This page was machine-translated and may differ from the original. View original

Retail, travel, and hospitality industries are "most vulnerable to web attacks."

Google 우선 소스Published2020.10.29 15:12
Credential stuffing attacks targeting retail, travel, and hotels,
Approximately 63 billion accidents occurred over two years, accounting for 63% of all accidents.
During the same period, it also received approximately 4.3 billion web attacks.



Retail, travel, and hotel industries were found to be the most vulnerable to internet attacks.

Akamai announced this on the 29th, releasing the '2020 State of the Internet / Security Report: Fraud Targeting Loyalty Programs in the Retail and Hotel Industries'.
▲ Retail, travel, hotel industry, cyber attackers
Appears as the optimal prey [Image = Akamai]

According to Akamai, between July 2018 and June 2020, approximately 63 billion credential stuffing attacks were committed against the retail, travel, and hospitality industries.

“Attackers will exploit any information they can get their hands on,” said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report. “That’s why we’ve seen so many credential stuffing attacks in the last few years.”

Retail and loyalty profiles contain a large amount of personal and financial information. This data can be collected, sold, traded, or stored as bulk profile information that can later be used for crimes such as identity theft.

Attackers targeted the e-commerce industry during the COVID-19 lockdowns of the first quarter of 2020, taking advantage of the unprecedented global situation and leaked password combination lists. This period saw a significant increase in criminal inventory and sales related to loyalty programs, as attackers began recycling old credential lists to identify new vulnerable accounts.

Akamai observed over 100 billion credential stuffing attacks across all industries between July 2018 and June 2020. In the commerce sector, which includes retail, travel, and hospitality, approximately 63 billion credential stuffing attacks were observed.

This shows that more than 90% of attacks in the commerce sector targeted the retail industry. Furthermore, the retail, travel, and hospitality industries experienced approximately 4.3 billion web attacks between July 2018 and June 2020.
▲ In addition to credential stuffing, SQLi attacks are also common [Image = Akamai]

Credential stuffing isn't the only method used. Attackers also utilize SQL injection and local file inclusion attacks. These attacks accounted for 41% of all web attacks, and 83% of these attacks focused solely on the retail industry. SQLi attacks are a preferred attack vector for attackers, accounting for approximately 79% of all web application attacks against retail, travel, and hospitality industries.

The full report can be found on the Akamai website .
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김동우 기자