
Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years
Cambridge, MA | October 21, 2020
Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.
Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.
During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.
Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.
Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.
As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.
Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.
All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.
The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.
For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
Europe Stories
09/11/2025
Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...
24/10/2025
As global connectivity demands continue to grow, non-terrestrial networks (NTNs) are emerging as a transformative force in telecommunications. By extending cove...
24/10/2025
24 Oct 2025
VEON to Release 3Q25 Earnings Update on November 10, 2025 Dubai, October 24, 2025 - VEON Ltd. (NASDAQ: VEON), a global digital operator, today conf...
24/10/2025
One-off special from the team behind BAFTA award-winning Libby, Are You Home Yet...
24/10/2025
The review examined how the model is developed, managed, and delivered against the requirements set out in the Origin framework.
Simon Redlich, Chief Executive...
24/10/2025
RT will provide extensive coverage of the results of the Presidential Election across television, radio and online on Saturday, 25 October 2025.
Throughout th...
24/10/2025
New Coaches, New Families and New Challenges Set for Ireland's Fittest Famil...
24/10/2025
Westlife, Imelda May and Ben Elton among the guests on this week's Late Late...
23/10/2025
The 90-minute film is produced by Rogan Scotland, part of BAFTA-winning Rogan Pr...
23/10/2025
RT is today publishing a statistical summary from the Register of External Activities for the second quarter of 2025.
The RT Register of External Activities ...
23/10/2025
Series three of the award winning, hit comedy entertainment series The 2 Johnnies Late Night Lock In is back on your screens, celebrating the very best of all t...
23/10/2025
Performances by Michael Flatley, Andy Irvine, Cuckoo's Nest, Foster and Allen and more
Friday 24 October, 8pm on RT One and RT Player
Fleadh Cheoil re...
22/10/2025
In 1995, a young Colombian artist released an album that would change Latin pop ...
22/10/2025
Over the past few months, a photovoltaic system has been installed on a three-he...
22/10/2025
Rohde & Schwarz and TRUMPF cooperate in drone defense Rohde & Schwarz and TRUMPF partner to deliver a comprehensive drone defense solution combining Rohde & S...
22/10/2025
Everyone Gets a Better Deal on Verizon with New FOX One Perk The $15 FOX One streaming service perk is yet another way Verizon continues to add savings for cu...
22/10/2025
First Look Hidden Assets Series 3
Premieres on 9th November 9:30pm on RT One & RT Player
WATCH HERE Promo Link: Hidden Assets Series 3 | RT
The Crimin...
21/10/2025
Last week, Spotify and Columbia Records transformed Pier 4 at the Brooklyn Army ...
21/10/2025
As global operators simplify and evolve their digital platforms, NPS improvement...
21/10/2025
eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...
21/10/2025
21 Oct 2025
VEON's Beeline Kazakhstan to Acquire Online Classifieds Busines...
21/10/2025
Series from Sony Music Vision Features Exclusive Performances From Legendary Bas...
21/10/2025
Tuesday 21 October 2025
Buying a home ranks above becoming a parent as a key rite of passage into adulthood, chosen by almost half of Brits
New research also ...
21/10/2025
Synchron Stage Reverb SO: free for Focusrite customers Bring the sound of Vienna's legendary recording stage into your music, free for all Focusrite custo...
20/10/2025
In March, we launched Concerts Near You to help listeners find concerts from their favorite artists. Since then, more than 3 million people have used it to disc...
20/10/2025
Em diversas cidades do Brasil, um movimento tem se fortalecido para celebrar o poder, a beleza e a profundidade da criatividade negra. O Dia AMPLIFIKA, agora em...
20/10/2025
In cities across Brazil, a movement is growing that celebrates the power, beauty, and depth of Black creativity. AMPLIFIKA Day, now in its fifth edition, return...
20/10/2025
Monday 20 October 2025
To view this content, please enable our use of cookies. ...
20/10/2025
Rohde & Schwarz transfers Pixel Power to Imagine Communications Companies work collaboratively to ensure continuity and ongoing support for existing customers...
20/10/2025
RT 's Prime Time is set to host the final Presidential Election Debate this Tuesday night, October 21, providing an opportunity to hear directly from Irelan...
17/10/2025
M sica e arte se uniram em uma noite especial na semana passada na ZIV Gallery, ...
17/10/2025
Music and art came together for one special night last week at ZIV Gallery, an i...
17/10/2025
Spotify and FC Barcelona are extending our partnership through 2030, continuing a collaboration that's redefining how fans, players, and artists connect. Th...
17/10/2025
Gexcon is a trusted safety and risk management partner for complex, high hazard environments. ICG has been a dedicated marketing partner since 2018, building up...
17/10/2025
Here is your host, Patrick Kielty!
After an incredible breakthrough year, Kingf...
16/10/2025
AI technology is advancing quickly, bringing both new creative possibilities and...
16/10/2025
In 2017, Imani Ellis launched CultureCon, a conference that's become a must-attend event for more than 10,000 diverse creatives and Black professionals to c...
16/10/2025
It might still be a little early to break out the tinsel and mistletoe, but Spotify's already queuing up some holiday magic. This year's Spotify Singles...
16/10/2025
Earlier this year, our in-house publishing imprint, Spotify Audiobooks, put out ...
16/10/2025
TV's most charming detective drama * Shakespeare & Hathaway: Private Investi...
16/10/2025
This Saturday October 18 Katja Mia will burst onto the radio airwaves for the first time as she joins 2FM. Katja will be standing in for Bl thnaid Treacy on Sat...
16/10/2025
This October, RT is delighted to support Wexford Festival Opera, Babor International Arts Festival for Children, Open House Dublin and 36 other arts and cultu...
15/10/2025
Across the world, early-career reporters are interrogating systems that shape daily life, from mortuaries and classrooms to the corridors of legal education and...
15/10/2025
Two years ago, Spotify set out to grow the entire publishing industry by making ...
15/10/2025
People turn to DJ for a listening experience that feels personal, dynamic, and j...
15/10/2025
Las personas recurren a DJ para vivir una experiencia de escucha personal, din m...
15/10/2025
Rock legend Bruce Springsteen and luminary actor Jeremy Allen White came togethe...
15/10/2025
At Spotify, we're all about supporting rising talent and helping them connec...
15/10/2025
eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({ content_source:......
15/10/2025
Sheldon Nichols and Will Trickett to find and prepare more classic cars for budget conscious would-be owners from Wiser Films
UKTV have recommissioned the clas...