Credential Stuffing
www.remora.co.uk #credentialstuffing #databreach #cybersecurity

Credential Stuffing

The coronavirus crisis has meant a number of changes to how business is conducted, the biggest difference on a day to day basis has been the increase in Zoom or Teams for video conferencing.

The use of these tools has brought back a blast from the past with credential stuffing, where fraudulently gaining valid credentials for one site, allows cyber criminals to use the same credentials on other sites and gain access to those other legitimate accounts.

Credential stuffing used to have a small success rate, but new techniques and our own stupidity has led us to making life easier for cyber criminals, now over 700 000 login credentials for Zoom accounts are for sale on the dark web, the collation of these accounts in these numbers would simply not be possible if people did not create their Zoom account using the same username and password that they used elsewhere.

Cyber criminals are also utilising advances in automation and botnet technology to make credential stuffing a more viable attack. Security features built into web application logins often include deliberate time delays and IP address blocking for users who have repeatedly failed login attempts. Modern credential stuffing strategies attempt to avoid these defences by simultaneously attempting logins that appear to come from different device types and IP addresses.

Traditional prevention techniques are largely unsuccessful in mitigating credential stuffing attacks, as they are not designed to defend against attacks coming from a wide range of sources.

It is hard to prevent these sophisticated attacks, but the route cause of the attacks can be prevented through employee cyber education. Your staff are being targeted right now as cyber criminals know this offers them the easiest and cheapest route into your organisation. You can prevent this from happening to you through the Remora Staff Awareness Training, where your employees can develop the most up-to-date understanding of the cyber risks they face and how to mitigate them, enabling them to remain safe, both at work and at home. In turn your staff will go from your biggest cyber security threat to your best cyber security asset.

www.remora.co.uk #credentialstuffing #databreach #cybersecurity

要查看或添加评论,请登录

Chris Merchant的更多文章

  • New devices can cause cyber threats

    New devices can cause cyber threats

    5% of under 30’s in the UK received or bought a mobile phone for Christmas. The cyber security implications of a new…

  • Why you should be concerned about your ex-employees

    Why you should be concerned about your ex-employees

    January is the busiest month for job changes. The number of job changes in January may have reached a 10-year high.

  • Crypto Exchanges without cyber security must be shorted like crypto miners

    Crypto Exchanges without cyber security must be shorted like crypto miners

    Cryptocurrency is receiving a great deal of attention from investment companies, especially more conventional funds…

  • FTX Investors were negligent

    FTX Investors were negligent

    In the last couple of weeks we have all come to learn about the cryptocurrency exchange FTX which filed for Chapter 11…

    1 条评论
  • Cyber Monitoring prevents ICO fines

    Cyber Monitoring prevents ICO fines

    The Information Commissioner's Office (ICO) fined Interserve Group Ltd. £4.

  • Revolut and TAP herald a new leapfrog attack

    Revolut and TAP herald a new leapfrog attack

    A leapfrog attack occurs when hackers obtain passwords, valid email addresses, or ID information in one attack and then…

  • Cyber Insurance - is it worth paying?

    Cyber Insurance - is it worth paying?

    The validity of some cyber insurance policies being offered in the UK is currently under increasing scrutiny. Insurance…

  • T-Mobile hack to cost $500m

    T-Mobile hack to cost $500m

    T-Mobile hack to cost $500m “Keeping our customers’ data safe is a responsibility we take incredibly seriously and…

  • Can data analytics predict a football season?

    Can data analytics predict a football season?

    Without a world cup this summer, using my time unwisely is more difficult to justify, so I wondered if it was possible…

  • Cyber Threats to Online Gambling Platforms

    Cyber Threats to Online Gambling Platforms

    Customers are at the core of every aspect of the gaming industry and without them the industry simply would not exist…

社区洞察

其他会员也浏览了