Table of Contents
ToggleAn easy guide to Credential Stuffing Attacks – How businesses can Detect and Prevent it?
Wondering if you have been a victim of a Credential Stuffing Attack? The answer is most likely YES! Surprisingly via platforms or applications of famous brands! Indeed, credential stuffing attacks are more common than you think; Here are some of the shocking data breaches which conclude that Credential Stuffing Attacks’ can happen to any brand, big or small.8fit
In 2018, 8fit, a health and fitness service app, suffered a data breach. After the violation, the attacker initiated the credential stuffing attack and later sold it on the dark web marketplace in February 2019. Compromised data: Email addresses, Genders, Geographic locations, IP addresses, Names, Passwords.BigBasket
In 2020, Bigbasket witnessed a data breach that impacted all its users. Before leaking the data publicly, the attacker was selling the data on the dark web. Compromised data: Dates of birth, Email addresses, IP addresses, Names, Passwords, Phone numbers, Physical addresses.Canva
In 2019, the famous brand Canva, a graphic design tool website, suffered a data breach. This Attack impacted 137 million Canva users. Compromised data: Email addresses, Geographic locations, Names, Passwords, Usernames.Dunzo
In 2019 June, the Indian brand Dunzo, a hyperlocal delivery service, suffered a data breach. This incident impacted 3.5 million unique email addresses. Compromised data: Device information, Email addresses, Geographic locations, IP addresses, Names, Phone numbers. Recently, the internet has witnessed an unprecedented increase in Credential Stuffing Attacks. Cybersecurity experts have issued warnings and alerts against it. In this blog, we will decode what Credential Stuffing Attack is, the cause of its rise, and how to prevent it.Decoding Credential Stuffing Attacks for Beginners
Credential Stuffing is a cybercrime happening all around the globe. It occurs when a hacker obtains many stolen or leaked login credentials (Username and Passwords) of one website and tests them on other platforms.
For example, the “Username and Password” of Email are the same as their bank accounts. Taking advantage of this, hackers acquire account credentials of platforms like Email that mostly have common or long-term passwords and use them to access crucial platforms like bank accounts to execute the fraudulent activity.
Is it Risky?- Indeed!
The hacker with unauthorized access attacks the victim’s bank account, e-commerce, or OTT account by drawing off funds, stealing credit or debit information or loyalty points, and sometimes committing another cybercrime. When taking all the possible advantages, the attacker sells the credentials on the dark web to make more profit, which is just the beginning of another cybercrime story. Usually, credentials data breaches are from the famous brands of EdTech, OTT platforms, e-commerce, and e-retail applications, for which many users share common or long-term passwords.Reasons why credentials stuffing attack is so prevalent!
The universally accepted identity mechanism: Credentials like “Usernames and Passwords” are the standard and trusted identity mechanism for access control. Almost all online portals or mobile apps grant access to users by identifying valid usernames and passwords. Unfortunately, this type of authentication is partially secure since it relies on just one factor: Something the user knows which someone else can quickly learn, e.g., birthdays, names, regular terms, etc. Extra security requires users to provide additional and distinct authentication factors, such as code or a biometric feature such as a fingerprint. People mostly reuse passwords for multiple accounts: An average person has nearly 100 passwords, according to the research by Nordpass. Creating or remembering so many passwords is next to impossible. Hence it is apparent that many people reuse passwords for many or all accounts. Taking advantage of this, attackers obtain legitimate credentials from one website and try their luck on other websites. Outrageous data breaches continue to occur: In 2005, we saw the first data breach of over 1 million records, followed by another breach of 94 million records. We thought this would be the most significant data breach, but the Yahoo data breach exposed an astonishing 3 billion records eight years later. The violations have continued to climb ever since. A profitable crime – Low-Cost Entry, High Returns: Credential Stuffing is a numbers game. Even a novice cybercriminal can test 100,000 credentials for less than 200$. Although the typical success rate is around 0.2 to 2%, the intruder can obtain anywhere from 200 to 2,000 accounts from a single attack. A million fraudulent login attempts could yield as many as 20,000 valid accounts for a cybercriminal willing to make a more significant investment. Attackers can run the same test on other websites with a similar success rate. After milking the advantages from the credentials, they can sell those ‘used’ credentials on the dark web to make more money. A large window of opportunity: The users are mostly unaware of the data breaches for months or even years after they occur. The average time of crime discovery or public disclosure is around 15 months; it gives the attacker a large window of time to intrude and abuse stolen credentials.