What is it - Credentials stuffing attack is a type of cyber attack where attackers use usernames-passwords combinations leaked at other sites to gain illegal access on user accounts.
Examples of Credential stuffing attacks
Example 1 - Intuit, a victim of credential stuffing attack
In February 2019, the financial software company Intuit learned that TurboTax account users’ tax return information was compromised in a credential stuffing attack. The financial company disclosed that an unauthorized party accessed TurboTax accounts by using the username-password combination obtained from a non-Intuit source.
The unauthorized party who gained illegal access to TurboTax user accounts obtained information contained in the previous year's tax return or current tax return in progress.
Example 2 - Dunkin’ Donuts suffered a credential stuffing attack
On January 10, 2019, Dunkin’ Donuts suffered a credential stuffing attack which led to attackers gaining unauthorized access to some of its customers’ accounts. Attackers used user credentials leaked at other sites to gain access to DD Perks rewards accounts.
DD Perks account includes information such as users’ first and last names, email addresses (also used as usernames), 16-digit DD Perks account number and DD Perks QR codes.
Once attackers gained access to customers’ Dunkin' Donuts accounts via credential stuffing attack, they have put up the breached accounts for sale. The accounts are then bought by other persons who use the reward points at Dunkin' Donuts shops to receive free beverages and other discounts.
It is to be noted that this is the second credential stuffing attack that Dunkin’ Donuts has experienced in the last three months. The first credential stuffing attack occurred on October 31, 2018.
How to stay protected?
It is best to use two-factor authentication while login and log out after the session is complete.
Publisher