HomeinetCredential Stuffing attacks execute billions of login attempts

Credential Stuffing attacks execute billions of login attempts

Credential stuffing attacks are a growing problem, especially in the financial sector, where botnets can mass-produce so many login attempts that the end result resembles a DDoS (distributed denial of service) attack.

Credential stuffing

Credential stuffing attacks are carried out by trying combinations of usernames and passwords that have been leaked in the past, on different services such as Facebook, Twitter, Google and others. The success of the attack is based solely on the common practice that many users have of using common usernames and passwords between their online accounts.

The cybercriminals behind these attacks use automated tools that try combinations one by one. The ultimate goal is to gain access to an account, and then steal credit card details or personal information from the owner that can later be used for identity theft attacks.

Information published by a company that provides protection against DDoS attacks shows the unrealistic amount of 30 billion malicious login attempts in less than a year.

When credential stuffing attacks are carried out, the "traffic" on the site increases significantly. This not only slows down the response of the site, but in some cases there is a complete collapse, where users cannot even visit the page.

Akamai , the botnet made 59 requests per second during the day. However, it was easy to “filter” some of the attacks as the incoming traffic used the same user agent (Samsung Galaxy SM-G531H).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS