
Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years
Cambridge, MA | October 21, 2020
Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.
Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.
During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.
Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.
Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.
As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.
Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.
All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.
The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.
For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.
About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
Europe Stories
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
06/09/2026
June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
20/06/2026
New add-on creates doubles & vocal stacks
IK Multimedia's latest ReSing add-on kits the innovative software out with the ability to automatically genera...
19/06/2026
Company launch comprehensive mix-comparison tool
The Him DSP are a plug-in company founded by The Him, an EDM DJ and producer who has amassed over half a bi...
19/06/2026
Major Sampler upgrades introduced
The latest version of Bitwig's DAW software has just entered public beta testing, and is available now for all users w...
19/06/2026
Four times the power of their predecessors
Akai Pro have just introduced upgraded versions of two of their popular standalone MPC systems, kitting them out ...
19/06/2026
Friday 19 June 2026
How to watch the 2026/27 Premier League season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Premier League opening we...
19/06/2026
Catch up on the latest developments across Baselight and Daylight v7, Nara and FilmLight API Wednesday 8 July, 5pm onwards
Firehouse: DCTV, 87 Lafayette St, Ne...
18/06/2026
Improvements & new IR content
iamReverb Audio have just launched a free update that kits their convolution reverb plug-in out with some new features and int...
18/06/2026
Modelling suite gains improved captures, iOS support & more
Two notes Audio Engineering have just announced the launch of Genome 2.0, a significant update t...
18/06/2026
New AI assistance feature, video overhaul & more
VSL have just announced the launch of Vienna Ensemble Pro 8.1 and 8.1V, a pair of major updates to their ev...
18/06/2026
New study reveals 10 hidden data drainers costing Brits hundreds abroad - and the holiday hotspots where you could get rinsed the mostThursday 18 June 2026
The...
18/06/2026
Thursday 18 June 2026
How to watch the 2026/27 Scottish Premiership season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Scottish Premiers...
18/06/2026
Thursday 18 June 2026
Sky Sale: Latest deals now on, with discounts on iPhone Air & 2.5Gbps speeds
The latest deals have dropped from Sky Mobile, the award-wi...
18/06/2026
FOX Advertising and Toonstar Team to Create New Opportunities for Brands in Digi...
18/06/2026
Arqiva's Crawley Court and Chalfont Grove teleports re-certified at highest World Teleport Association standard
18 June 2026, Winchester, UK - Arqiva, the ...
18/06/2026
Apple today announced changes impacting iOS apps in Brazil that reflect a recent agreement with Brazil's competition regulator, the Conselho Administrativo ...
17/06/2026
New features, changes & bug fixes
SoundBridge have just released another update for their remote collaboration-focused DAW - reviewed here in SOS March 2026...
17/06/2026
Valve-based front end for digital & modelling rigs
The latest addition to Fryette's product range delivers a packed-down, pedalboard-friendly version of...
17/06/2026
GearExpo UK - 27 June 2026
Sound On Sound are proud to announce GearExpo UK, a major new recording and music technology exhibition in London! This is the bi...
17/06/2026
SAM monitoring line-up gains Dante and AES67 support
The latest expansion of Genelec's UNIO monitoring ecosystem introduces a new device that provides D...
17/06/2026
The R&S PR300 portable receiver from Rohde & Schwarz sets new standards in spect...
17/06/2026
Elt Group and Rohde & Schwarz sign a cooperation agreement to explore commercial...
17/06/2026
** MEDIA ALERT **
BY POPULAR DEMAND SHONEN JUMP SHOP RETURNS TO
LOS ANGELES...
17/06/2026
Wednesday 17 June 2026
Two in three fans will connect to venue WiFi this World ...
17/06/2026
Transaction Positions Harmonic as a Pure-Play Broadband Company SAN JOSE, Calif. - June 17, 2026 - Harmonic Inc. (NASDAQ: HLIT), the worldwide leader in virtual...
17/06/2026
FOX Advertising To Launch Industry's First End-to-End Agentic Advertising Pl...
17/06/2026
How SGN is future-proofing critical national infrastructure with Arqiva Managed Connectivity.
When disruption becomes the norm As Storm Eunice tore across the ...
17/06/2026
The RT Concert Orchestra will bring the timeless music of The Beach Boys to aud...
16/06/2026
Thomson's highly regarded expert-led online learning courses are now easier to access on the go via our new App.
Available now on Google Play Store, the J...
16/06/2026
Boasts individual synths for each band
UVI's latest synth takes an interesting approach to synthesis, offering a trio of synth engines that each operate...
16/06/2026
New intelligent auto-fader plug-in unveiled
PSPaudioware's latest release offers automatic level adjustment and provides more detailed control than many...
16/06/2026
New performance-focused library announced
Crystal Pads is the latest addition to The Crow Hill Company's ever-growing product range, and according to th...
16/06/2026
Developed in partnership with Sequential
In recent years, GForce Software have branched into official emulations of classic hardware synths, delivering a ha...
16/06/2026
Designed specifically for live performance monitoring
beyerdynamic's latest announcement sees the company introduce an affordable in-ear monitoring syst...
16/06/2026
Official emulation celebrates iconic synth's 40th anniversary
Cherry Audio have just introduced Ensoniq ESQ-1, an official recreation of the 1986 polyph...
16/06/2026
Rohde & Schwarz achieves highest number of GCF validated 3GPP NR NTN test cases ...
16/06/2026
Bydgoszcz to Become a Local Centre of Excellence for Advanced Rail Technologies....
16/06/2026
Tuesday 16 June 2026
Record audiences tune in for opening weekend of ICC Women&...
15/06/2026
Innovative three-band soft synth introduced
UVI's latest synth takes an interesting approach to synthesis, offering a trio of synth engines that each op...
15/06/2026
Applications now open for 2026
The Oram Awards have returned for 2026 to celebrate the unusual, unique and unfiltered creative worlds of women and gender-di...
15/06/2026
New intelligent auto-fader plug-in revealed
PSPaudioware's latest release offers automatic level adjustment and provides more detailed control than many...
15/06/2026
Greater Manchester Police installs Rohde & Schwarz security scanner for custody ...
15/06/2026
Insights from NAGRAVISION's latest industry webinar featuring One Hungary, Liberty Global and Media Press Group
In this blog, Laura Rognoni explores the k...
15/06/2026
** MEDIA ALERT **
First-Ever Official Studio Ghibli Store Opens in the U.S.
Fans Can Step Into the World of My Neighbor Totoro, Kiki's Delivery Servic...
15/06/2026
Monday 15 June 2026
Sky News takes viewers inside Minab in new film investigati...
15/06/2026
Fox Corporation to Acquire Roku, Inc. Combination Creates a Scaled Media and Technology Platform with Superior Reach, Engagement and Monetization Capability
...
14/06/2026
Library captures 1960s R&B/pop drum sound
Following on from their recent wave of plug-in effects, Iconic Instruments have just launched an all-new virtual d...