One of the UK's largest energy companies , Npower , was forced to disable its mobile app after it learned of a coordinated credential stuffing campaign targeting users . its

Npower has notified all customers affected by the credential stuffing attacks, although it is currently unclear how many user have been affected.
Attackers may have gained access to personal information such as: dates of birth, contact details and addresses, some financial information (last four digits of bank account numbers), etc.
It is said that the energy company's customers were informed about the incident in early February.
“We immediately locked the affected online accounts, blocked suspicious IP addresses and disabled the Npower app,” the company said in a statement.
The energy company also informed the Information Commissioner's Office and Action Fraud.
“The security and protection of our customers’ data is our top priority,” Npower said.
Npower intended to remove the mobile app, but credential stuffing attacks accelerated the process.

Credential stuffing attacks are successful because of a common mistake that many users. This mistake is using the same passwords across multiple applications and sites. If one account is compromised, the rest can be compromised as well, since attackers use the stolen credentials in software that tests them on many different sites.
James McQuiggan of KnowBe4 explained that users can try free monitoring services, such as HaveIBeenPwned, to check if credentials and data have been compromised.
“Monitoring your passwords is the first step in protecting your accounts. The second step is to change your password if it has been compromised. The third step is to have unique and strong passwords for every account you create, to reduce the chance of a successful credential stuffing attack. Finally, by using multi-factor authentication (MFA), you can add an extra layer of protection to an account,” he said.
Source: Infosecurity Magazine
