Please ensure Javascript is enabled for purposes of website accessibility

What AG report on ‘credential stuffing’ hacks mean for your business

What AG report on ‘credential stuffing’ hacks mean for your business

Listen to this article
Jenny Holmes

In January, New York Attorney General Letitia James released a report summarizing the findings of a broad investigation into so-called “credential stuffing” that revealed more than 1.1 million online accounts have been compromised in cyberattacks at 17 prominent companies. The report explains that the attacks involve repeated, automated attempts to access online accounts using usernames and passwords stolen from other online services and also offers suggestions for how businesses can protect themselves.

Credential stuffing has become a popular form of cyberattack. In fact, the operator of one large content delivery network reported that it witnessed more than 193 billion attacks of this nature in 2020 alone. So what is credential stuffing? Credential stuffing occurs when hackers who come into possession of a user’s password for one website or app then attempt to use the same password to access other online accounts linked to that same user. Despite our best intentions, we are all guilty of reusing the same passwords across multiple online services and websites. We know the risks but yet we can’t help ourselves; we continue to use the same passwords again and again.

According to the Attorney General’s report, there are more than 15 billion stolen login credentials being circulated across the Internet — giving rise to an extraordinary number of opportunities for hackers to exploit using bots or other automated mechanisms. In a typical credential stuffing attack, the cybercriminal will submit hundreds of thousands of login attempts on a business’s website using automated software and lists of stolen credentials from the dark web or hacking forums. Only a small percentage of these attempts will likely succeed, but given the volume of the attempts, a single attack can result in thousands of compromised accounts and severely disrupt the availability of a website.

Once a cybercriminal gains access to an account, it may use the available information in a multitude of ways. For example, the criminal can view and use the individual’s personal information, including name and address, for further cyberattacks. Or if the individual has a stored credit card, the criminal could make fraudulent purchases. The cybercriminal could even sell the login credentials or acquired personal information to another bad actor on the dark web. Whether we like it or not, our personal information has certainly become a hot commodity.

The Attorney General’s investigation was proactive and involved the review of thousands of dark web posts that contained customer login credentials that attackers purportedly had tested in a credential stuffing attack. From these posts, the investigators determined that customer accounts at seventeen well-known online retailers, restaurant chains and food delivery services appeared to have been compromised in credential stuffing attacks and proceeded to warn those seventeen companies. According to the Attorney General, “businesses have the responsibility to take appropriate action to protect their customers’ online accounts.”

The report acknowledged that credential stuffing attacks are, for the most part, unavoidable, but urged all businesses that maintain online customer accounts to have data security programs that include effective safeguards to protect customers from credential stuffing attacks. Some recommended safeguards include: (1) bot detection services to identify the large scale attempts to login; (2) multi-factor authentication, which would generally halt the attacker from gaining access; and (3) password-less authentication, where an attacker would need to know more information besides a password to gain access.

Credential stuffing is just one of many types of attacks cybercriminals are now effectuating. It joins the list of ransomware, phishing, and spoofing as ways for cybercriminals to hurt your customers and disrupt your business.

On Nixon Peabody’s recent podcast, “She Talks Law,” I discussed the time is now to either draft or review existing cybersecurity policies. Implementing written, internal policies that govern or regulate the ways that your business collects, uses, stores and shares important information is the best way to create a secure space for your customers to interact with your business. These policies should describe the treatment of personal information at all stages — from collection to disposal — and identify who or what department is responsible for ensuring the security of the information.

Importantly, businesses can no longer ignore the need for effective policies governing your information collection because they are “too small” or “not sophisticated enough” for cybercriminals to attack. Gone are the days of simply ignoring cybersecurity until it happens. Cybercriminals seeking to steal information or disrupt your business are not discriminating against size or sophistication. In fact, smaller or less sophisticated businesses may be just as attractive, if not more so, to cybercriminals as easy targets. Having written policies holds your business accountable for the protection of information.

But no safeguard is 100 percent effective and it’s therefore imperative that businesses develop, implement and maintain written incident response plans that can effectively and quickly guide a business through the response and remediation of a cyberattack. Incident response policies only work for your company if they are an active part of your company’s culture. This means you cannot just draft an incident response policy and let it sit. Effective response policies must be reviewed, tested, and taught regularly. All employees must be aware and understand the protocols of response policies, not just upper management or your information security department.

As we enter the new year, the Attorney General’s investigation and report is a well-timed reminder that cybersecurity and data privacy should remain on the forefront of business plans. Prioritizing effective cybersecurity programs now can help reduce the risk — and the fallout — of a cybersecurity attack.

Jenny Holmes is counsel in Nixon Peabody’s Litigation practice and serves as deputy leader of the Privacy and Technology group. She is a Certified Information Privacy Professional (CIPP/US). Holmes developed this article with Nixon Peabody partner Jason Kravitz.

Nixon Peabody’s new podcast, “She Talks Law,” is a celebration of women business owners and entrepreneurs across industries. In each episode, women business owners, entrepreneurs and industry leaders discuss legal issues affecting women in business and in life. Listen and subscribe to the latest episode of She Talks Law on Spotify and Apple Podcasts.

 

e