top of page
ON-DEMAND
WEBINAR

Breach Data Is Dead Data! Stop ATO with Live Data

59 results found with an empty search

  • Email Hygiene: A Hidden Lever in Reducing Fake Accounts & Improving Business Metrics

    Every executive decision relies on trustworthy numbers. Metrics like CAC (Customer Acquisition Cost), CLTV (Customer Lifetime Value), churn, and growth are only as accurate as the data behind them. When fake, synthetic, or compromised email addresses start clogging up your customer account lists, they distort these critical measurements, inflating acquisition costs, diluting lifetime value, and creating churn that doesn’t reflect real customer behavior. By eliminating fake, compromised, and other high-risk accounts, companies get a clearer picture of their true customer base and a more reliable financial view of their business. This isn’t just a fraud problem, it’s a cross-functional issue that affects how Marketing measures campaign ROI, how Sales forecasts pipeline growth, and how Finance evaluates capital efficiency. One of the most effective and under-leveraged processes to achieve cleaner data is email account hygiene. This approach evaluates the trustworthiness of an email address at account creation, login, or during ongoing use, helping to detect synthetic identities, compromised accounts, disposable emails, and addresses linked to recent criminal activity. Filtering these out early protects your business and ensures that your growth, retention, and revenue metrics reflect reality rather than noise. Impact on Business Metrics Fraud Vector Signal from Email Reputation Impact on Business Metrics Disposable / temporary email addresses Poor domain reputation, short lifetimes, high churn Marketing : Campaign performance looks inflated but doesn’t convert. Finance:  CAC rises as acquisition spend is wasted Compromised / breached credentials Appear in breach dumps or infostealer logs Fraud:  Direct ATO losses. Sales:  Inflated LTV that disappears with churn. Finance:  Missed revenue forecasts due to account attrition Synthetic / fake accounts Detected via email age, domain reputation, behavioral signals Sales:  Inflated pipeline and false “user growth”. Marketing:  Campaign ROI reporting skewed. Finance: Overstated revenue potential in models Observed criminal / fraud activity Known fraud rings, chargebacks, spam networks Operations:  Reduced manual review and chargeback costs. Customer Experience:  Trust and retention improve. Finance:  More predictable fraud loss reserves. The Bigger Picture Behind the Numbers The data paints a sobering picture: synthetic and fake accounts aren’t just a nuisance, they are warping the very financial metrics executives rely on to make decisions . TransUnion reports that more than half of financial institutions now see synthetic identities as their top fraud concern. At the same time, the tactics behind these accounts are evolving, with 40% of institutions observing increased fraud attempts tied to generative AI, and nearly a third already facing deepfake-driven synthetic identities. These aren’t fringe issues; they’re mainstream risks undermining the quality of customer data. It’s not just financial services feeling the impact. Ping Identity highlights a 32% growth in fraudulent new bank accounts in a single year, and a staggering 183% spike in synthetic fraud attempts in retail over a three-year period. These accounts don’t only drain fraud budgets, they inflate Marketing’s lead counts, Sales’ user growth numbers, and Finance’s forecasts. Executives making calls on CAC, LTV, or churn are often doing so with corrupted data sets. Email Reputation from myNetWatchman Exposes Compromised, Fake Email Accounts Email Reputation doesn't just reduce fraud losses; it restores trust in the numbers themselves . By filtering out the noise of fake, synthetic and compromised accounts, companies can ensure their financial reporting is grounded in reality. And for business managers, that clarity isn’t a nice-to-have, it’s essential for allocating capital, planning growth, and proving ROI across the organization. For Marketing : Better segmentation, cleaner campaign attribution, higher conversion rates For Sales : Real pipeline, not padded by synthetic users For Finance : Capital efficiency ratios (CAC, payback, LTV/CAC) calculated on real customer, not fake ones Email Reputation is a simple API that helps companies determine if an email address is trustworthy, fake, synthetic, deliverable, or actively compromised. Businesses use Email Reputation during new account setup, login, and password reset to reduce authentication costs, enhance security, and prevent fraud. The real impact goes beyond fraud to ensure the metrics driving strategy and valuation actually reflect reality. For more information on Email Reputation by myNetWatchman, click here .

  • Sleeper Accounts Are Waking Up, Right on Cue for iPhone 17 Pre-Orders & Holidays

    Apple just opened iPhone 17 pre-orders (stores launch September 19), and history has shown that fraudsters treat new-phone hype and holiday volume as their favorite cover. Sleeper Accounts Are Set for Attack One common tactic used by fraud groups is to set up accounts well in advance of an attack. These accounts, sometimes called "sleeper" or "dormant" accounts, are used to hit companies at scale and avoid the scrutiny of guest checkouts. Experian describes this as new or hijacked accounts that behave normally until a rapid cash-out. Fraudsters typically create new accounts using synthetic identities or compromise existing accounts. In some cases, fraudsters have pre-positioned tens of thousands of accounts for the holidays alone. When you add in the hype of a new iPhone, the stage is set for a season of attacks. After weeks or months of lying low, these accounts are then activated by criminals to purchase upgrades, device financing, add-a-line promotions, or execute SIM swaps and port-outs. Why this matters for mobile carriers: the new-account step is already the riskiest stage in digital onboarding; of which the Communications Fraud Control Association (CFCA) reports 1 in 9 telecom applications are believed to be fraudulent and that subscription/application fraud dominates telco fraud cases. Once a sleeper slips through, detection gets harder because the identity has “aged” and looks trustworthy. What the numbers say (and don’t) The telecom industry’s fraud pain is well documented even if “sleeper accounts” aren’t broken out as a standalone line item. The CFCA estimates $38.95B in telecom fraud losses in 2023 (about 2.5% of global telecom revenue). Subscription/application and handset-related schemes are repeatedly cited among the top drivers, exactly the channels sleepers exploit when high-demand devices land. Bottom line: sleeper accounts deserve carrier attention, especially during iPhone launches and the seasonal spike in orders. How sleepers behave Age the account: Clear KYC/IDV, low-risk behavior, on-time micro-payments to build trust/limits. Change-then-spike : Recent contact or address changes, then a sudden upgrade/financing basket, add-a-line, or number port. Cross-linking tells : Shared delivery addresses, devices, IPs/subnets, or emails across “unrelated” accounts, hallmarks of organized crime rings. All patterns consistent with dormant/ATO and subscription-fraud lifecycles. myNetWatchman spots synthetic and compromised accounts before they can monetize How quickly can you spot a compromised or synthetic/fake account? At myNetWatchman, we identify "sleeper" accounts in real-time giving you the earliest possible heads-up to fraud. We're constantly sifting through attack traffic and monitoring criminal activity as it happens. This means you get the best detection and remediation for hijacked accounts, right when it matters most. Here's how we do it: Our Email Reputation service is a low cost and easy-to-use API companies use to determine if an email address really works, was created-for-fraud (its fake), or if criminals have compromised the email account and are actively using it. Stop Fraud Before it Starts : Check the validity of an email account, anytime. Companies use Email Reputation to enhance user experience and optimize costs to authenticate and verify users as part of KYC, security, and fraud prevention. At account opening At login with 2FA/MFA During password reset User verification before large transaction Not Just Customer Accounts : Since fraud can come at you from several directions, Email Reputation is applicable for all users with emails, customers, employees, vendors, partners, suppliers, consultants and contractors. We're always gathering data, from live sources to the darknet. Then, our own intelligence and analysis kick in, pulling out the most relevant details—raw data, comparisons, velocities, and key features. All this incredibly accurate and actionable data is deployed in real-time, ensuring a smooth and secure experience for you. Want to learn more? Check us out at myNetWatchman.com. Sources : CFCA global telecom fraud loss estimate (2023); TransUnion State of Omnichannel Fraud (new-account fraud rate); Experian on dormant/sleeper fraud; TransUnion on rising SIM-swap/port-out & Javelin ATO losses.

  • The Real Economics of Credential Stuffing: Low Success, High Impact

    (Excerpts from the recently published Special Report, “ The Economics of Credential Stuffing Attacks and Account Takeover Fraud ” by myNetWatchman) Credential stuffing has endured because it’s ruthlessly economical. Attackers take username/password pairs harvested from one breach, or several combined, and automate login attempts across thousands of sites. Even when only a tiny fraction succeed, think 0.00018% to 0.025% , the sheer scale turns pennies into profits and headaches into real losses for businesses (see report pages 1 and 5 ). The problem persists because consumers, employees, and vendors reuse passwords and criminals can cheaply rent botnets, proxies, and tools that mimic human behavior. The math favors the adversary. As the report details, a large-scale campaign can cost around $300 for the total package of credential lists, residential proxies, 2FA-bypass kits, and automation software ( page 4 ). Break-even can happen at ~0.006% success if each compromised account yields just $50 and many accounts are worth far more. At volume, the numbers get staggering: one streaming service saw 773 million credential tests/attacks in a year, producing nearly 2 million successful logins at a 0.0025% hit rate; even a “low” success rate becomes material at internet scale ( page 5 ). For organizations, the economics cut the other way. There are direct fraud losses , investigation and remediation costs, and reputational harm. The report cites $13B lost to ATO fraud in 2023 and an average of $4.81M per credential-stuffing attack (pages 4–5 ). Operationally, bots can clog login flows, ~16.5% of login-page traffic is linked to stuffing, driving latency, downtime, and support load ( page 5 ). Compliance risk compounds the pain: PCI DSS, GDPR, and CCPA enforcement can stack on fines and legal exposure ( page 7 ). The threat is evolving, too. AI-powered bots and headless browser automation help attackers solve CAPTCHAs, navigate complex flows, and adapt to defenses ( page 6 ). That means static controls won’t keep up. What does work is shifting the economics back in your favor. The report recommends a multi-layered defense : credential screening to spot exposed or actively abused credentials, MFA, aggressive rate limiting, device fingerprinting, behavioral biometrics, cooling-off periods for high-risk actions, and zero-trust checks for sensitive steps ( pages 8–9 ). Real-world outcomes are compelling. One international ISP drove ATOs down from 3,000/day to 4/day , and the sidebar on page 9 also highlights a 91% detection rate of compromised credentials observed in a multi-channel retailer slashing ATO successes from 532,000 to under 49,000 after implementing myNetWatchman’s AllCreds screening. If losses from credential stuffing feel inevitable, this report shows it isn’t. You can upend the attacker ROI with layered controls and proactive credential screening at account creation, reset, and login. Want to view the full report? Download here for all the details.

  • Is Your Business a Target for Credential Stuffing?

    Credential stuffing is a serious cyberattack because it’s cheap, easy to scale, and takes advantage of the common problem of people reusing passwords. Even though only a tiny fraction of these attacks succeed (0.00018% to 0.25%), the sheer number of attempts means big profits for criminals and big costs for organizations. The financial gains for attackers, combined with how these attacks work, highlight the urgent need for strong defenses. Our latest report, "The Economics of Credential Stuffing Attacks and Account Takeover Fraud," breaks down why these attacks are so effective and what they cost both criminals and organizations. Inside, you'll learn about: The Low-Risk, High-Reward Business Model : A large-scale attack can cost as little as $300, while a single successful login can lead to hundreds or even thousands of dollars in fraud. The Alarming Cost to Businesses : From direct financial losses and operational expenses to severe reputational damage, the costs for organizations can be millions of dollars per breach. AI's Growing Role : Discover how AI-powered bots and generative AI are making these attacks more sophisticated and harder to detect. Essential Defensive Strategies : We outline the multi-layered approach organizations must take to protect themselves, including implementing Multi-Factor Authentication (MFA), behavioral biometrics, and our own AllCreds Compromised Credential Screening solution. Don't wait until your organization becomes the next victim. Download our report today to get a clear understanding of the threat and how to protect your customers and your business.

  • Mind the Gap in Your Verification Analysis

    Bridging the Divide Between Breach Data and Actionable Intelligence It has been a year since the massive AT&T data breach shook the digital landscape, an incident affecting 73 million current and former customers stretching back to 2019. While the $177 million settlement and the offer of complimentary credit monitoring may signal closure for AT&T, for the individuals affected and every other business online, this event could be only the beginning. Once customer data enters the dark web, its impact reverberates for years. This data is bought, sold, and repurposed time and again in countless fraud schemes. Breach data is a point in time, static indicator of what a user’s credentials were on a site. As time passes it becomes less and less accurate as users could have closed their account or changed their password. This leads to lots of false positives when relied on to detect compromised accounts. In fact, industry estimates suggest that business losses from false positives reach an astonishing $300–$400 billion each year. While breach data informs risk assessment systems during credential verification, it cannot stand alone as the ultimate arbiter of trustworthiness. It requires supplementary evidence to provide a holistic determination. Informative, yes, but rarely actionable by itself. By contrast, integrating live data, information that demonstrates not only past compromise but that a fraudster is actively and or successfully using the credentials, transforms risk assessment, essentially bridging the gap from suggestive to actionable. Live data is rooted in real evidence, tracking accounts actively exploited by bad actors, and remarkably, it delivers zero false positives in relation to “we know the bad actor is using your data”. The difference may seem nuanced, but this gap can make a big difference in how businesses respond to perceived risk. With over 12,000 data breaches reported last year alone, nearly everyone has faced exposure over the past decade, often more than once. If every breached account were classified by businesses as high risk, the result would be universal step-up authentication, an expensive, tedious, and frequently insulting process for customers. A smarter approach combines breach data with live actionable intelligence, painting a clearer, more precise picture of the risk tied to each account, be it customer, employee, or vendor. This enables organizations to make judicious decisions about who merits additional verification or deserves to be declined outright. That’s why at myNetWatchman, we built our credential screening service to collect and combine breach data with actionable live data from multiple sources. Prioritizing the use of live data can help bridge the gap between mere information and genuine security. How Can myNetWatchman Help? For more than a decade, myNetWatchman has been at the forefront of live data tracking, empowering organizations to anticipate and mitigate bad actor activity. With a dataset exceeding 38 billion credential pairs, growing by 15 million new entries daily, and available within seconds of detection, myNetWatchman offers unparalleled clarity into the risks associated with every user account.

  • The Rising Threat of Business Email Compromise

    Cybercrime is evolving faster than ever, and Business Email Compromise (BEC) stands out as one of the most insidious threats. Unlike flashy malware attacks, BEC is a subtle, social engineering scam where fraudsters impersonate trusted figures like CEOs, vendors, or partners to trick employees into wiring funds, sharing data, or authorizing bogus transactions. The result? Massive financial losses, data breaches, and shattered reputations. According to the FBI's Internet Crime Complaint Center (IC3), BEC scams racked up a staggering $2.9 billion in losses in 2023 alone, with an average hit of $137,000 per incident. Fast-forward to 2024, and BEC accounted for 73% of all reported cyber incidents, with losses soaring past $55 billion over the decade. What's more alarming? A 13% spike in attacks in early 2025, fueled by AI-generated emails that are now 40% of BEC phishing attempts—making them eerily polished and undetectable. In addition, nearly 40% of ransomware attacks begin with a compromised email. These attacks exploit poor habits like credential reuse across personal and work accounts. Real-world examples paint a grim picture. In 2023, Children's Healthcare of Atlanta lost $3.6 million to fake invoices from a spoofed CFO. The School District of Philadelphia saw $700,000 diverted in a vendor impersonation scheme in 2024. Even charities aren't safe: Treasure Island in San Francisco was fleeced of $625,000 in a month-long BEC ploy. These aren't isolated incidents—they highlight how BEC preys on trust and rushed decisions, turning everyday emails into financial nightmares. Don't let BEC blindside your organization. Dive into myNetWatchman's special report, "The Rising Threat of Business Email Compromise (BEC) Fraud" for in-depth insights, more case studies, and actionable strategies.

  • Evolving Landscape of Cyber Threats Necessitates Advanced Risk Assessment for Cyber Insurers

    Cyber insurance is a critical tool for businesses to mitigate financial losses from cyberattacks. However, insurers' traditional approach of using questionnaires to assess cyber risk is inadequate in today’s rapidly evolving threat landscape. Unless insurance companies stop relying primarily on questionnaires for risk assessment, they will continue to experience increased financial losses due to cyber fraud and crime. Questionnaires have long been a staple for insurers to evaluate a company’s cybersecurity posture. They typically ask about basic security measures, such as whether a company uses firewalls, antivirus software, or Multi-Factor Authentication (MFA). However, these static, self-reported assessments fail to capture the dynamic and sophisticated nature of modern cyber identity threats. Avoiding real world catastrophes like 23&Me and Marks & Spencers requires insurers to update risk assessments protocols to meet the ever-evolving threat today’s criminals present. This new Special Report outlines what is needed to protect Cyber Insurance Carriers and reduce losses for both insurers and policy holders.

  • Webinar Recording – Using Live Data to Stop ATO

    According to the 2025 Verizon Data Breach Incident Report, credential abuse (i.e., credential stuffing, account takeover attacks, etc.) is the leading initial attack vector and is up over 22%. Credential screening – evaluating credentials for potential compromise at various points, including login, signup, and account reset – is a best practice for enhancing security measures to fight these types of attacks. Many organizations use breach data to screen against compromised credentials. However, using breach data alone for credential screening can result in higher false positives rates, poor user experiences, and increased fraud remediation costs. Why? Here’s a breakdown of breach data compared to live data. Breach Data Live Data Can be months or even years old – Data breaches are not always known right away nor is the data available immediately. This means the data accessed by criminals could have been in use for weeks, months, or years before it is available for credential screening. Provides recent activity – Data gathered through live channels is actively being used by criminals and can be used for credential screening immediately, demonstrating a clear threat in real time. Known to criminals & corporations – Data from breaches is known to both criminals and corporations which diminishes the effectiveness of credential screening. Known only to mNW – Live data is known only to myNetWatchman which makes it more accurate and more actionable when conducting credential screening. 100% of the live data presented by myNetWatchman is criminal activity and shows a higher risk of account compromise. Everyone’s data has been breached – With more than 12,000 data breaches in 2024 alone, it is a safe bet that everyone’s data has been breached in the past few years and is available on the dark web. So, credential screening with breach data alone can be lacking in actionable information and in determining where the highest risk is. Not everyone’s data is being used – Knowing whose data is actively being tested and used by criminals is far more predictive of risk and account compromise. Credential screening with live data results in zero false positives and a better customer experience. Comes in batches – Breach data generally comes in batches and needs to be constantly updated to get the latest data available. Seen in real-time – Live data is delivered in real time via an API with the most recent activity on over 38 billion credential pairs highlighting risk immediately. No updating necessary. Doesn’t require monitoring – Breach data is not real time, so monitoring is not a factor. Monitoring for compromised credentials – myNetWatchman constantly monitors for criminal activity to ensure the latest data is available and delivered in real time. mNW improves breach data by adding “live data”, enhancing detection of compromised credentials linked to criminal activity. This helps companies prevent account takeovers and other fraud events. The difference between using typical breach data and live data for your credential screening can make a significant difference. In this webinar we reviewed The problems of using breach data alone What does “live data” add to enhance fraud detection? Two case studies highlighting the increased levels of accuracy for preventing ATO Audience Q&A Presenters: David Montague David is the CEO of myNetWatchman and an experienced risk and security executive and GM with highly specialized skills in eCommerce, fintech, payments, fraud, risk and security. For more than 20 years, David has applied his skills in executive positions at leading technology companies like Amazon, Expedia, IBM and consulting firms like The Fraud Practice, Inc. A true technology leader, David blends business acumen, empathy and technical expertise to solve the toughest challenges facing enterprises today. Jen Baldwin Jen is the COO at myNetWatchman and a seasoned technology professional with a passion for fighting fraud. Experienced in management, data analysis, and investigations in cyber and identity fraud, specialty retail loss prevention, contract fraud, litigation support, and due diligence projects. Jen’s time at Cars.com and CareerBuilder managing Fraud Prevention and Site Security respectively give her an insider's view of what really happens when criminals target your organization. Watch the webinar by clicking here .

  • Big Mac, Fries, and 64 million Records To Go Please

    Seriously, McDonald's? A Wake-Up Call for Enterprise Security Leaders. To all CISOs, cybersecurity managers, and fraud prevention experts out there, pull up a chair. We need to talk about something both utterly shocking and yet unbelievably common. It's about a recent data breach that affected a global powerhouse, a multi-billion dollar corporation, through a vulnerability so basic, it's almost a cartoon villain's password: " 123456 ." Yes, you read that right. The Golden Arches' Glaring Security Gap Remember that news about McDonald's and its 64 million job applicants? The one where their personal information was exposed? This wasn't some sophisticated nation-state attack or a zero-day exploit requiring an army of highly specialized threat actors. This was, quite frankly, a facepalm moment brought to you by a third-party AI system, Paradox.ai, which provides the McHire platform for screening candidates. …they tried common credentials, including "123456" for both username and password, and it worked. This simple password granted them administrator access to a test McDonald’s restaurant on McHire, without multi-factor authentication. Security researchers Ian Carroll and Sam Curry uncovered this gaping hole. While initially looking for prompt injection vulnerabilities in the AI chatbot, Olivia, they stumbled upon a login link for Paradox.ai staff. What happened next is almost unbelievable for a company of McDonald's' stature: they tried common credentials, including "123456" for both username and password , and it worked . This simple password granted them administrator access to a test McDonald’s restaurant on McHire, without multi-factor authentication. The compromised account, a test account, was the obvious weakness in the first layer of defense and had not even been logged into since 2019 and "should have been decommissioned." And with that oversight they had access to "virtually every application that's ever been made to McDonald’s going back years." This single, neglected, and woefully insecure credential exposed names, email addresses, phone numbers, and IP addresses of 64 million job applicants. Beyond the initial access, the researchers found they could also manipulate applicant ID numbers to view other candidates' chat logs and contact information. The implications? Massive phishing risks and potential payroll scams, as applicants are eager and waiting for communication from McDonald's. McDonald's was, understandably, "disappointed by this unacceptable vulnerability from a third-party provider", but the truth is, this highlights a fundamental, yet often overlooked, vulnerability in today's interconnected digital landscape. Whether a first line of defense or the last, credentials like passwords should be secure at least as far as not being easily guessed, should not be a known-breached credential pair, and at best should be screened for recent criminal activity. The Achilles' Heel: Reused and Compromised Credentials The McDonald's breach is a stark reminder that your most sophisticated firewalls and cutting-edge threat detection systems can be utterly bypassed by the simplest weak link: a compromised credential. Why is this such a prevalent problem? Because users—whether your customers, employees, or third-party vendors—often reuse credentials across many sites and accounts . A staggering 52% of US adults reuse the same password across two or more accounts, and 13% admit to using the same password for ALL their accounts. The McDonald's breach is a stark reminder that your most sophisticated firewalls and cutting-edge threat detection systems can be utterly bypassed by the simplest weak link: a compromised credential. This habit is the fuel for devastating attacks like credential stuffing , where credential pairs obtained from one source (like a data breach) are used to attack other systems. Weak Active Directory (AD) credentials are a primary vector for both initial compromise and lateral movement within an organization, leading to ransomware, data breaches, and business email compromise (BEC). Even when multi-factor authentication (2FA) is enforced, gaps can exist, especially with third-party applications, making the security of the "first factor"—the password—paramount. In fact, employees using company credentials outside of work were tracked in 40% of data breaches. The Easiest, Most Effective Defense: Proactive Credential Screening Given the staggering statistics and the McDonald's debacle, it's clear: screening credentials for your corporation's customers, employees, and vendors is one of the easiest, most accurate, and highly effective ways to drastically reduce access to your corporate and customer data. This isn't about blaming users for their password habits; it's about putting robust systems in place that protect your organization despite those habits. Enter myNetWatchman. We provide the tools to proactively detect and mitigate these risks before criminals can exploit them. myNetWatchman's Active Directory (AD) Audit Tool : This powerful solution directly scans your Active Directory to identify compromised employee and vendor credentials . It screens your organization's internal credentials against our extensive repository of known compromised credentials, making it paramount for preventing account takeover. It's designed to secure your AD against modern threats and address weak credentials that can lead to initial compromise and lateral movement. Our secure API compares NT hashes from your AD against our vast password repository, leveraging K-Anonymity for enhanced privacy. This allows you to securely identify compromised accounts instantly and helps you get ahead of potential credential stuffing attacks against your employees. myNetWatchman's AllCreds Compromised Credential Screening : This solution enables you to detect if compromised credentials are being used by your consumers and/or employees at key events like account creation, login, and password changes . AllCreds doesn't just screen for breached credentials; it identifies ones that are actively being used, focusing on credential pairs to significantly reduce false positives and unnecessary friction. It allows you to prevent account takeover (ATO) by directing users to choose secure passwords and can even trigger 2FA for high-risk accounts. AllCreds is your front-line defense against credential stuffing attacks, which are effective because so many consumers reuse passwords. We've built an ever-expanding database of 35+ billion unique compromised credential pairs , with 15 million new pairs added daily. Stop Playing Catch-Up, Start Leading The McDonald's breach was a painful, public lesson in the critical importance of basic credential hygiene, and, of course, security-conscious configuration settings. It's mind-boggling that the combination of two such significant missteps such a simple vulnerability could open the floodgates to 64 million records. Don't let your organization be the next cautionary tale because of a "123456" moment. With myNetWatchman's AD Audit and AllCreds, protecting your organization from credential-based attacks is not just possible, it's remarkably easy and effective. Stop wishing you had fries with that breach and start putting a real defense in place.

  • Pig Butchering Scams: A CISO’s Guide to Mitigating a Sophisticated Cyber Threat

    According to the Global Anti-Scam Alliance ( GASA ) and Chainalysis Reports , "pig butchering" scams, which involve luring victims into investing in fraudulent financial schemes often involving cryptocurrency, represent a growing menace in the cybersecurity landscape, costing victims $75 billion globally from 2020 to 2024. Compromised credentials on dating sites, for example, provide scammers with a valuable toolset for executing pig butchering scams. By leveraging stolen information and impersonating real individuals, they can effectively target and manipulate victims, leading to significant financial losses and emotional distress. MyNetWatchman has seen ongoing credential testing at multiple dating sites, with 235 thousand compromised accounts accessed by miscreants in the past year. These scams combine social engineering, romance fraud, and fraudulent investment schemes, often leveraging cryptocurrency to exploit customers and challenge enterprise security teams. For Chief Information Security Officers (CISOs), fraud prevention managers, and cybersecurity professionals, understanding and countering this threat is critical to protecting customers and organizational reputation. The Anatomy of a Pig Butchering Scam Pig butchering is a long-con fraud where scammers build trust with victims over weeks or months, often posing as romantic or friendly contacts, before luring them into fake investment platforms, typically cryptocurrency-based. The scam’s name reflects the process of “fattening” victims with trust before “slaughtering” them financially. Operated by sophisticated crime syndicates, these scams exploit human psychology and the anonymity of crypto transactions, posing unique challenges for cybersecurity teams. Pig butchering isn’t just a scam—it’s a systemic threat that exploits customer trust and bypasses traditional security controls. The Pig Butchering Playbook: A Step-by-Step Breakdown Understanding the scam’s methodology is essential for developing effective countermeasures. The process unfolds as follows: Initial Contact (Social Engineering) Scammers initiate contact through unsolicited texts, social media, or dating apps, often using “wrong number” messages to engage victims. These messages exploit human curiosity and are tailored to appear personal. Example: “Hi, is this Sarah? It’s been ages!” CISO Challenge : Detecting these initial vectors requires monitoring unusual communication patterns across customer-facing channels. Trust-Building Phase Over weeks or months, scammers cultivate relationships via frequent messaging, fake personas, and AI-generated content (e.g., deepfake images or videos). They pose as successful investors to establish credibility. CISO Challenge : Social engineering bypasses technical controls, requiring behavioral analytics to identify manipulative patterns. Investment Pitch Scammers introduce fraudulent investment opportunities, often directing victims to malicious apps or websites mimicking legitimate platforms like Binance. These platforms display fake returns to build confidence. CISO Challenge : Identifying and blacklisting fraudulent domains and apps in real time is critical but complex due to their rapid proliferation. Escalation and Fake Gains Victims are encouraged to invest small amounts, often seeing “returns” to build trust. Scammers then push for larger investments, sometimes pressuring victims to borrow funds. CISO Challenge : Monitoring for micro-transactions or unusual crypto wallet activity can signal early scam involvement. Financial Extraction and Disappearance When victims attempt withdrawals, scammers cite fees or technical issues, eventually vanishing with the funds. CISO Challenge : Post-scam recovery is nearly impossible due to cryptocurrency’s anonymity, emphasizing the need for preemptive detection. Real-World Impacts: Case Studies Pig butchering scams have caused significant harm, illustrating the stakes for cybersecurity teams: Connecticut Financial Institution (2020) : A customer lost $180,000 after a scammer, initiating contact via WhatsApp, guided them to a fake crypto platform. The institution faced reputational damage and legal inquiries for failing to flag the transfers. Message Sample: “Sorry, wrong number! But you seem nice, what’s your story?” Ohio Bank (2024) : A regional bank reported $6 million in customer losses to pig butchering scams, with scammers using cloned apps to mimic legitimate trading platforms, overwhelming the bank’s fraud detection systems. Illinois Credit Union (2024) : A widower lost $1 million after months of communication with a scammer posing as a romantic partner. The credit union’s lack of real-time monitoring delayed detection, leading to regulatory scrutiny. The FBI’s IC3 logged 4,300+ pig butchering complaints in 2021, with losses exceeding $429 million, underscoring the scale of the threat to financial institutions. Enterprise Risks and Detection Challenges For CISOs and fraud prevention managers, pig butchering presents unique hurdles: Bypassing Traditional Controls: Scams rely on human manipulation, not malware, evading firewalls and antivirus solutions. Cryptocurrency Anonymity : Blockchain transactions are hard to trace, complicating recovery efforts. Scalability of Attacks : Crime syndicates operate at scale, using call centers and trafficked labor, overwhelming manual detection efforts. Customer Education Gaps : Even sophisticated customers fall for well-crafted scams, requiring proactive monitoring to compensate for human error. Pig butchering exploits the human element, making it a blind spot for traditional cybersecurity. Advanced monitoring is our best defense. Conclusion Pig butchering scams pose a sophisticated threat to customers and enterprises alike, exploiting trust and evading traditional cybersecurity controls. For CISOs and fraud prevention managers, the stakes are high: financial losses, reputational damage, and regulatory scrutiny demand proactive measures. By combining customer education, behavioral analytics, and advanced tools like those provided by myNetWatchman, organizations can detect and disrupt these scams early, safeguarding customers and their bottom line. Explore myNetWatchman’s solutions at myNetWatchman.com to strengthen your defenses.

  • The Achilles' Heel of Online Security: Why Passwords Leave Companies Vulnerable

    In our digital-first world, passwords, combined with an email address or User ID, are the primary gatekeepers to vast amounts of sensitive data. However, for nearly every online company, this reliance on passwords as a verification and identity method presents a critical weakness. This leaves them vulnerable to a relentless barrage of criminal activities, including credential stuffing, account takeover, and ransomware attacks. The inherent flaws in how passwords are created, managed, and exposed have transformed them into the Achilles' heel of cybersecurity. Pervasive Problems: Weak, Reused, and Leaked Passwords Recent studies paint a bleak picture of password hygiene. A Cybernews study on billions of leaked passwords revealed that a staggering 94% are either reused or duplicated across multiple services. Many users opt for "lazy" patterns like "123456" or simple combinations of lowercase letters and digits, making them trivial targets for brute-force and dictionary attacks. Despite decades of cybersecurity education, there has been little to no progress in user behavior, underscoring the urgent need for more robust authentication methods. Compounding the issue, massive databases of compromised credentials are routinely exposed. For example, two recent incidents of massive data leaks: A recent Wired article revealed a mysterious, unsecured database containing 184 million login credentials, including those for major platforms like Google, Apple, Facebook, Microsoft, banks, and even government services. This trove, possibly collected via infostealer malware, offers cybercriminals direct access into accounts, serving as a dream working list for credential stuffing, phishing, and targeted attacks. Cybernews reported a data leak of nearly 16 billion passwords and other credentials from over 30 databases. The article states in part, “This is not just a leak – it’s a blueprint for mass exploitation.” Even if a company's systems remain unbreached, employees reusing passwords across personal and professional accounts can inadvertently create a critical threat vector, opening the gates for criminals to exploit vulnerabilities and introduce security problems like ransomware. Employees: The Unintentional Weak Link The human element remains a significant vulnerability. Employees unknowingly become the weakest link by reusing emails, passwords, and company credentials across various online services. This practice creates a pathway for criminals to infiltrate corporate networks if even one of those external accounts is compromised, leading to devastating consequences such as ransomware attacks that cripple operations. Building a Protective Barrier: myNetWatchman's 1-2-3 Security Screening Solutions To counteract these pervasive threats, companies must adopt a multi-layered security approach that proactively addresses credential vulnerabilities. myNetWatchman offers a comprehensive 1-2-3 security screening suite designed to create a protective barrier for companies, their customers, and their employees: Securing Company Active Directories with AD Audit : The myNetWatchman AD Credential Audit scans internal Active Directory accounts for compromised passwords and credential pairs. Leveraging a repository of over 35 billion compromised credentials, this tool identifies vulnerable accounts within your organization. By detecting and re-securing these exposed credentials, companies can significantly reduce the chances of infiltration by criminals looking to exploit weaknesses through ransomware and other attacks. This proactive auditing helps prevent breaches and strengthens your core network defenses. Screening Customer Credentials with AllCreds : myNetWatchman AllCreds Compromised Credential Screening proactively screens credentials at login, signup, or password reset against a live data surveillance system containing billions of exposed credential pairs. When a user attempts to authenticate, AllCreds checks if the entered username and password have been compromised. If detected, the system flags them, allowing companies to force password changes or implement step-up authentication. This significantly mitigates the risk of credential stuffing and account takeover attacks, directly reducing financial losses and protecting customer accounts. Screening Email Addresses with Email Reputation : Recognizing that email, never intended as a robust security channel, is frequently targeted by criminals, myNetWatchman Email Reputation provides critical screening for email addresses. This service checks email validity, synthetic nature, and whether it has been actively used by criminals to gain access to accounts. By making a simple API call, companies can determine if an email address is compromised, when it was accessed, and for what purpose. This enables organizations to head off criminal activity like fraud and account takeover, especially in scenarios involving password resets, sign-in links, or new account sign-ups, by enabling crucial decision points for step-up authentication or flagging high-risk transactions. By implementing this strategic 1-2-3 security screening, companies can move beyond the inherent weaknesses of passwords, establishing a robust protective barrier that safeguards their operations, customers, and employees from the ever-present threat of cybercrime. The future of online security lies in proactive, intelligent credential management that assumes compromise and builds defenses accordingly.

  • The Hidden Vulnerability: How Compromised Credentials Fuel Ransomware and Beyond

    In today's interconnected digital landscape, the security of a company's sensitive data is only as strong as its weakest link. While organizations invest heavily in perimeter defenses, a critical vulnerability often lurks within: the exposed email addresses, passwords, and user IDs of employees and third-party vendors. These seemingly small exposures can provide an open door for cybercriminals to unleash devastating ransomware attacks, data breaches, and other malicious activities. Recent incidents at major retailers like Victoria's Secret and Adidas serve as stark reminders of the far-reaching consequences of security lapses. Victoria’s Secret’s internal corporate systems and customer website were shut down for several days, and Adidas’ customer data was stolen from a third-party vendor. Overlooking the security posture of internal personnel and external partners is a significant threat that many companies fail to adequately address. The Ripple Effect of Compromised Credentials Threat actors actively harvest employee credentials from various sources, including previous data breaches, phishing campaigns, and malware infections. myNetWatchman sees millions of attempts every year by bad actors targeting company systems. Once obtained, these credentials become a golden key, allowing attackers to: Gain Initial Access : Compromised credentials provide a legitimate entry point into a company's network, bypassing traditional firewalls and intrusion detection systems. This enables attackers to operate undetected for extended periods. Escalate Privileges : If the compromised account belongs to a privileged user (e.g., an administrator), attackers can rapidly escalate their access, moving deeper into the network and gaining control over critical systems. Lateral Movement : With valid credentials, attackers can move horizontally across a network, accessing various systems and applications without triggering immediate alarms. This allows them to map out the network, identify valuable data, and prepare for their primary objective. Deploy Ransomware : This is often the ultimate goal. Once inside, attackers can deploy ransomware, encrypting critical files and demanding a ransom for their release. The impact can halt operations, cripple productivity, and lead to significant financial losses. Data Exfiltration : Beyond ransomware, compromised credentials can also lead to the theft of sensitive customer, employee, or proprietary business data, resulting in regulatory fines, reputational damage, and loss of competitive advantage. Business Email Compromise (BEC) and Funds Transfer Fraud (FTF) : Compromised email accounts, especially those of executives or financial personnel, can be leveraged for sophisticated BEC scams, tricking employees into making fraudulent wire transfers. The Adidas breach, which originated from a compromise at a third-party customer service provider, highlights the insidious nature of vendor-related risks. Even if a company has robust internal security, its interconnectedness with third parties means that a vulnerability in a vendor's systems can directly impact the company's data and operations. The Victoria's Secret incident led to the company taking down its website and some in-store services. The "security incident" also reportedly locked employees out of email accounts, directly impacting internal operations and implying compromised employee access. These incidents are clear and forceful reminders that the human element and the supply chain are critical attack surfaces that demand constant vigilance. Proactive Defense: Auditing Credentials for Stronger Security The good news is that these risks can be significantly mitigated through proactive security measures, particularly a robust auditing strategy for internal employee and third-party vendor credentials. Key aspects of such an audit include: Continuous Monitoring of Compromised Credentials : Regularly scanning for employee and vendor credentials that have appeared in public data breaches or on the dark web. Strong Password Policies and Enforcement : Implementing and enforcing policies that require complex, unique passwords for all accounts, especially those with elevated privileges. Multi-Factor Authentication (MFA) : Mandating MFA for all access points, significantly increasing the difficulty for attackers even if they obtain a password. Least Privilege Principle : Ensuring that employees and vendors only have the minimum necessary access rights required to perform their duties. Regular reviews of access permissions are crucial. Regular User Access Reviews : Periodically reviewing and revoking access for inactive accounts or those where privileges are no longer needed. Third-Party Risk Management : Establishing comprehensive vetting processes for all third-party vendors, including assessing their cybersecurity posture, contractual obligations for data security, and ongoing monitoring. Security Awareness Training : Educating employees and vendors about phishing, social engineering tactics, and the importance of strong password hygiene. Securing Your Digital Gates with myNetWatchman's AD Audit Understanding the critical role of credential security in preventing ransomware and other attacks, myNetWatchman offers a specialized AD Credential Audit service. This service is designed to help organizations identify and address weaknesses in their Active Directory environment, which is often the central hub for managing user identities and access. myNetWatchman's AD Audit service provides: Comprehensive Scanning : Proactively scans your Active Directory for compromised employee credentials, including emails, passwords, and user IDs that may have been exposed in breaches or are circulating on the dark web. NIST Compliance Checks : Helps ensure your organization's password policies and practices align with the latest NIST (National Institute of Standards and Technology) guidelines for robust cybersecurity. Elevated Privilege Account Monitoring : Identifies accounts with elevated privileges that may be vulnerable to compromise, allowing for targeted remediation efforts. Policy Compliance Verification : Confirms adherence to company security policies regarding credential management, without requiring you to share any Personally Identifiable Information (PII) with myNetWatchman. Real-time Threat Intelligence : Leverages a vast and continuously updated database of compromised credentials to provide real-time insights into potential threats targeting your organization. By leveraging services like myNetWatchman's AD Audit, businesses can proactively identify and remediate credential-related vulnerabilities, significantly reducing their attack surface and bolstering their defenses against the ever-present threat of ransomware and other devastating cyberattacks. In an era where every credential is a potential entry point, diligent auditing is not just a best practice – it's a necessity for survival.

Search Results

bottom of page