Threat Management, Network Security

Gaming industry has become popular target of credential stuffing attacks: study

A company's recent analysis of credential abuse activity over a 17-month period uncovered roughly 55 billion credential stuffing attack attempts against various online services, roughly 12 billion of which targeted the gaming industry.

Researchers at Akamai Technologies revealed the data in their latest State of the Internet/Security report, which specifically focuses on web attacks and gaming abuse.

Credential stuffing has become an increasingly popular tactic among cybercriminals, in part due to many consumers' bad habits of using the same passwords across multiple online accounts.

Based on Akamai's findings, gaming platforms and their users are among the biggest victims of this trend. In particular, malicious actors are looking to hijack gamers' accounts and sell them off to the highest bidder. Accounts that have earned special weapons or character upgrades that ordinarily must be either purchased or earned through play are often considered especially valuable.

"For example, criminals target popular games like Fortnite and Counter-Strike: Global Offensive (CS:GO), looking for valid accounts and unique skins," the report explains. "Most compromised accounts sold in gaming marketplaces are used to avoid bans, but others are purchased for the novelty of playing with a rare skin or unique item. Sometimes, the items in the compromised account are traded away or later sold."

"If the hijacked profiles are connected to a valid credit card or PayPal account, they're considered more valuable," the report continues, "since the criminal can purchase additional items... and then trade or sell the account at a markup."

Akamai's study incorporated data gathered from its global network of more than 230,000 servers from November 2017 through March 2019. Over this time period the largest share of credential stuffing attacks that specifically targeted the gaming industry originated in Russia (≈ 2.67 billion), followed by Canada (≈ 1.49 billion) and the U.S. (≈ 1.44 billion). In fact, nearly 51 percent of all credential stuffing attacks coming from Russia over those 17 months targeted the gaming industry.

"When we take a look at the source countries for credential stuffing attacks against the gaming industry only, Russia takes the top spot," the report states. "There could be a number of reasons for this, but the most commonly accepted one is the growth of Russian-based proxy services and bot farms where accounts are compromised at scale, before being packaged up and sold on various forums and markets."

However, the U.S. was far and away the leading source of credential stuffing attack traffic when accounting for all industry verticals. America spawned roughly 17.9 billion attack attempts, followed by Russia (≈ 5.26 billion) and Brazil (≈ 3.04 billion).

Akamai's "source country" data refers only to where the traffic originates from, and not where the attacker is physically located, the company notes in its report.

Akamai said that many of credential stuffing attacks it recorded were the work of botnets or All-in-One (AIO) applications configured to act like botnets.

"Criminals using AIOs target the authentication aspects of a victim's organization, and seek to automate access, which leads to an account takeover if they're successful," the report states. Typically, these attackers use large data sets of credentials that were accidentally or intentionally leaked online.

Akamai also looked at web application-layer attacks launched against gaming websites and saw that the U.S. was the top source of such incidents, with roughly 43.4 million such attacks during the 17-month observation period. Russia and China were a distant second and third, respectively.

Researchers examined web application-layer attacks perpetrated across all sectors, and found the top attack vectors by a wide margin were SQL injection (65.1 percent of attacks) and Local File Inclusion (24.7 percent).

In late November 2018, Akamai's customers detected a marked spike in SQL injection alerts, recording more than 35 million attempted attacks. While Akamai attributes the increase in activity to the start of the holiday shopping season, "it's also important to note that there's been a continuing elevated trend since that time," the report notes.

According to the study, the U.S. experienced around 2.67 billion web application attacks over the 17-month period way more than any other nation, with a 67 percent total share (the U.K. and Germany experienced the next most attacks, with ≈ 210 million and ≈ 130 million, respectively). But the U.S. was also a top source of these attacks, generating approximately 968 million alerts. (Russia was second with ≈ 609 million and the Netherlands was third with ≈ 281 million.)

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.