Site icon Bizety: Research & Consulting

Distil Networks Research On ATOs (Account Takeovers)

Distil Networks, the San Francisco-headquartered bot detection and mitigation specialists, today issued ­ The 2018 Anatomy of Account Takeover Attacks Report focused on ATOs (account takeovers). The report draws on data from 600 domains, including login pages; 100 of which that had the largest bad bot traffic datasets were then analyzed. All the monitored login pages were hit with bad bot traffic, suggesting that every single website that has a login page faces Account Takeover (ATO) attempts.

The report analyses patterns discerned in ATO attacks, lists the most popular tools used to carry out the attacks, and creates categories for the three primary types of ATO bot attack profiles. It also outlines the differences between simple, moderate and advanced attacks, and puts forward methods for how to detect and mitigate each attack type.

ATOs conducted by bots on behalf of hackers or fraudsters are undertaken for a range of purposes, from attempting to validate sets of logins to gaining access to an account and information within, such as credit card details. Stolen account data can also be put to use in transferring money, purchasing goods, selling it on the dark web or spreading a specific agenda.

Key Findings from the Distil report include:

“Every time a breach comes to light and consumer credentials are exposed, any business with a login page should prepare themselves for a swell of volumetric credential stuffing attacks,” said Anna Westelius, senior director of security research at Distil Networks. “While bot operators may be purposeful in their strategy of carrying out ATO attacks, this data also renders them predictable. Organizations must educate themselves in order to identify the warnings signs, and be prepared for times when an attacker may strike.”

A full copy of the Distil Networks The Anatomy of Account Takeover Attacks Report can be downloaded here.

Copyright secured by Digiprove © 2018
Exit mobile version