Image courtesy of SC Magazine
Richard Dufty, chief commercial officer at Arkose Labs, describes credential stuffing as 'the attack CISOs fear most' because its volumetric nature can overwhelm an entire security team while serving as a precursor to account takeovers. Arkose Labs' Q2 2022 State of Fraud and Account Security report found credential-stuffing attacks were 30% higher in Q1 2022 than the two-year prior average, a trend illustrated by high-profile attacks on Zola and General Motors in the same week. Dufty warns that the persistent, scalable nature of credential stuffing makes it one of the most urgent threats facing payments and financial firms.



