• 18-19 College Green, Dublin 2
  • 01 685 9088
  • info@cunninghamwebsolutions.com
  • cunninghamwebsolutions
    Cunningham Web Solutions
    • Home
    • About Us
    • Our Services
      • Web Design
      • Digital Marketing
      • SEO Services
      • E-commerce Websites
      • Website Redevelopment
      • Social Media Services
    • Digital Marketing
      • Adwords
      • Social Media Services
      • Email Marketing
      • Display Advertising
      • Remarketing
    • Portfolio
    • FAQ’s
    • Blog
    • Contact Us
    MENU CLOSE back  

    Taking the ‘stuff’ out of credential stuffing

    You are here:
    1. Home
    2. Digital Marketing
    3. Taking the ‘stuff’ out of credential stuffing

    We’re only human. You’ve heard that phrase before. Right?! We’re only human is a phrase readily applied to universal faux pas and shortcomings – one that highlights how our temporal existence all too often falls short of expectations. Read another way, we can only do so much. And this is exactly what cybercriminals depend on to take advantage of our desire to uncomplicate our lives. Let’s stop and consider the following: how often do you use the same email address or user name, and password to log into different websites? I thought so. We all do it. It’s a universal habit given how many times we log into our work account, social media, shopping and other digital properties (not to mention our phones) throughout the course of a day. Let me ask another question: how many of you use the same four digit pin to access your mobile phone as you do your bank account? I rest my case.

    What is credential stuffing?

    The internet has permeated every corner of our lives – it is how we bank, shop, and during the age of COVID-19, how we order groceries, deliver food, communicate, attend webinars, join video calls, and so much more. As you know, each of these actions requires a login. Like a good chef, who will use every part of an animal (down to the bones) to make a rich stock, bad actors use every bit of data siphoned from one data breach to conduct their next attack. A treasure trove of user information isn’t just harvested for the credit cards to use in purchasing illicit goods or paying for services, the usernames and passwords are then often used to gain entry, in an automated fashion, to other websites and platforms. This is what a credential stuffing attack is in its simplest and most basic form.

    However, acquiring user credentials doesn’t require theft. There are markets on the dark web that routinely traffic in stolen credentials. Remember the analogy of a chef, those bits of stolen data are separated and sold over and over again because they each possess a value on the dark web. In addition to value, they possess a utility to a bad actor that will leverage them to create more chaos and havoc leading to the compromise of other platforms—invariably leading to identity theft and potentially much worse.

    Account takeovers

    We can all agree that identity theft is the scourge of the internet, a shared resource that we find indispensable in this day and age. However, stealing identities is far from the only thing that hackers can do. When attackers took over the Twitter account of the Spanish football club FC Barcelona they used it to send bogus tweets. Similar attacks have been launched against Statefarm and Dunkin Donuts. The most recent Verizon Data Breach Investigations Report found that 80% of breaches that include hacking are brute force attacks, or leverage lost or stolen credentials (i.e. credential stuffing). The Open Web Application Security Project classifies credential stuffing as a subset of brute force attacks. The difference is that a brute force attack uses no context and just tries to guess password and login credentials. These are also sometimes called dictionary attacks. Credential stuffing, however, uses known password and login credential combinations to make the process far more targeted and likely to succeed.

    Feel uneasy? You should. I don’t mean to downplay the significance of identity theft – it’s horrible and can take months to clean up – I know, I had to do it for my wife’s accounts. However, account takeovers can have massive consequences – imagine if an attacker was to get a hold of a government officials’ personal email account. Think of the information and secrets they would find and the damage they could wreak if they began to send emails as that government official.

    Protecting our shared infrastructure begins with understanding that we are all our personal CISO, and therefore are responsible for securing each and every account we use against attacks. And guess what else? Marketers can help because they are the tip of their company’s brand—marketers are the stewards of the brand experience and how a given product or service is perceived in the industry. Everyone – including marketers – plays a role in making sure that the internet thrives.

    Basic cybersecurity for marketers

    Now that we’re aligned on the need to become savvier with our personal cybersecurity, therefore helping our companies by being good stewards of our own logins, let’s talk about how to make that happen.

    • Don’t reuse the same login name and password across multiple sites. Use different passwords in conjunction with a login name. Should one of the passwords get compromised, it’s highly unlikely that other accounts can then be compromised as a result.
    • Use complex passwords. And yes, your pet’s name is not a complex password even if you capitalize every other letter and put an exclamation mark at the end. Wait, did I just give you my pAsSwOrD!?
    • Use a password manager. When I started this article I mentioned how we’re all fallible, and being human in a digital world is hard. It’s true. Remember that many passwords are nearly impossible unless you have a photographic memory.
    • As much as you can, rotate your passwords. This is just good password hygiene. If you’ve been using the same simple password on a website for the last 10 years, it’s time to update it and make a habit of changing it every so often. The more critical the site (like your banking website) the more often you should update and change that password. For those of you that work at companies with strict password policies that force you to update it every 30, 60 or 90 days, that’s done for a reason. It’s not just to make your lives more difficult, it’s to make the company more secure. Take that as a queue and apply it to your own life. Also, apply it to the customer experience your applications and e-commerce shops have waiting for your customers.
      • Ask your customers to choose passwords that are long and complicated with special characters, numbers and combinations of capital letters.
      • Ask your customers to change their passwords at least once a year if not more often, or if they haven’t logged-in in a really long time.
    • The single most effective way to secure your accounts is by using multi-factor authentication (MFA). Multi-factor authentication is using a secondary device to access an account online — like receiving a text to a mobile phone when attempting to log in, or having to open an authenticator app that issues a code to access a site. According to Microsoft, using MFA blocks 99.9% of account attacks! What’s more, if you don’t turn on your account’s MFA then there’s a high likelihood that attackers will turn it on for you and make it harder to recover, according to a recent article by cybersecurity reporter Brian Krebs. Yes, it’s an extra step, but it is one that can vastly diminish the ability of an attacker to gain access to your platform, or worse, your customer’s experience, on your platform or service.

    As much joy as the internet brings us, it can bring equally as much – if not more – anxiety and pain, should our critical accounts fall into the hands of criminals. It’s important that we pause and consider just how simple our online lives could be, should we take the minor precautions necessary to keep our identities and our critical assets secure. Because I assure you, the bad guys are watching and constantly probing our defenses – it’s just how they operate.

    Marketers can help build good habits by insisting their sites require things like MFA, and complex passwords that are rotated. Because if our e-commerce experience evolves, then we may all be more likely to evolve our personal security habits for things like email and banking. We are all creatures of habits – it’s high time we started engaging in better security ones.

    The post Taking the ‘stuff’ out of credential stuffing appeared first on Marketing Land.

    From our sponsors: Taking the ‘stuff’ out of credential stuffing

    Posted on 29th July 2020Digital Marketing
    FacebookshareTwittertweetGoogle+share

    Related posts

    Thumbnail for 25786
    The Future of CX with Larry Ellison
    19th October 2020
    20201019 ML Brief
    19th October 2020
    Must-know tips for boosting your video strategy
    19th October 2020
    20201016 ML Brief
    19th October 2020
    Thumbnail for 25769
    How to make your data sing
    13th October 2020
    NewsCred rebrands as Welcome
    13th October 2020
    Latest News
    • Archived
      22nd March 2023
    • Archived
      18th March 2023
    • Archived
      20th January 2023
    • 20201019 ML Brief
      19th October 2020
    • Thumbnail for 25788
      Handling Continuous Integration And Delivery With GitHub Actions
      19th October 2020
    • Thumbnail for 25786
      The Future of CX with Larry Ellison
      19th October 2020
    News Categories
    • Digital Marketing
    • Web Design

    Our services

    Website Design
    Website Design

    A website is an important part of any business. Professional website development is an essential element of a successful online business.

    We provide website design services for every type of website imaginable. We supply brochure websites, E-commerce websites, bespoke website design, custom website development and a range of website applications. We love developing websites, come and talk to us about your project and we will tailor make a solution to match your requirements.

    You can contact us by phone, email or send us a request through our online form and we can give you a call back.

    More Information

    Digital Marketing
    Digital Marketing

    Our digital marketeers have years of experience in developing and excuting digital marketing strategies. We can help you promote your business online with the most effective methods to achieve the greatest return for your marketing budget. We offer a full service with includes the following:

    1. Social Media Marketing

    2. Email & Newsletter Advertising

    3. PPC - Pay Per Click

    4. A range of other methods are available

    More Information

    SEO
    SEO Services

    SEO is an essential part of owning an online property. The higher up the search engines that your website appears, the more visitors you will have and therefore the greater the potential for more business and increased profits.

    We offer a range of SEO services and packages. Our packages are very popular due to the expanse of on-page and off-page SEO services that they cover. Contact us to discuss your website and the SEO services that would best suit to increase your websites ranking.

    More Information

    E-commerce
    E-commerce Websites

    E-commerce is a rapidly growing area with sales online increasing year on year. A professional E-commerce store online is essential to increase sales and is a reflection of your business to potential customers. We provide professional E-commerce websites custom built to meet our clients requirements.

    Starting to sell online can be a daunting task and we are here to make that journey as smooth as possible. When you work with Cunningham Web Solutions on your E-commerce website, you will benefit from the experience of our team and every detail from the website design to stock management is carefully planned and designed with you in mind.

    More Information

    Social Media Services
    Social Media Services

    Social Media is becoming an increasingly effective method of marketing online. The opportunities that social media marketing can offer are endless and when managed correctly can bring great benefits to every business.

    Social Media Marketing is a low cost form of advertising that continues to bring a very good ROI for our clients. In conjuction with excellent website development and SEO, social media marketing should be an essential part of every digital marketing strategy.

    We offer Social Media Management packages and we also offer Social Media Training to individuals and to companies. Contact us to find out more.

    More Information

    Cunningham Web Solutions
    © Copyright 2025 | Cunningham Web Solutions
    • Home
    • Our Services
    • FAQ's
    • Account Services
    • Privacy Policy
    • Contact Us