network encryptor portfolio - more...

12/03/2026

Rohde & Schwarz to showcase future-proof EMC testing solutions at EMV 2026

Rohde & Schwarz to showcase future-proof EMC testing solutions at EMV 2026 Rohde & Schwarz will participate in EMV 2026, Europe's premier trade fair and c...

12/03/2026

Blue Lucy's 6 Key Tenets

Modern media operations demand a platform that unites automation, orchestration, and human oversight without compromise. In this post, we explore the six key te...

12/03/2026

Blue Lucy Technology

A deep dive into the platform Architecture The Blue Lucy platform follows a distributed microservices architecture, meaning the overall operational capability...

12/03/2026

Blue Lucy Brings Order to the AI Wild West at NAB 2026

Orchestration platform enables broadcasters to deploy multiple AI models safely with full auditability, rights protection, and regulatory oversight. LONDON, En...

12/03/2026

Riedel Expands Managed Technology Division in the Americas, Taps Jan Schaffner to Lead Regional Growth

Wuppertal March 12, 2026 Riedel Expands Managed Technology Division in the Ame...

12/03/2026

Harmonic Redefines the Economics of Video Playout with New Spectrum X Plus Media Server

Advanced Media Server Delivers Double the Channel Density at Half the Cost per C...

12/03/2026

Jam-packed weekend of Irish entertainment, sport and music across RT for St Patrick's Day

The Late Late Show Show St Patrick's Day special Dancing with the Stars f...

11/03/2026

SES Brings Satellite Connectivity to Refugees in Chad

First Medium-Earth Orbit (MEO) deployment of the emergency.lu platform for refugees and their host communities' use provides dependable broadband for humani...

11/03/2026

Reign extended for CLASSIC CAR KINGS with two more series ordered for U and U&YESTERDAY

Following a successful first series, UKTV today announces the commission of two ...

11/03/2026

Sky and CANAL+ launch new partnership to develop English-language drama

Wednesday 11 March 2026 Sky and CANAL launch new partnership to develop English-language drama Sky and CANAL are today announcing a strategic co commissioni...

11/03/2026

NTCA, Cartesian Release New Report on the Business Case for USF

NTCA, Cartesian Release New Report on the Business Case for USF March 11, 2026 Network Economics News NTCA - March 11, 2026 - As the FCC and Congr...

11/03/2026

The 2026 RT Short Story Competition is now open for entries

TELL US YOUR (SHORT) STORIES The 2026 RT Short Story Competition is now open for entries Recognising and rewarding the best new Irish fiction writing for...

11/03/2026

Celtic Media Festival 2026 Nominees Announced

RT 's The Traitors Ireland is among the nominees for the 2026 Celtic Media Festival Torc Awards for Excellence, announced today....

10/03/2026

VEON's Largest Market Pakistan Almost Triples Mobile Spectrum in Reform Push; Jazz Secures Largest Allocation with 190 MHz

10 Mar 2026 VEON's Largest Market Pakistan Almost Triples Mobile Spectrum i...

09/03/2026

Duality Strings Bundle from VSL

Contains all six dual-ensemble libraries VSL's Duality Strings series offers an intriguing alternative to your average string library, capturing two str...

09/03/2026

The 1975 to receive MPG Award

Outstanding Contribution To UK Music Photo: Samuel Bradley Ahead of their upcoming MPG Awards, the Music Producers Guild (MPG) have revealed the latest win...

09/03/2026

Strymon reveal the PCH X1 & X2

Two new high-quality DI boxes announced Boasting some impressive technical specifications and versatile routing options, Strymon's latest active DI boxe...

09/03/2026

Sonora Cinematic introduce Pure Steel String

Latest MPE-capable Soundbox library released The follow-up release for Sonora Cinematic's Pure Nylon has arrived, and becomes the latest addition to the...