HomeSecurityPetSmart: Warns customers about credential stuffing attack

PetSmart: Warns customers of credential stuffing attack

PetSmart is warning some customers to reset their passwords due to a credential stuffing attack attempting to compromise accounts.

PetSmart credential stuffing

PetSmart is the largest pet-related retailer in the US, with 1,600 stores across the country.

The company notifies customers via email to keep an eye on their accounts.

PetSmart is resetting passwords on all accounts that were logged in during the credential stuffing attacks, as they could not determine whether the logged in user was the account owner or the attackers.

See also: Jason's Deli: Customer data breach via credential stuffing

" We want to assure you that there is no indication that petsmart.com or any of our systems have been compromised ," PetSmart said in an email

“Instead, our security tools detected an increase in password guessing attacks on petsmart.com, and during that time your account was logged in. While the login may have been valid, we wanted you to know. Out of an abundance of caution, to protect you and account , we have disabled your petsmart.com password. The next time you visit petsmart.com, simply click the “forgot password” link to reset your password.“.

PetSmart: Credential stuffing attack targets customers

During these attacks, attackers collect credentials from previous data breaches and then use them to try to log in to other websites. Many users use the same passwords across different services. So if credentials are stolen on one service, attackers can use them to log in to other accounts.

Typically, threat actors sell the compromised accounts to others, who use them to make purchases, redeem reward points, or steal money.

See also: American Express: Cards exposed by vendor breach

PetSmart: Warns customers of credential stuffing attack

Protection against PetSmart credential stuffing attacks

One of the most effective ways to protect yourself is to use strong, unique passwords for each account. This means using long passwords that include letters, symbols, and numbers. If you have trouble remembering a password for each account, consider using a password manager .

Enabling two-factor authentication (2FA) can also provide an extra layer of protection. This means that even if someone has your username and password, they'll need a second factor—usually a code sent to your phone—to gain access.

See also: Golden Corral: Data breach affects 183,000 people

Finally, it's important to regularly monitor your PetSmart accounts for any suspicious activity. If you notice anything unusual, change your password immediately and contact your service.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS