Credential Stuffing Attacks are Targeting Gamers

Here's a few easy steps to protect yourself

<p><span data-contrast&equals;"none">The quarantine is tough&comma; but for those who enjoy spending time at home&comma; it <&sol;span><span data-contrast&equals;"none">isn&&num;8217&semi;t<&sol;span><span data-contrast&equals;"none"> that bad&period; And what better way to spend countless hours at home than playing immersive video games&quest; Game developers and publishers are reporting an increase in sales&comma; which is <&sol;span><span data-contrast&equals;"none">excellent&period; Even though some game releases have been postponed due to everyone working from home&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">There&&num;8217&semi;s<&sol;span><span data-contrast&equals;"none"> one alarming trend in the game industry that&comma; sadly&comma; increased during the quarantine&period; <&sol;span><span data-contrast&equals;"none">That&&num;8217&semi;s<&sol;span><span data-contrast&equals;"none"> hacking attacks directed against gamers&period; A<&sol;span><a href&equals;"https&colon;&sol;&sol;portswigger&period;net&sol;daily-swig&sol;gamers-fragged-by-surge-in-credential-stuffing-attacks-during-lockdown&num;&colon;~&colon;text&equals;Gamers&percnt;20as&percnt;20individuals&percnt;20are&percnt;20also&comma;login&percnt;20pages&percnt;20of&percnt;20targeted&percnt;20sites&period;"><span data-contrast&equals;"none">ccording to cybersecurity news at <&sol;span><span data-contrast&equals;"none">portswigger<&sol;span><&sol;a><span data-contrast&equals;"none">&comma; there&&num;8217&semi;s <&sol;span><span data-contrast&equals;"none">an increase in DDoS attacks&comma; SQL injections&comma; and credential stuffing&period; The last one &&num;8211&semi; credential stuffing attack &&num;8211&semi; is easily executable and is gaining in popularity due to decent financial gains&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><span data-contrast&equals;"none">Luckily&comma; <&sol;span><span data-contrast&equals;"none">it&&num;8217&semi;s<&sol;span><span data-contrast&equals;"none"> very easy to defend against&comma; so we&&num;8217&semi;d like to e<&sol;span><span data-contrast&equals;"none">xplain to you what credential attack is&comma; and how you can protect your gaming accounts&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<h4 style&equals;"text-align&colon; center&semi;"><strong>What is a Credential Stuffing Attack&quest;<&sol;strong><&sol;h4>&NewLine;<p><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <a href&equals;"https&colon;&sol;&sol;4a7efb2d53317100f611-1d7064c4f7b6de25658a4199efb34975&period;ssl&period;cf1&period;rackcdn&period;com&sol;credential-stuffing-attacks-vs-brute-force-attacks-showcase&lowbar;image-8-p-2767&period;jpg"><img class&equals;"aligncenter size-large" src&equals;"https&colon;&sol;&sol;4a7efb2d53317100f611-1d7064c4f7b6de25658a4199efb34975&period;ssl&period;cf1&period;rackcdn&period;com&sol;credential-stuffing-attacks-vs-brute-force-attacks-showcase&lowbar;image-8-p-2767&period;jpg" width&equals;"860" height&equals;"520" &sol;><&sol;a><&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">First Credential stuffing attacks appeared in 2014 and over the last couple of years rapidly increased in popularity&period; In fact&comma; th<&sol;span><span data-contrast&equals;"none">ey became so common that even the FBI in the United States <&sol;span><a href&equals;"https&colon;&sol;&sol;www&period;documentcloud&period;org&sol;documents&sol;7208239-FBI-PIN-on-credential-stuffing-attacks&period;html&quest;ref&equals;hackernoon&period;com"><span data-contrast&equals;"none">released a Private Industry Notification<&sol;span><&sol;a><span data-contrast&equals;"none">&comma; warning that the US finan<&sol;span><span data-contrast&equals;"none">cial sector became targeted by cybercriminals&period; And numerous password <&sol;span><a href&equals;"https&colon;&sol;&sol;nordpass&period;com&sol;free-password-manager&sol;"><span data-contrast&equals;"none">privacy<&sol;span><&sol;a><span data-contrast&equals;"none"> cybersecurity companies are alerted to take better care of your online accounts&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p>A Credential stuffing attack is a type of cyber attack that is surprisingly simple to execute&period; Typically&comma; the attack involves four easy steps and requires minimal effort on the part of the attacker&period; The first step is for a significant number of username-password combinations to be leaked online from an insecure service&comma; which unfortunately happens more often than it should&period; This leaked information is often sold on the Black markets of the web&period; Once a cybercriminal has obtained a dataset of leaked username-password combinations&comma; which are known as combolists&comma; they can use them in a Credential stuffing attack&period; To protect yourself against this type of attack&comma; you may want to consider using a <a href&equals;"https&colon;&sol;&sol;fully-verified&period;com&sol;id-verification-service&sol;">service from Fully-Verified<&sol;a> or another reputable provider&comma; which can help you secure your login credentials and prevent unauthorized access to your accounts&period;<&sol;p>&NewLine;<p><span data-contrast&equals;"none">Next step is to obtain an automation software&comma; which can be purchased for several dollars&period; With the help of this <&sol;span><span data-contrast&equals;"none">software&comma; the hacker then targets another service with leaked credentials&comma; in hopes that the same username and password were reused&period; And if this turns out to be the case&comma; the account is stolen and most often sold on the same black markets&period; <&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"><a href&equals;"https&colon;&sol;&sol;www&period;secureworldexpo&period;com&sol;hubfs&sol;credential&percnt;20stuffing&period;png"><img class&equals;"aligncenter size-large" src&equals;"https&colon;&sol;&sol;www&period;secureworldexpo&period;com&sol;hubfs&sol;credential&percnt;20stuffing&period;png" width&equals;"667" height&equals;"422" &sol;><&sol;a><&sol;span><span data-contrast&equals;"none">One of the mor<&sol;span><span data-contrast&equals;"none">e recent cases of successful credential stuffing attacks is the <&sol;span><a href&equals;"https&colon;&sol;&sol;www&period;cpomagazine&period;com&sol;cyber-security&sol;new-disney-plus-streaming-service-hit-by-credential-stuffing-cyber-attack&sol;"><span data-contrast&equals;"none">Disney&plus; case<&sol;span><&sol;a><span data-contrast&equals;"none">&comma; which happened right after the launch&period; Cy<&sol;span><span data-contrast&equals;"none">bercriminals had a vast collection of <&sol;span><span data-contrast&equals;"none">combolists<&sol;span><span data-contrast&equals;"none">&comma; and right after the release of this new popular streaming service&comma; targeted it with acquired credentials&period; The success rate proved to be high&comma; and soon Disney&plus; accounts were sold for half the price on online<&sol;span><span data-contrast&equals;"none"> Black Markets&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">The crucial thing to notice is that this attack can only succeed if the same username-password was used&period; Sadly&comma; password management is still a problem&comma; and such easy-to-guess passwords as &&num;8220&semi;qwerty&&num;8221&semi; or &&num;8220&semi;password&&num;8221&semi; or &&num;8220&semi;123456&&num;8221&semi; are still used&period; <&sol;span><span data-contrast&equals;"none">And that is precisely why this attack became so popular&period; <&sol;span><span data-contrast&equals;"none">It<&sol;span><span data-contrast&equals;"none">’<&sol;span><span data-contrast&equals;"none">s<&sol;span><span data-contrast&equals;"none"> very easy to execute and requires little &&num;8220&semi;hacking&&num;8221&semi; in the traditional sense <&sol;span><span data-contrast&equals;"none">of the word&period; And lousy password management practices ensure this attack is profitable to a cybercriminal&period; <&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;">Regularly change passwords and use a <a href&equals;"https&colon;&sol;&sol;www&period;passwarden&period;com&sol;password-checker">strong password checker<&sol;a> to keep them secure&period;<&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">Luckily&comma; th<&sol;span><span data-contrast&equals;"none">ere are easy ways to protect yourself against these kinds of attacks&comma; so go straight ahead to the next paragraph&comma; where you can take the first steps to secure yourself online&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<h4 style&equals;"text-align&colon; center&semi;"><strong>How to Protect Yourself Against Credential Stuffing Attacks&quest; <&sol;strong><&sol;h4>&NewLine;<p><span data-contrast&equals;"none"> <a href&equals;"https&colon;&sol;&sol;images&period;idgesg&period;net&sol;images&sol;article&sol;2019&sol;10&sol;cso&lowbar;many&lowbar;keys&lowbar;one&lowbar;lock&lowbar;by&lowbar;petr&lowbar;bonek&lowbar;gettyimages-872739656&lowbar;2400x1600-100815712-large&period;jpg"><img class&equals;"aligncenter size-large" src&equals;"https&colon;&sol;&sol;images&period;idgesg&period;net&sol;images&sol;article&sol;2019&sol;10&sol;cso&lowbar;many&lowbar;keys&lowbar;one&lowbar;lock&lowbar;by&lowbar;petr&lowbar;bonek&lowbar;gettyimages-872739656&lowbar;2400x1600-100815712-large&period;jpg" width&equals;"1200" height&equals;"800" &sol;><&sol;a>The first step&comma; o<&sol;span><span data-contrast&equals;"none">bviously&comma; is not to use the same username-password for different services&period; However&comma; <&sol;span><span data-contrast&equals;"none">it&&num;8217&semi;s<&sol;span><span data-contrast&equals;"none"> harder to do than it sounds&comma; because we use so many other services these days&comma; that there would be a need to remember hundreds of passwords&period; But password managers are <&sol;span><span data-contrast&equals;"none">there to help&excl;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><span data-contrast&equals;"none">Password managers are cybersecurity software that was designed to store large amounts of long and complex passwords&period; Remembering a <&sol;span><span data-contrast&equals;"none">60 symbol<&sol;span><span data-contrast&equals;"none"> password with upper and lower case letters&comma; and numbers can be challenging for the best of us&period; And <&sol;span><span data-contrast&equals;"none">remembering a lot of passwords like this is nearly impossible&period; <&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">Password managers quickly rose to popularity&period; Not only do they boost your cybersecurity significantly&comma; but they also provide a more comfortable browsing experience due to autofill function&period; Y<&sol;span><span data-contrast&equals;"none">ou can <&sol;span><span data-contrast&equals;"none">actually save<&sol;span><span data-contrast&equals;"none"> time when browsing with a password manager because you don&&num;8217&semi;t have to type passwords anymore and import them straight from the manager with one click&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> The <a href&equals;"https&colon;&sol;&sol;www&period;deccanherald&period;com&sol;brandpr&sol;what-is-a-password-manager-for-mac-and-how-it-works-2773438">best password manager for Mac<&sol;a> is very useful to secure your various accounts&period;<&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">Another service <&sol;span><span data-contrast&equals;"none">we&&num;8217&semi;d<&sol;span><span data-contrast&equals;"none"> advise using is a www&period;haveibeenpwnd&period;com website&comma; that was creat<&sol;span><span data-contrast&equals;"none">ed by a prominent cybersecurity expert Troy Hunt&period; On it&comma; you can check your email address for leaks so that you know which one of your passwords have been exposed and can change it to a more secure one&period;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> Using a disposable email address from <a href&equals;"https&colon;&sol;&sol;10minute-email&period;com&sol;">10 Minute Mail<&sol;a> to register on websites&comma; blogs&comma; and forums keep your real one hidden from hackers&&num;8217&semi; eyes&comma; thereby improving email security&period; <&sol;span><span data-contrast&equals;"none">These steps do sound easy&comma; but even small changes can be crucial and defend your account against a cybercriminal looking for an easy grab&period; And what could be worse than losing your steam account with all the games on it&quest;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p><span data-contrast&equals;"none">We hope this has been informative a<&sol;span><span data-contrast&equals;"none">nd will help some of you secure yourself online better&excl;<&sol;span><span data-ccp-props&equals;"&lbrace;&quot&semi;201341983&quot&semi;&colon;0&comma;&quot&semi;335559740&quot&semi;&colon;276&rcub;"> <&sol;span><&sol;p>&NewLine;<p style&equals;"text-align&colon; center&semi;"><em>This article contains sponsored links&period;<&sol;em><&sol;p>&NewLine;

Exit mobile version