HomeSecuritySam's Club: Credential stuffing behind account breach?

Sam's Club: Credential stuffing behind account breach?

Sam's Club

For the past two weeks, Sam's Club has been sending security alerts and password reset emails to customers who may have been affected by credential stuffing attacks. Sam's Club is an American company owned by Walmart and has been in operation since 1983.

Possible credential stuffing attacks

The messages that Sam's Club has sent to its members (and seen by BleepingComputer), indicate that unauthorized users may have gained access to their (members') accounts.

The company discovered the unauthorized access in September. According to Sam's Club, the attackers already had credentials users' phishing attacks.

In credential stuffing attacks, attackers try username and password combinations that have been leaked online from breaches at other companies. Using the exposed credentials, hackers could gain access to a Sam's Club member's account (if that member also uses their passwords on other sites).

This is why security professionals emphasize the importance of using different credentials on different sites and applications. Using the same credentials on all accounts is dangerous because if one site is compromised and user , other accounts. Criminals try the exposed credentials on other applications and may be able to gain access (credential stuffing).

“We recently learned that, in mid-September, an unauthorized party used your login credentials (email address and password) to access your Sam's Club account. Based on our investigation, the credentials used did not come from a Sam's Club breach,” the security alert sent to members said.

"Instead, it is possible that your credentials were obtained from another source, for example, from another company's website, where you may have used the same or similar login details," he said.

Sam's Club spokesperson Meggan Kring told BleepingComputer:

“Protecting the privacy of our members is something we take very seriously and we are constantly monitoring for suspicious activity. As part of this effort, we recently found that unauthorized users had logged into certain member accounts.“.

Credential stuffing

The spokeswoman said the unauthorized access did not come from a breach of the company's systems. The attackers already had the credentials, likely from phishing attacks, malware or breaches at other companies.

“We have reset the passwords for these accounts and are taking additional measures to protect them from fraudulent activity“.

Automatic password reset

All affected Sam's Club members received security notifications for automatic password resets due to suspected unauthorized account access.

One of the emails sent by the company said:

“Our monitoring indicates that someone may be attempting to exploit your account. As a precaution, we have reset your password on SamsClub.com. We apologize for any inconvenience this may have caused, but we are focused on protecting you and your account“.

This proactive monitoring of customer accounts and prompt password resets is very important. Other companies should follow Sam's Club's example.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS