
Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years
Cambridge, MA | October 21, 2020
Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.
Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.
During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.
Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.
Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.
As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.
Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.
All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.
The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.
For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
Europe Stories
09/11/2025
Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...
07/11/2025
Word of mouth has always been at the heart of the Spotify experience, with people sharing music, podcasts, and audiobooks with friends and family millions of ti...
07/11/2025
X-Rite to Acquire Select Assets of Rutherford Graphic Products (RGP), LLC (USA) ...
07/11/2025
Friday 7 November 2025
Lioness and Arsenal forward Alessia Russo launched the f...
07/11/2025
-- Building on last year's success at COP29, the three initiator organizati...
06/11/2025
Media organisations from across the globe are uniting to promote media and information literacy (MIL) to help ensure their future survival and win back the trus...
06/11/2025
At Spotify, we're always finding new ways to bring you closer to the music that moves you, turning sound into something personal. From the playlists that ma...
06/11/2025
O mundo est ouvindo a Am rica Latina. Os artistas da regi o est o constantement...
06/11/2025
The world is listening to Latin America. The region's artists are consistent...
06/11/2025
El mundo est escuchando a Latinoam rica. Los artistas de la regi n marcan const...
06/11/2025
After nine months of fiscal year 2025, SGL Carbon generated sales of 652.9 million, down 16.5% on the previous year (9M 2024: 781.9 million). This is attribut...
06/11/2025
Contact information:
Miriam Johnson, Website Lead, Fotoware Group
miriam.johnson@fotoware.com
Oslo, October 2025: As part of our brand unification, the Pic...
06/11/2025
Calrec's 36-fader Argo M in Steiger Media's newly equipped OB truck parked outside the venue will showcase a live remote workflow connected to the Calre...
06/11/2025
06 Nov 2025
VEON Appoints Sebastian Rice as General Counsel Vitaly Shmakov promoted to the newly created Chief Investment Officer role
Dubai, November 6, 2025...
06/11/2025
The prequel to the Sky Original mob crime saga is a six-part drama tracking the ...
06/11/2025
The six-part drama, set in a close-knit Welsh town fractured by an unspeakable c...
06/11/2025
Rohde & Schwarz at productronica 2025: Innovation and production - hand in hand As a trusted partner for electronics manufacturing, Rohde & Schwarz will prese...
06/11/2025
Red Seat Ventures Announces Partnership with Renowned Entrepreneur, Author and M...
06/11/2025
We're delighted to announce the appointment of Max Mehta and Mark Fannon as Junior Systems Engineers, further strengthening our growing Technology team.
Ma...
06/11/2025
RT Announces Alex Walden as General Manager of the
RTE Concert Orchestra
Alex Walden, renowned orchestra manager, most recently for the BBC Concert Orche...
06/11/2025
Actors Steve Coogan and anna Hardwicke will be on the Late Late Show this week ...
06/11/2025
In the third episode of The 2 Johnnies Late Night Lock In actor Danny O'Carr...
05/11/2025
On Monday night, Ed Sheeran and Spotify lit up The Royal Dublin Society in Dublin for a one-night-only performance. The occasion? The third installment of Billi...
05/11/2025
Cumbia has long been woven into daily life in Argentina, and its popularity on S...
05/11/2025
La cumbia forma parte del d a a d a de los argentinos desde siempre, y su popula...
05/11/2025
Earlier this year, our in-house publishing imprint, Spotify Audiobooks, put out ...
05/11/2025
Wednesday 5 November 2025
To view this content, please enable our use of cookie...
05/11/2025
Wednesday 5 November 2025
Um diesen Inhalt zu sehen, aktiviere bitte die Verwen...
05/11/2025
Rohde & Schwarz Mobile Test Summit 2025 on the future of wireless communications...
05/11/2025
Wuppertal November 5, 2025
Riedel RefCam and Easy5G to Make Handball Debut at the Men's EHF EURO 2026The European Handball Federation (EHF) will introduce...
05/11/2025
Comscore and Polaris I/O Partner to Automate Audience Insights in MarketView for...
05/11/2025
New schedule will be live on-air Monday 10 November
Brand-new Today with David McCullagh from 9am
Oliver Callan in all-new extended show from 11am to 1pm
Kie...
05/11/2025
Explore the future with Science Week on RT
Dive into a week of innovative, themed programming and content across RT television, radio and online
Includes a ...
05/11/2025
Get ready for six weeks of United FC, a brand-new, feel-good teen docuseries kic...
04/11/2025
Today, we announced our third quarter 2025 earnings, marking strong momentum as we surpassed 700 million Monthly Active Users and achieved double-digit subscrib...
04/11/2025
Idag rapporterar vi v rt resultat f r det tredje kvartalet 2025, vilket markerar en stark och fortsatt tillv xt d vi passerade 700 miljoner m natliga aktiva an...
04/11/2025
Comscore Reports Third Quarter 2025 ResultsRESTON, Va., November 4, 2025 Comscore, Inc. (Nasdaq: SCOR), a trusted partner for planning, transacting and evalu...
04/11/2025
Damien Moloney as Jim Bergerac
As filming wraps on the highly anticipated second series of Bergerac (6x60'), UKTV today unveils a selection of first look i...
04/11/2025
Tuesday 4 November 2025
To view this content, please enable our use of cookies....
04/11/2025
From the recent SMPTE Media Technology Summit in Pasadena, with FilmLight Image Engineer, Daniele Siragusano, and Research Engineer, Julius Tschannerl.
Matchin...
04/11/2025
Begins Thursday November 6 on RT One and RT Player at 10:15pm
Camogie: Inside...
03/11/2025
Harmonic's cOS Virtualized Broadband Platform Will Further Enhance Broadband...
03/11/2025
Monday 3 November 2025
To view this content, please enable our use of cookies. ...
03/11/2025
Rohde & Schwarz acquires open source intelligence specialist Munich Innovation L...
03/11/2025
Rohde & Schwarz launches revolutionary super wideband mobile network scanner, se...
03/11/2025
ESA, MediaTek, Eutelsat, Airbus, Sharp, ITRI, and R&S announce world's first...
03/11/2025
Nokia and Rohde & Schwarz collaborate on AI-powered 6G receiver to cut costs, ac...
03/11/2025
A4ESSOR and OCCAR sign new procurement contract to advance development of intero...
03/11/2025
Sitep Australia joins Rohde & Schwarz team for Hunter class frigate communicatio...
03/11/2025
Red Seat Ventures and The 33rd Team Announce Exclusive Sales Partnership Red Seat Ventures to Spearhead Sales Representation for The 33rd Team's Dynamic S...