Credential stuffing attacks becoming common | xxxCredential stuffing attacks becoming common – xxx
菜单

Credential stuffing attacks becoming common

八月 7, 2019 - BleepingComputer

Credential stuffing attacks becoming common

United States based insurance company State Farm has begun to send out email notifications to users whose online account login credentials were discovered by an attacker during a credential stuffing attack.

A credential stuffing attack is when attackers compile usernames and passwords that were leaked from different company’s data breaches and use those credentials to try and gain access to accounts at other sites. This type of attack works particularly well against users who use the same password at every site.

In a “Notice of Data Breach” sent to users impacted by this breach, State Farm says:

State Farm recently detected an information security incident in which a bad actor used a list of user IDs and passwords obtained from some other source, like the dark web, to attempt access to State Farm online accounts. During our investigation, we determined that the bad actor possessed the user ID and password for your State Farm online account. 

State Farm states that a bad actor was able to confirm the username and passwords of impacted users, but that no personal information was viewable and that fraudulent activity was not detected. It is not known, based on the data breach notification, if the attackers actually logged into the accounts as well.

Credential stuffing attacks becoming common
Portion of State Farm Notification

In response to these attacks, State Farm reset the passwords for accounts whose login credentials were confirmed by the attacker.

According to the data breach notification filed with the Office of the California Attorney General, the first detected credential stuffing attack was on Saturday, July 6, 2019. Subsequent attacks were on Monday, July 8, 2019, Friday, July 12, 2019, Saturday, July 13, 2019, Sunday, July 14, 2019, Wednesday, July 17, 2019, Friday, July 19, 2019, Saturday, July 20, 2019, and Monday, July 22, 2019.

BleepingComputer has reached out to State Farm for further information on the breach dates and the number of accounts impacted in the event but had not heard back at the time of this publication. This article will be updated when a response is received.

Credential stuffing attacks becoming common

Credential attacks are becoming more common as data breaches expose the account credentials of their users.

Knowing that many people use the same password at numerous sites, attackers capitalize on this by compiling these exposed credentials and attempting to access other accounts that the user may have.

It has gotten so bad, that the 2019 State of the Internet report by Akamai states 28 billion credential stuffing attempts were detected in the second half of 2018.

These types of attacks have caused companies like TripAdvisor to monitor data breaches for exposed accounts and compare them to the login credentials of their own user accounts. When they detect a match, TripAdvisor invalidates the account and makes the user reset their password.

Related Articles:

Crooks Sell Credentials Using Combolists-as-a-Service Model

Streaming Service Suffers 13-Day DDoS Siege by IoT Botnet

TripAdvisor Invalidates Member Passwords Found in Data Breaches

Forum Rules and Posting Guidelines

Bleeping Computer® is a community of individuals of all ages who are here to learn new information, to help each other, and to help their fellow peers. With that in mind, we ask that all members please follow these simple rules in order to create an atmosphere where everyone feels comfortable.

The rules are as follows:

Violation of any of these rules can lead to a banning of the user from our Web Site and a deletion of their account. The consequences will be determined by the Staff on a case by case basis.

When posting you agree that the administrators and the moderators of this forum have the right to modify, delete, edit or close any topic, signature, account, or profile data at any time that they see fit. If you have any questions concerning this, please do not start a new thread, but rather private message to an administrator or moderator.

contact us


Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51