Credential Stuffing Attacks Reach “Unprecedented” Levels

Published:

spot_img

Okta Reports Unprecedented Scale of Credential Stuffing Attacks

Okta, a leading identity and access management provider, has reported a surge in credential stuffing attacks targeting its solutions, resulting in the breach of some customer accounts. These attacks, which use techniques like password-spraying and brute-forcing, have been facilitated by the availability of residential proxy services, stolen credentials, and scripting tools.

The attacks, originating from TOR anonymization networks and residential proxies like NSOCKS and Luminati, have been notably effective against organizations using Okta’s Classic Engine with ThreatInsight configured in Audit-only mode. The FBI has warned of a rising trend of cybercriminals using residential proxies for large-scale credential stuffing attacks.

Despite the low success rate of credential stuffing attacks, estimated at around 0.1%, they remain profitable due to the vast number of credentials attackers possess and the prevalence of password reuse among digital users. Okta reports that credential stuffing accounts for 24.3% of all login attempts in 2023, with retail and e-commerce companies being the most targeted.

To counter these threats, Okta recommends enabling ThreatInsight in Log and Enforce Mode, denying access from anonymizing proxies, implementing enhanced security features like CAPTCHA challenges, and using Dynamic Zones to manage access based on criteria like geolocation.

As the prevalence of credential stuffing attacks continues to rise, organizations must remain vigilant and implement robust security measures to protect their systems and data from malicious actors.

spot_img

Related articles

Recent articles

Flaw in OpenAI, Anthropic, and Google APIs Allows Weaker AI Models to Decode Stronger Models’ Reasoning

A newly disclosed flaw in the APIs of OpenAI, Anthropic, and Google has raised significant security concerns, allowing researchers to recover internal reasoning and...

Cyberattacks Target North Carolina Ports and Ryde, Exposing Millions of Records

In a week marked by significant cyber incidents, the cybersecurity landscape has seen notable attacks targeting critical infrastructure and major companies. The latest Threat...

Active Exploitation of High-Severity Vulnerability CVE-2026-20349 in Cisco ASA and FTD Software

Number: AL26-018Date: August 13, 2026 Active Exploitation of High-Severity Vulnerability CVE-2026-20349 in Cisco ASA and FTD Software The Canadian Centre for Cyber Security (Cyber Centre) has...

Emirates SkyCargo Transports UAE’s First AI-Enabled Satellite Altair-1 to Los Angeles Ahead of October Launch

Emirates SkyCargo has successfully transported Altair-1, the UAE’s first commercial AI-enabled earth observation satellite, from Dubai to Los Angeles. This significant milestone, part of...