59 results found with an empty search
- New White Paper from The Fraud Practice and myNetWatchman Discusses Balancing Protection Against ATO with Preserving the User Experience
We provide an alternative perspective on the myth that 2FA makes user credentials secure so you don’t need to detect compromised creds. Traditional security measures are proving insufficient in terms of protecting consumer accounts from takeover and in reducing friction in consumer eCommerce. The Fraud Practice and myNetWatchman present this free white paper: There is no Silver Bullet: User Credentials are not Secured with 2FA Alone , which sheds light on the limitations of two-factor authentication (2FA) and emphasizes the necessity of adopting more risk aware, user-friendly security solutions. Two factor authentication is a useful tool, but it does nothing to protect the first factor of authentication: the password. This gives a level of success to credential stuffing attacks even when 2FA prevents account takeover (ATO) by validating to the attacker that the credentials used are still valid. Further, consumers don’t want 2FA on all “interactions” and 2FA is used sparingly by consumers outside of the workplace and for online or mobile banking, so it doesn’t make sense for most organizations. Stronger protection and risk mitigation at the first factor are needed, and it’s an area where most organizations stand to improve. In this free white paper, misconceptions and challenges around 2FA are discussed along with alternative ATO detection and mitigation strategies that put more emphasis on protecting the first factor of authentication. One of the areas discussed is leveraging services that detect compromised credentials and credential stuffing attacks which can enhance security while maintaining a seamless user experience for most users who present low risk. These insights help protect against unauthorized access and reduce the need for broad user-unfriendly authentication steps that cause more friction and incur a nominal fee. By adopting more nuanced, passive security measures, organizations can better protect their users without compromising on user experience. This approach not only fortifies defenses against ATO attacks but also ensures a smoother, less intrusive login process for consumers. Download the free white paper today.
- User Password Behavior can be Exploited by Criminals
End users are at the source of every login. Companies can, and do, create mechanisms to encourage people to manage their credentials – requiring lengthy passwords, or passwords with special characters or digits. But humans, comfortable with repetition, follow patterns that fraudsters can recreate when testing for valid credentials. Consumers reuse passwords, and bad actors capitalize on that It’s well known that consumers reuse passwords. Our analysis of criminal behavior shows that they know that as well. For example, the credential stuffing attack against Company M showed nearly 10% of the successful passwords were also used successfully by miscreants at other sites (get the full case study document here ). Consumers are also reluctant to change passwords. Less than half of Americans would update their password after knowing it was compromised in a data breach. You can read our in-depth report on credential and password reuse here . Consumers change passwords in predictable ways If your password policy requires it, consumers may take the time to create a strong password with numbers and special characters peppered throughout the character string. Or, they may simply append a digit or character like “!” to the end of their “default” password. More complicated passwords are more difficult to remember, and consumers may have strong passwords that they use across multiple sites. They may rely on one strong password that meets nearly all password policies and reuse that across several different logins. Attackers mimic common user password changes to test password variants This behavior is seen all across myNetWatchman data and across our live monitoring of credential stuffing activity, and we see this applied to both passwords and usernames. When a cred stuffer sees a username and password credential pair compromised in a data breach, and they see that the password is insecure (i.e. alpha characters only), they will absolutely use variations of this password when they attempt to use it in credential stuffing attacks. Bad actors performing credential stuffing attacks are often sophisticated. They use bots or scripts to automate their attacks, including the use of tumbling and swapping techniques, which refers to making slight variations in a username and/or password. A seasoned attacker will do some research to ensure they know the specifics of the password policies of the organizations they are targeting with a credential stuffing attack. They will then plan and attempt variations of the compromised password with capital letters (often the first character of the password), numeric characters and special characters (often added at the end). Here are just a few examples of what myNetWatchman sees when miscreants test passwords. Note the slight variations to the passwords. It’s unknown whether these variants were obtained through breach sets or were created by the bad actor. However, for each of these usernames, at least one of the password variations (in some cases more than one variation) was successful, allowing the bad actor access to the user’s account. Password variations for Username 1 Password variations for Username 2 Password variations for Username 3 Password variations for Username 4 Tit@s1127 Tit@s1128 Titas1126 titas1126 titas1127 Titas1127 Titas11278 Titas1128 titas1128 Carol2002 carol2002 carol2002! carol2002? Carol2002@ carol2002$ Carol2002$ Carol20021 Carol2002123 MIlc_aeroger1 MILcaeroger-912 MILcaeroger1 MIlcaeroger1 milcaeroger1 Milcaeroger1 MILcaeroger1! MILcaeroger123 Milcaeroger123 MILcaeroger345 MILcaeroger912! Patyn3ta patyn3ta Patyn3ta* patyneta Patyneta*17 Patyneta*1703 patyneta123 Patyneta123 Patyneta2511 patyneta2511 myNetWatchman has been observing criminal behavior for more than 20 years. We see the bad actors testing password variations - incrementing numbers, changing case, adding special characters. And the miscreants are having success with these passwords, because they aren’t completely random. They are variations created from known habits of people creating and changing passwords. AllCreds is myNetWatchman’s credential screening service that lets you check any credential, any time, to see if it has ever been used or tested by a criminal. Our proprietary data repository has over 30 billion compromised credential pairs and grows by 15 million new credential pairs daily.
- Anatomy of an FI Credential Stuffing Attack
Many types of organizations rely on myNetWatchman to help protect against credential stuffing and account takeover attacks, but user account security is especially important for financial institutions (FIs). In this article, we’ll explore a recent credential stuffing attack against a financial institution, where myNetWatchman observed this attack as part of our continuous, real-time monitoring. Bad actors tend to repeat their attacks and attack patterns against many FIs, and the intent of sharing this case study is to help others recognize and defend against similar patterns when they see a credential stuffing attack. The credential stuffing attack detailed here occurred between June and August 2024, targeting a large financial institution with many consumer accounts. Let’s discuss some of the details of this attack and why these techniques and patterns are so common. For readers less familiar with the basics of credential stuffing attacks, please read our previous Blog Post on Credential Stuffing . It’s a high-volume numbers game. Credential stuffing attacks systematically test credentials (email or username and password combinations) exposed via data breaches and phishing attacks to see where else the same credential pair may be used. Although it is expected that there will be a large percentage of failures, the idea is to identify the credentials that successfully provide access to the account to extract value from this more refined list. In this credential stuffing attack, myNetWatchman observed over eight million unique usernames attempted in a 6-week period. Attackers cater to their targets. The bad actors behind this attack took into account the fact that FIs, including this one being targeted, do not typically use email addresses as usernames. Nearly all of the more than eight million usernames attempted during this credential stuffing attack were non-email usernames. The cred stuffing success rate is lower for FIs compared to eCommerce retail. However, the damage or impact of account takeover is much greater for FIs than it is for eCommerce merchants. The success rate of this credential stuffing attack was 0.1 percent , or about eight thousand of the accounts tested. This FI supports two factor authentication (2FA), but was not presenting it for all logins. We are uncertain as to how many successful login attempts from the cred stuffing attack were presented or stopped by 2FA. However, even when 2FA stops the bad actors from gaining access to the account, they have confirmed that the credentials are valid. From that point they may use phishing techniques, SIM swaps or other techniques to gain control of the email address or phone number used for authenticating with 2FA. You are rarely the first target of a credential stuffing attack. Where AllCreds provides myNetWatchman clients deep value is in knowing that credentials being attempted against them are not only compromised, but have been seen in other credential stuffing attacks. As is typically the case, a majority of the successful (able to advance to be presented 2FA) credential pairs attempted against this FI were seen previously. Nearly nine-in-ten, or 86 percent , of successful credentials used in the cred stuffing attack were previously observed by myNetWatchman. You often aren’t the first target in your industry either. More than one-quarter, 26 percent , of the valid credentials used in this credential stuffing attack were previously observed by myNetWatchman as being used against other FIs. We know that consumers have a tendency to reuse passwords. Thankfully, many realize that they should use a more secure password for access to online banking than they do other online accounts. It may be that many consumers reuse the same password across multiple online banking logins and fraudsters are exploiting this fact by testing these compromised credential pairs across multiple FIs. Or it may be that the bad actors mine their compromised credential data set for non-email usernames and strong passwords, as these are more likely to be used for online banking. They don’t know what FIs the account holders bank with, so they target many with credential stuffing attacks. It’s not a matter of if, but when. FIs will see credential stuffing attacks because the ability to take over online banking accounts is valuable to fraudsters. 2FA may prevent account takeover, but the successful credential stuffing attack is valuable to the attackers who may later target that account holder with phishing or other schemes to try and beat or circumvent 2FA. FIs need to be aware when credential stuffing attacks are occurring and know what online banking consumer accounts are using compromised credentials. myNetWatchman offers unique visibility into credential stuffing attacks, specifically as it relates to FIs. It is extremely valuable to know not only that the presented credentials are compromised, but that they are actively being tested. It is even more valuable to know that these credentials are actively being tested against other FIs. myNetWatchman provides this visibility which offers high-quality and meaningful risk signals, all built on our continuously growing data repository containing over 30 billion exposed credential pairs that protects over 550 million users for our clients.
- myNetWatchman Cybersecurity Glossary
Whether you’re a professional, a business owner, or an end user, here are common cybersecurity terms you should know. 2FA Two-factor authentication. An authentication process in which the user who is authenticating needs to provide more than one type of evidence (factor) to verify their identity. For example, after entering a username and password (one factor), they are prompted to provide a code (second factor) received via email or text message. A two-step MFA. Account Online profile associated with a username that allows a user to conduct transactions and a service provider (e.g., a streaming service or online retailer) to manage your experience. For example, you may have an online bank account, an account at a retailer like Amazon, an account at a streaming provider like Netflix, and so on. Actor, bad actor, criminal actor The person or entity doing an action or activity. In computing, “actor” is used because it can represent an unknown person (a criminal actor), an organization, or a computer process. In cybersecurity, often used interchangeably with miscreant, criminal, fraudster. More...
- myNetWatchman Releases Study on Credential and Password Reuse
Consumers are frequently reusing passwords & credentials according to a myNetWatchman review of criminal breach activity. myNetWatchman data shows that criminals successfully used 68 million credentials (usernames & passwords) to access consumer accounts. Consumers re-used those credentials for multiple accounts, and more than 8 million were found by criminals to be valid (successful) at more than one site. Others report that 23 percent of all logins are ATO attempts while more than half of consumers reuse at least one password and the average direct financial cost of ATO to an organization is nearly $300 per account. The widespread availability of consumer credentials from data breaches combined with consumers’ tendency to reuse passwords across multiple sites and logins leaves organizations exposed to credential stuffing attacks. myNetWatchman’s Credential and Password Reuse study leverages insights from our proprietary data that captures fraudster use of over 15 million new credentials per day, combined with public data sources and findings related to account takeover (ATO) and password reuse. Just as a bad actor will test compromised payment card numbers to see which are active then use those cards to make fraudulent purchases, a bad actor will use a botnet to test a trove of username and password combinations across many sites to see where the same credential pair is also used. While we know that passwords are inherently insecure, organizations must be careful about the level of friction presented at the login event, considering how and when step-up authentication is required for account access. Like fraud prevention at the transaction event, this must strike a balance between risk mitigation and user experience, relying on risk signals to determine when more friction is warranted. Credential stuffing is the path of least resistance for ATO attacks, and simply put, ATO events are damaging and expensive. myNetWatchman’s study on Credential and Password Reuse discusses the data and trends around credential stuffing, how to detect these attacks and considerations around balancing ATO protection and user experience. Download this free white paper to learn more.
- myNetWatchman’s AllCreds and Active Directory Audit Helps Organizations Prevent Use of Stolen Credentials Like Those Targeting Snowflake Accounts
In June, cloud services provider Snowflake along with Mandiant, a cyber security firm, notified at least 165 Snowflake clients about potential account compromises. Data breaches at Santander Bank, Ticketmaster and QuoteWizard were linked to the Snowflake cloud storage and analytics accounts these organizations hold, as reported by Wired and Verge . Bad actors used employee credential stuffing to attack companies using Snowflake to steal their company’s customer data. Snowflake has numerous clients and holds a large amount of PII data for those clients. Snowflake clients were likely not even aware these attacks were occurring. And Snowflake is only one of many third party providers in this space. It’s becoming more common for companies to use third parties like Snowflake to hold sensitive data and increases the need to expand your visibility into where you may be vulnerable for account takeover. Mandiant traced the issue to a hacker group leveraging stolen credentials, some going as far back as 2020, from infostealer malware. While this cyber attack has primarily been referred to as the Snowflake data breach in the media, it would be more accurately described as a credential stuffing attack targeting companies using Snowflake, using credential pairs compromised by malware. This is typical of credential stuffing attacks. Our web monitoring services alerts our clients to their exposure from over 50 million credential stuffing attacks a day, across thousands of companies with over 50 attacks each day impacting 1m or more accounts. Bad actors capitalize on poor password hygiene and frequent credential password reuse among users, using systematic credential stuffing attacks to test passwords compromised by malware or a third-party data breach across other systems where these compromised credential pairs may also be used. Business user accounts get compromised, just like consumer accounts, and many of these account holders reuse their passwords if not full credential pairs. Organizations need to ensure their employees, vendors and contractors are not using compromised credentials, as they can be used to access business services (as in the case of credential stuffing targeting Snowflake accounts) and sensitive data. AllCreds is myNetWatchman’s compromised credential screening service. This service can be applied at account creation, but in the wake of attacks like those targeting Snowflake accounts, it should be used to identify compromised credentials in an organization’s Active Directory. We call this AD Audit. AllCreds screens the credentials of all users and identifies which are known to be compromised. Those flagged as compromised should then be required to change their passwords, preventing account takeover via use of the stolen credentials, similar to what Ticketmaster and others experienced with their Snowflake accounts. myNetWatchman is trusted by top firms around the world to help detect, prevent and recover from compromised credentials. It doesn’t matter how they were compromised or that the password is used across multiple accounts or services for a given user – when compromised credential pairs are presented, it is up to the organization seeing the credential stuffing attack or account takeover (ATO) attempt to stop unauthorized account access. Here’s how we help: myNetWatchman’s credential web monitoring service : Benefit from myNetWatchman’s ten-plus years of live data surveillance, proprietary and constantly growing data set of over 30 billion exposed credential pairs and network of 550 million protected users. Leveraging live surveillance, myNetWatchman alerts clients of bad actors’ activity targeting your company or domains, including where your clients log-in or access your services. Know whether it’s an isolated credential stuffing or ATO attack targeting one client’s account login page, or a widespread attack targeting many clients across the various URLs and pages where they authenticate to access your services. AllCreds is myNetWatchman’s compromised credential screening service . Risk and reputation scoring is provided on specific users (customers or employees) based on whether we see their credential pairs implicated in data breaches or successfully used by bad actors on other sites. Companies use these insights to strategically present forms of step-up authentication or to require password resets. Chances are that compromised credential pairs will be used or tested elsewhere before they are attempted against your users or site. myNetWatchman brings this information to light so you can act accordingly. Not just compromised passwords, but credentials pairs. Not just credentials that have been breached, but ones that are actively being used. About myNetWatchman – Georgia based myNetWatchman has been providing cyber fraud intelligence data for more than 20 years to retailers, financial services, insurance, and other industries. With over 10 years of live data surveillance, the company manages a continuously growing data repository containing over 30 billion exposed credential pairs and protects over 550 million users for their clients.
- PrincipleLogic finds mNW's Active Directory Audit revealing and enlightening
Kevin Beaver, Cybersecurity Consultant at PrincipleLogic, recently added myNetWatchman’s Active Directory Audit tool from our Compromised Credential Screening solution to his vulnerability and penetration testing toolset, and he says it " can pay huge dividends ." The Active Directory audit tool helps clients, consultants and security professionals review employee accounts on Active Directory to identify any that have compromised credentials (username and password). Fast and easy to use, the tool helps companies speed up the detection of compromised credentials to prevent account takeover risk and attacks that could lead to data loss or infection with malware like ransomware. Check out his post Find at-risk internal user accounts with myNetWatchman’s Active Directory Audit tool for the full story on how he used it to find holes in his customers' password security. He found Active Directory Audit " both revealing and enlightening " - you can too.
- Using AllCreds to Successfully prevent Account Takeover from Compromised Credentials, a myNetWatchman Client Case Study
myNetWatchman analyzed the 48 million credentials and 533,000 successful account takeovers from a large-scale credential stuffing attack against our repository of over 30 billion compromised credential pairs. This analysis was performed after-the-fact, but had myNetWatchman’s AllCreds service been applied proactively, 91 percent of the account takeovers could have been stopped, as they used credential pairs we had previously identified as compromised. In this comprehensive case study, myNetWatchman analyzed data from a client credential stuffing attack that spanned four months using nearly 48 million compromised credential pairs. This large-scale attack took place in early 2024 against an omni-channel retailer with a large, global online sales presence, referred to as “Company M.” Company M faced a threat many online organizations see frequently: credential stuffing attacks. Many consumers have poor password hygiene, reusing passwords or credential pairs and making it easier for criminal actors to find success with account takeover attacks through credential stuffing. Credential stuffing involves systematically testing lists of compromised credential pairs, which are abundant as data breaches occur frequently and are often large. The credential stuffing attack against Company M exemplified the severity of poor consumer password hygiene. Out of tens of millions of unique credential pairs tested, over half a million customer accounts were able to be successfully accessed — a 1.13 percent success rate. The overall success rate, including repeated attempts, was 1.7 percent. myNetWatchman’s analysis of the compromised credentials used against Company M found that more than nine-tenths of the successful logins involved credential pairs that were previously tested on other sites. Leveraging myNetWatchman’s live data surveillance and proprietary data repository of over 30 billion exposed credentials, our analysis showed that the compromised credentials presented at Company M’s site had been used or tested across thousands of other websites first. Using AllCreds as a preventive tool at login and password change to force customer step-up authentication and to change their passwords when they become compromised would have prevented 91% of the bad actors successful logins. With AllCreds , organizations can fight poor password hygiene and credential stuffing attacks by knowing not only if the presented credentials are compromised, but if they are actively being tested. This allows for strategic use of step-up authentication, such as two-factor authentication (2FA) or requiring a password change, while maintaining a seamless user experience for legitimate users.
- Understanding the RockYou2024 Data Dump: Implications and Realities
myNetWatchman clients (and most others) don’t need to be concerned about RockYou2024 - don’t be put off by the size. The RockYou2024 data set, with its staggering 10 billion records freely available online, has caused quite a stir in the cybersecurity world. We took a look beyond the headlines to understand what this data dump truly represents and its actual impact. While the primary focus on 10 billion records overstates the breadth of what is actually useful, the 65 percent (at least) of the data set that is likely to be real, unencrypted passwords might be useful to a small group of fraudsters. Even then, the reality is that the compromised passwords contained in it were being used well before it was released. What is it RockYou2024 is a data dump, freely available online. It is a mix of plain-text passwords, hashed passwords, plausible (but not necessarily in-use) passwords from wordlists and likely some junk data. The name "RockYou" dates back to 2009 when a file named “rockyou.txt” containing 14 million unique passwords was posted online. The list grew over the years, reaching 8.4 billion records by 2021. The latest iteration, RockYou2024, added 1.5 billion new records, approaching the headline-grabbing number of 10 billion. What’s inside RockYou2024 has only passwords, or more accurately, records that might be passwords. These are not credential pairs - credential pairs (username and password together) are more valuable than passwords alone. In contrast, we have over 30 billion pairs in our repository. Encrypted data - About 950 million records, about 10% of the data set, is encrypted words; little value to attackers, because cracking the hashed word (moreso a hashed and salted word) is technically challenging and time-consuming. Junk - random strings, company names, and other garbage that aren’t really passwords people use. For example, we found more than 50 thousand records starting with “0x00” and agree with Red Hot Cyber that junk data was included because the hacker probably “wanted to reach 10 billion records at all costs just for fame or attention.” What’s left is about 6.14 billion records that could be plain-text passwords. Real-world use We monitor live criminal traffic, as it happens. In the week after RockYou2024 was released, we saw 370 million credential pairs used in illegitimate logins, credential stuffing attacks, and ATO attempts. 56% of those used passwords in the RockYou2024 data set. However, in the week before RockYou2024 came out, we also saw the same amount - 56% - of logins using passwords in RockYou2024. In other words, we didn’t see any indication that RockYou2024 exposed a significant amount of passwords that hadn’t been used before. Threat Level For our clients, we don’t see this breach increasing the level of existing threat to account takeover from compromised credentials. The attributes – potential, unverified passwords are low value compared to breaches that contain username and password combinations, for example the 30+ billion credential pairs we have that criminals have actually used. We do expect some criminals will use them in brute-force stuffing attacks, but that kind of activity has a significantly lower success rate than credential stuffing attacks which rely on compromised credential pairs. And the timing risk is low - 84% of the set was available three years ago or more. Wide availability of breached passwords and poor password hygiene makes ATO and credential stuffing attacks a persistent and credible threat, but RockYou2024 didn’t greatly elevate that threat, it was already quite high. Recommendations As always, we recommend our clients help users practice good password hygiene. Have password policies in place to require strong passwords, use 2FA where it makes sense for the user experience, and protect users from using known compromised accounts with our services . We DO NOT recommend you let the hype around RockYou2024 alarm you into drastic action. Forcing all users implicated in RockYou2024 to change passwords would cause unnecessary friction without significantly reducing risk.
- Naz.API and Making the Case for using Compromised Credential Monitoring
In a study of the Naz.API breach data myNetWatchman found that Companies using their compromised credential screening service were able to detect 94% of these compromised credentials earlier, in some cases years earlier, using myNetWatchman versus making use of the breach data when it became public. When news broke about the 71 million user accounts that were compromised in the Naz.API data breach in September 2023 it provided a great comparative example between using vendors that make use of static data breach data once its public versus vendors that rely on real time credential monitoring, like myNetWatchman, for detection of compromised or at risk credentials (username and password). In the case of Naz.API the data set consisted of aggregated breach data from multiple breaches, so some would have been public in the past and some were likely not known. From the data we can see a large cluster from years in the past likely indicating they were pulled from a much older breach. if a company was relying on a vendor that uses static data breach data, the complete list of compromised credentials would not have been known before September 2023 as that was when it was discovered, and likely would not be available for several months after as attribution and legal processing for getting access to this data takes time. In contrast if a company was using myNetWatchman, a real time credential monitoring vendor, they would have had a higher likelihood of detecting it earlier as 94% of these compromised credentials were known to be compromised before the breach became public. Beyond the indication that the credentials were compromised, using myNetWatchman’s real time credential monitoring service would have also alerted on 5% of these creds that there was a successful access into an account by a bad actor.
- Krebs on Security: Who’s Behind the SWAT USA Reshipping Service?
Our team at myNetWatchman is thrilled to be referenced in the latest article by KrebsOnSecurity: Who's Behind the SWAT USA Reshipping Service? , exposing the identities of the SWAT USA Reshipping Service. The premise of the article provides further confirmation that criminals follow the same behavior as everyone else reusing passwords from their personal lives. Following these tips of best practices can help you keep you and your organization secure: Keep work and personal email separate Do not include personal data (such as date of birth) in passwords Do not reuse passwords across platforms. We're proud to stand at the forefront of this fight, providing tools and strategies that keep our clients one step ahead of cyber threats. A huge thanks to KrebsOnSecurity for the recognition and for keeping the digital community informed and engaged.









