Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

NY AG: Credential Stuffing Impacts 1.1 Million Users at 17 Companies

New York Attorney General Letitia James this week announced the results of an investigation into credential stuffing, which resulted in the discovery of 1.1 million compromised accounts associated with 17 companies.

New York Attorney General Letitia James this week announced the results of an investigation into credential stuffing, which resulted in the discovery of 1.1 million compromised accounts associated with 17 companies.

Credential stuffing – a type of cyberattack where adversaries repeatedly attempt to access a user’s account using usernames and passwords stolen from other online services – has become one of the most prevalent attack vectors on the Internet, Attorney General James says.

With almost all applications and websites employing passwords as means of authentication, credential stuffing allows cybercriminals to compromise multiple accounts of the individual, if they employ the same credentials.

According to a “Business Guide for Credential Stuffing Attacks” that the New York Attorney General has just released, there are over 15 billion credentials currently circulating on the web. Adversaries are abusing these to launch hundreds of billions of credential stuffing attacks each year.

[ Related: 21 Million Stolen Fortune 500 Credentials For Sale on Dark Web ]

Following months of monitoring online communities dedicated to credentials stuffing, a list of 1.1 million impacted customer accounts at 17 well-known companies was compiled, including accounts at food delivery services, online retailers, and restaurant chains.

Advertisement. Scroll to continue reading.

The Office of the Attorney General (OAG) has alerted the relevant companies so they would prompt password resets and notify their customers.

In addition to sharing details on the investigation, the newly released guide provides a series of recommendations on how companies can improve the security of their user accounts and prevent credential stuffing attacks.

Safeguards include the use of multi-factor authentication, bot detection software (such as CAPTCHA systems), implementing passwordless authentication where possible, using firewalls, and preventing users from securing accounts with passwords that were compromised in previous attacks.

The guide also recommends that organizations implement systems to detect credential stuffing attacks, through monitoring user activity, monitoring reports of fraud, notifying users of suspicious account activity, and monitoring the Internet for signs of compromised user accounts.

“Businesses have the responsibility to take appropriate action to protect their customers’ online accounts and this guide lays out critical safeguards companies can use in the fight against credential stuffing. We must do everything we can to protect consumers’ personal information and their privacy,” said Attorney General James.

In June 2021, global law enforcement agencies took down stolen login credentials marketplace Slilpp, which had been selling credentials for more than 1,400 account providers.

Related: LastPass Automated Warnings Linked to ‘Credential Stuffing’ Attack

Related: Dark Hash Collisions: New Service Confidentially Finds Leaked Passwords

Related: Tips for a Smarter Approach to Password Policy

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.