Image courtesy of Help Net Security
Arkose Labs documented 2,831,028,247 credential stuffing attacks in the 12 months from October 2020 to September 2021, a 98% increase over the prior year that the company warned would peak during the Christmas shopping months. The attack type, which exploits reused passwords to gain unauthorized access to financial and personal accounts, made up 5% of all online traffic in the first half of 2021. Arkose Labs cautioned that cybercriminals monetize compromised accounts through fund theft, personal data resale and money laundering — making the holiday surge in online shopping a particularly high-risk window.



