Credential stuffing is a method that hackers use to infiltrate a company’s system by automated injection of breached username & password pairs. Attackers use credentials to bypass anti-spam and firewall devices and access users accounts. Once they were inside the company network, they can send phishing emails or compromise company systems/data. Note that attackers just need to gain access to only a few accounts, or just one admin account to compromise the system. According to OWASP report, these Attackers/hackers do money laundering, social security fraud, and identity theft, or disclose legally protected highly sensitive information.

Situation of Breached Credentials:

Usage of stolen credentials is reported as #1 reason in 2018 Verizon Data Breach Investigations Report with being the cause of 22% of all breaches in 2017. 6 out of 10 confirmed data breaches in 2016 leveraged weak or stolen passwords.

Simple Steps to Prevent Password Breaches:

  • Use 2-Factor Authentication
  • Change passwords at least in three months
  • Create awareness among employees
    • Ask employees to not use company credentials for their personal accounts (social media, online purchasing etc.). Research shows that nearly 75% of people are still using duplicate passwords across multiple systems
    • To Use different passwords for different purposes like business, personal and banking
  • Monitoring continuously of the cyber data leaks

We can see credential stuffing in OWASP – 2017 – Top 10 critical web application security risks report under the second most critical risk: Broken Authentication. According to OWASP – 2017 report, Attackers/hackers do money laundering, social security fraud, and identity theft, or disclose legally protected highly sensitive information.

Some High-Profile Breaches Caused: 

LinkedIn Breach in 2012:

LinkedIn, the Social Networking Website was hacked in 2012 by Russian cyber criminals and they hacked around 65M user accounts & passwords. They posted the stolen credentials on a Russian forum, the next day after the LinkedIn was breached. Also in 2016, they found out that 100M email addresses and hashed passwords are claimed as an additional data along with breached credentials in 2012. LinkedIn was not sure whether the hackers were also able to steal email IDs associated with the compromised user accounts.

Adobe Breach:

Adobe was hacked in October 2013, where the attackers had gotten access to IDs and encrypted passwords of 38 Million active users. After many weeks of research, adobe found out that the hacker had exposed customers IDs, Names, Passwords and Debit/Credit Card information.

Home Depot:

Home Depot’s POS systems had been infected with Malware, which posed as Anti-Virus Software. Home Depot agreed to pay a minimum of 19.5 Million dollars to compensate. The settlement covered about 40M people, whose payment card data was stolen.

Summary:

Breached Credentials cause a lot of damage every year to many companies. Continuous Monitoring is also required along with the above-mentioned preventive methods.

Reference:

https://www.csoonline.com/article/2130877/data-breach/the-biggest-data-breaches-of-the-21st-century.html

https://en.wikipedia.org/wiki/List_of_data_breaches

Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (Monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

6 City Round Table On "New Guidelines & CISO Priorities for 2025" (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    We are pleased to invite you to an exclusive roundtable series hosted by CISO Platform in partnership with FireCompass. The roundtable will focus on "New Guidelines & CISO Priorities for 2025"

    Date: December 1st - December 31st 2025

    Venue: Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata

    >> Register Here

  • Created by: Biswajit Banerjee

Fireside Chat With Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.)

  • Description:

    We’re excited to bring you an insightful fireside chat with Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.) and Erik Laird (Vice President - North America, FireCompass). 

    About Sandro:

    Sandro Bucchianeri is an award-winning global cybersecurity leader with over 25…

  • Created by: Biswajit Banerjee
  • Tags: ciso, sandro bucchianeri, nab