Credential Stuffing Attacks Reach “Unprecedented” Levels

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Okta Reports Unprecedented Scale of Credential Stuffing Attacks

Okta, a leading identity and access management provider, has reported a surge in credential stuffing attacks targeting its solutions, resulting in the breach of some customer accounts. These attacks, which use techniques like password-spraying and brute-forcing, have been facilitated by the availability of residential proxy services, stolen credentials, and scripting tools.

The attacks, originating from TOR anonymization networks and residential proxies like NSOCKS and Luminati, have been notably effective against organizations using Okta’s Classic Engine with ThreatInsight configured in Audit-only mode. The FBI has warned of a rising trend of cybercriminals using residential proxies for large-scale credential stuffing attacks.

Despite the low success rate of credential stuffing attacks, estimated at around 0.1%, they remain profitable due to the vast number of credentials attackers possess and the prevalence of password reuse among digital users. Okta reports that credential stuffing accounts for 24.3% of all login attempts in 2023, with retail and e-commerce companies being the most targeted.

To counter these threats, Okta recommends enabling ThreatInsight in Log and Enforce Mode, denying access from anonymizing proxies, implementing enhanced security features like CAPTCHA challenges, and using Dynamic Zones to manage access based on criteria like geolocation.

As the prevalence of credential stuffing attacks continues to rise, organizations must remain vigilant and implement robust security measures to protect their systems and data from malicious actors.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Dubai Government Launches Real-Time Cybersecurity Dashboard in Partnership with Microsoft

The Dubai Electronic Security Center (DESC) has partnered with Microsoft to launch a new Zero Trust assurance dashboard, providing real-time visibility into the cybersecurity...

INS Trishul arrives in Toulon with upgraded BrahMos missile capability

INS Trishul, the Indian Navy’s Talwar-class frigate, arrived at Toulon naval base in France on September 22, 2026, as part of its operational deployment...

Cisco Talos Unveils CAIRN Framework to Track AI-Integrated Malware with Autonomous Command Systems

Cybersecurity researchers at Cisco Talos have introduced an open-source framework called the Cognitive Artifact Intelligence Research Network (CAIRN) to help classify and analyze AI-integrated...

FQ-42 Vengeance unmanned fighter aircraft displayed at AFA 2026

The FQ-42 Vengeance unmanned fighter aircraft, developed by General Atomics, was prominently displayed at the Air, Space and Cyber conference on September 14, 2026....