HomeSecurityCredential stuffing: State Farm customer accounts compromised

Credential stuffing: State Farm customer accounts compromised

State Farm American insurance company State Farm has been the victim of a “credential stuffing” attack. This is a subcategory of brute-force attacks. Hackers use various compromised credentials (from data breaches of other companies), enter them into sites and gain access to user accounts using those credentials.

So, State Farm began sending email notifications to customers who have been affected by this attack.

In this “data breach notification,” State Farm said:

“State Farm recently discovered a security issue in which a malicious hacker used a list of usernames and passwords obtained from another source, such as the dark web, to gain access to online accounts. During our investigation, we determined that the hacker had your State Farm account credentials.”

The company says the hacker obtained some customers' usernames and passwords , but there is no evidence they were used for other malicious activities. State Farm says the hacker could not have seen any other personal information.

After an investigation, the company discovered the accounts of the affected users and proceeded to reset the passwords.

According to the data breach notification filed with the California Attorney General's Office, the first attack, which was discovered, was on Saturday, July 6, 2019. The remaining attacks followed almost immediately: Monday, July 8, Friday, July 12, Saturday, July 13, Sunday, July 14, Wednesday, July 17, Friday, July 19, Saturday, July 20, and Monday, July 22.

At present, there is no further information.

Credential stuffing: State Farm customer accounts compromised

Credential stuffing attacks are becoming more common

"Credential stuffing" attacks are becoming increasingly common as hackers exploit numerous breaches and gain access to user credentials.

It is known that many users use the same credentials on many different sites. So, when hackers obtain the credentials (which have been leaked from other sources) they can gain access to multiple accounts.

A report showed that in the second half of 2018, there were 28 billion attempted “credential stuffing” attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS