Sony Pixel Power calrec Sony

Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded

22/10/2020

Akamai Security Research: Loyalty Programs Continue to be Targeted by Criminals as Account Data is Easily Sold or Traded Retail, Hospitality, Travel industries were hit with over 63 billion credential stuffing and 4 billion web application attacks in last two years

Cambridge, MA | October 21, 2020

Akamai (NASDAQ: AKAM) the intelligent edge platform for security and delivering digital experiences, today published the State of the Internet / Security report: Loyalty for Sale - Retail and Hospitality Fraud. The report details criminal activity targeting the retail, travel, and hospitality sectors with attacks of all types and sizes between July 2018 and June 2020. The report also includes numerous examples of criminal ads from the darknet illustrating how they cash in on the results from successful attacks and the corresponding data theft.

Criminals are not picky -- anything that can be accessed can be used in some way, said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold, and traded or even compiled for extensive profiles that can later be used for crimes such as identity theft.

During the COVID-19 pandemic-related lockdowns in Q1 2020, criminals took advantage of the worldwide situation and circulated password combination lists, targeting each of the commerce industries featured in the report. It was during this time that criminals started recirculating old credential lists in an effort to identify new vulnerable accounts, leading to a significant uptick in criminal inventory and sales related to loyalty programs.

Between July 2018 and June 2020, Akamai observed more than 100 billion credential stuffing attacks in total. In the commerce category - comprising the retail, travel, and hospitality industries - there were 63,828,642,449 recorded. More than 90% of the attacks in the commerce category targeted the retail industry.

Credential stuffing isn't the only way that criminals target the retail, travel, and hospitality industries. They target organizations in these industries at the source using SQL Injection (SQLi) and Local File Inclusion (LFI) attacks. Between July 2018 and June 2020, Akamai observed 4,375,711,860 web attacks against retail, travel, and hospitality, accounting for 41% of the overall attack volume across all industries. Within this data set, 83% of those web attacks targeted the retail sector alone. SQLi attacks are an evident favorite among criminals, accounting for just under 79% of the total web application attacks against retail, travel, and hospitality.

As the global economy prepares for a holiday shopping season, it does so in an environment that has changed radically due to the pandemic. Consumers will not be standing outside of brick and mortar stores waiting for the latest deals in the same way they have in the past. They're going to log-in, collect their reward points, and maybe use loyalty programs to gain some discounts or other perks just for being a member.

Considering everything that goes into a successful loyalty program, and the information people need to provide in order to take part, the criminals have everything they need to get started in a number of crime-related ventures, from account takeovers, to straight-up identity theft. So, while an individual's loyalty to a merchant, airline, or hotel chain might not literally be for sale, there's a good chance the account associated with such programs might be.

All businesses need to adapt to external events, whether it's a pandemic, a competitor, or an active and intelligent attacker, Ragan concluded. Some of the top loyalty programs targeted require nothing more than a mobile number and a numeric password, while others rely on easily obtained information as a means of authentication. There is an urgent need for better identity controls and countermeasures to prevent attacks against APIs and server resources.

The Akamai 2020 State of the Internet / Security report, Loyalty for Sale - Retail and Hospitality Fraud is available here. In addition, Akamai will host a webinar on Thursday, October 22 at 11:00 a.m. ET where Akamai security experts discuss the findings of this latest report. To register for the webinar, visit here.

For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape, visit Akamai's Threat Research Hub.

About Akamai Akamai secures and delivers digital experiences for the world's largest companies. Akamai's intelligent edge platform surrounds everything, from the enterprise to the cloud, so customers and their businesses can be fast, smart, and secure. Top brands globally rely on Akamai to help them realize competitive advantage through agile solutions that extend the power of their multi-cloud architectures. Akamai keeps decisions, apps and experiences closer to users than anyone - and attacks and threats far away. Akamai's portfolio of edge security, web and mobile performance, enterprise access and video delivery solutions is supported by unmatched customer service, analytics and 24/7/365 monitoring. To learn why the world's top brands trust Akamai, visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations.
LINK: https://www.akamai.com/uk/en/about/news/press/2020-press/state-of-the-...
See more stories from akami

Europe Stories

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

07/11/2025

8 Easy Ways to Share Your Spotify Soundtrack with Friends

Word of mouth has always been at the heart of the Spotify experience, with people sharing music, podcasts, and audiobooks with friends and family millions of ti...

07/11/2025

X-Rite to Acquire Select Assets of Rutherford Graphic Products (RGP), LLC (USA) in Strategic Expansion

X-Rite to Acquire Select Assets of Rutherford Graphic Products (RGP), LLC (USA) ...

07/11/2025

Alessia Russo inspires 180 girls at inaugural Alessia Cup in partnership with Goals 4 Girls, presented by Sky

Friday 7 November 2025 Lioness and Arsenal forward Alessia Russo launched the f...

07/11/2025

From promises to progress: 21 global organizations unite at COP30 to champion International Standards in the climate action agenda

-- Building on last year's success at COP29, the three initiator organizati...

06/11/2025

How media and information literacy in newsrooms is winning back audience trust

Media organisations from across the globe are uniting to promote media and information literacy (MIL) to help ensure their future survival and win back the trus...

06/11/2025

Spotify's Latest Feature Charts Your Week in Listening

At Spotify, we're always finding new ways to bring you closer to the music that moves you, turning sound into something personal. From the playlists that ma...

06/11/2025

Spotify Sessions chega Amrica Latina, entregando o controle criativo a trios liderados por artistas

O mundo est ouvindo a Am rica Latina. Os artistas da regi o est o constantement...

06/11/2025

Spotify Sessions Launch in Latin America, Handing Creative Control to Artist-Led Trios

The world is listening to Latin America. The region's artists are consistent...

06/11/2025

Spotify Sessions se lanza en Latinoamrica, empoderando a tros creativos liderados por artistas

El mundo est escuchando a Latinoam rica. Los artistas de la regi n marcan const...

06/11/2025

SGL Carbon: Transformation progressing rapidly

After nine months of fiscal year 2025, SGL Carbon generated sales of 652.9 million, down 16.5% on the previous year (9M 2024: 781.9 million). This is attribut...

06/11/2025

Picturepark.com is moving to fotoware.com

Contact information: Miriam Johnson, Website Lead, Fotoware Group miriam.johnson@fotoware.com Oslo, October 2025: As part of our brand unification, the Pic...

06/11/2025

Tonmeistertagung Preview

Calrec's 36-fader Argo M in Steiger Media's newly equipped OB truck parked outside the venue will showcase a live remote workflow connected to the Calre...

06/11/2025

VEON Appoints Sebastian Rice as General Counsel

06 Nov 2025 VEON Appoints Sebastian Rice as General Counsel Vitaly Shmakov promoted to the newly created Chief Investment Officer role Dubai, November 6, 2025...

06/11/2025

Sky unveils first look teaser for highly anticipated prequel Gomorrah The Origins

The prequel to the Sky Original mob crime saga is a six-part drama tracking the ...

06/11/2025

Kelly Reilly and Rafe Spall star in gripping new Sky Original drama Under Salt Marsh first look teaser revealed

The six-part drama, set in a close-knit Welsh town fractured by an unspeakable c...

06/11/2025

Rohde & Schwarz at productronica 2025: Innovation and production - hand in hand

Rohde & Schwarz at productronica 2025: Innovation and production - hand in hand As a trusted partner for electronics manufacturing, Rohde & Schwarz will prese...

06/11/2025

Red Seat Ventures Announces Partnership with Renowned Entrepreneur, Author and Media Personality Jillian Michaels

Red Seat Ventures Announces Partnership with Renowned Entrepreneur, Author and M...

06/11/2025

dB Broadcast Welcomes Two New Junior Systems Engineers

We're delighted to announce the appointment of Max Mehta and Mark Fannon as Junior Systems Engineers, further strengthening our growing Technology team. Ma...

06/11/2025

RT Announces Alex Walden as General Manager of the RTE Concert Orchestra

RT Announces Alex Walden as General Manager of the RTE Concert Orchestra Alex Walden, renowned orchestra manager, most recently for the BBC Concert Orche...

06/11/2025

Steve Coogan, anna Hardwicke, Holly Cairns and Kieran Cuddihy among the guests on this week's Late Late Show

Actors Steve Coogan and anna Hardwicke will be on the Late Late Show this week ...

06/11/2025

Danny O'Carroll, Anna Clifford and PJ Gallagher join the lads for THE 2 JOHNNIES LATE NIGHT LOCK IN

In the third episode of The 2 Johnnies Late Night Lock In actor Danny O'Carr...

05/11/2025

Ed Sheeran Brings Billions Club Live Home to Dublin

On Monday night, Ed Sheeran and Spotify lit up The Royal Dublin Society in Dublin for a one-night-only performance. The occasion? The third installment of Billi...

05/11/2025

Cumbia Takes Center Stage as Spotify Celebrates Argentina's Most-Listened-To Genre

Cumbia has long been woven into daily life in Argentina, and its popularity on S...

05/11/2025

La cumbia toma el centro del escenario mientras Spotify celebra el gnero ms escuchado de Argentina

La cumbia forma parte del d a a d a de los argentinos desde siempre, y su popula...

05/11/2025

Spotify Publishes First Independent Author Releases Through Audiobook Selects, With More Planned Ahead

Earlier this year, our in-house publishing imprint, Spotify Audiobooks, put out ...

05/11/2025

Brits urged to turn off bad phone behaviour as 54% say phone icks are on the rise

Wednesday 5 November 2025 To view this content, please enable our use of cookie...

05/11/2025

Watch the official trailer: Battle of the Irish Dancers brings the heat to Sky Arts and NOW from 12 November

Wednesday 5 November 2025 Um diesen Inhalt zu sehen, aktiviere bitte die Verwen...

05/11/2025

Rohde & Schwarz Mobile Test Summit 2025 on the future of wireless communications - registrations open

Rohde & Schwarz Mobile Test Summit 2025 on the future of wireless communications...

05/11/2025

Riedel RefCam and Easy5G to Make Handball Debut at the Men's EHF EURO 2026

Wuppertal November 5, 2025 Riedel RefCam and Easy5G to Make Handball Debut at the Men's EHF EURO 2026The European Handball Federation (EHF) will introduce...

05/11/2025

Comscore and Polaris I/O Partner to Automate Audience Insights in MarketView for Faster Media Sale

Comscore and Polaris I/O Partner to Automate Audience Insights in MarketView for...

05/11/2025

RT Radio 1 officially launches refreshed weekday schedule

New schedule will be live on-air Monday 10 November Brand-new Today with David McCullagh from 9am Oliver Callan in all-new extended show from 11am to 1pm Kie...

05/11/2025

Explore the future with Science Week on RT

Explore the future with Science Week on RT Dive into a week of innovative, themed programming and content across RT television, radio and online Includes a ...

05/11/2025

New RT KIDS docuseries unites teens through football, friendship and fearless conversation

Get ready for six weeks of United FC, a brand-new, feel-good teen docuseries kic...

04/11/2025

Spotify Reports Third Quarter 2025 Earnings

Today, we announced our third quarter 2025 earnings, marking strong momentum as we surpassed 700 million Monthly Active Users and achieved double-digit subscrib...

04/11/2025

Spotify rapporterar intkter fr tredje kvartalet 2025

Idag rapporterar vi v rt resultat f r det tredje kvartalet 2025, vilket markerar en stark och fortsatt tillv xt d vi passerade 700 miljoner m natliga aktiva an...

04/11/2025

Comscore Reports Third Quarter 2025 Results

Comscore Reports Third Quarter 2025 ResultsRESTON, Va., November 4, 2025 Comscore, Inc. (Nasdaq: SCOR), a trusted partner for planning, transacting and evalu...

04/11/2025

FIRST LOOK images released for Bergerac Series 2 on U and U&DRAMA

Damien Moloney as Jim Bergerac As filming wraps on the highly anticipated second series of Bergerac (6x60'), UKTV today unveils a selection of first look i...

04/11/2025

Matt Smith stars in Sky Original limited event series The Death of Bunny Munro official trailer unveiled ahead of 20 November launch

Tuesday 4 November 2025 To view this content, please enable our use of cookies....

04/11/2025

From SMPTE MTS2025 Towards Automated Perceptual Shot Matching in Motion Pictures

From the recent SMPTE Media Technology Summit in Pasadena, with FilmLight Image Engineer, Daniele Siragusano, and Research Engineer, Julius Tschannerl. Matchin...

04/11/2025

RT announces Camogie: Inside the Championship, a two-part documentary offering all access to the 2025 All-Ireland Championship

Begins Thursday November 6 on RT One and RT Player at 10:15pm Camogie: Inside...

03/11/2025

Harmonic Expands Broadband Partnership with Spectrum Across Entire Subscriber Base

Harmonic's cOS Virtualized Broadband Platform Will Further Enhance Broadband...

03/11/2025

Trailer & poster unveiled for Sky Original festive family feature film Tinsel Town

Monday 3 November 2025 To view this content, please enable our use of cookies. ...

03/11/2025

Rohde & Schwarz acquires open source intelligence specialist Munich Innovation Labs GmbH

Rohde & Schwarz acquires open source intelligence specialist Munich Innovation L...

03/11/2025

Rohde & Schwarz launches revolutionary super wideband mobile network scanner, setting new standard for 5G

Rohde & Schwarz launches revolutionary super wideband mobile network scanner, se...

03/11/2025

Nokia and Rohde & Schwarz collaborate on AI-powered 6G receiver to cut costs, accelerate time to market

Nokia and Rohde & Schwarz collaborate on AI-powered 6G receiver to cut costs, ac...

03/11/2025

A4ESSOR and OCCAR sign new procurement contract to advance development of interoperable tactical communication

A4ESSOR and OCCAR sign new procurement contract to advance development of intero...

03/11/2025

Sitep Australia joins Rohde & Schwarz team for Hunter class frigate communications

Sitep Australia joins Rohde & Schwarz team for Hunter class frigate communicatio...

03/11/2025

Red Seat Ventures and The 33rd Team Announce Exclusive Sales Partnership

Red Seat Ventures and The 33rd Team Announce Exclusive Sales Partnership Red Seat Ventures to Spearhead Sales Representation for The 33rd Team's Dynamic S...