{"id":49077,"date":"2024-02-12T21:46:21","date_gmt":"2024-02-12T10:46:21","guid":{"rendered":"https:\/\/www.tomgrimshaw.com\/tomsblog\/?p=49077"},"modified":"2024-02-12T21:46:21","modified_gmt":"2024-02-12T10:46:21","slug":"credential-stuffing","status":"publish","type":"post","link":"https:\/\/www.tomgrimshaw.com\/tomsblog\/?p=49077","title":{"rendered":"Credential Stuffing"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone  wp-image-49078\" src=\"http:\/\/www.tomgrimshaw.com\/tomsblog\/wp-content\/uploads\/2024\/02\/Credential_Stuffing-300x162.jpg\" alt=\"Credential Stuffing\" width=\"776\" height=\"419\" srcset=\"https:\/\/www.tomgrimshaw.com\/tomsblog\/wp-content\/uploads\/2024\/02\/Credential_Stuffing-300x162.jpg 300w, https:\/\/www.tomgrimshaw.com\/tomsblog\/wp-content\/uploads\/2024\/02\/Credential_Stuffing.jpg 754w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/p>\n<div class=\"elementor-element elementor-element-22a224e elementor-widget elementor-widget-heading\" data-id=\"22a224e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n<div class=\"elementor-widget-container\">\n<h4 class=\"elementor-heading-title elementor-size-default\">Thousands of people across Australia have woken up to the news that they might be victims of ongoing online scams.<\/h4>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-c2a9fc9 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"c2a9fc9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n<div class=\"elementor-widget-container\">\n<p>Cyber security company, Kasada, has been investigating cyber attacks and found a number of well-known retailers might have been compromised, according to the\u00a0<a href=\"https:\/\/www.smh.com.au\/politics\/federal\/thousands-of-australians-hacked-in-credential-stuffing-credit-card-scam-20240116-p5exls.html\" target=\"_blank\" rel=\"noopener\">Sydney Morning Herald<\/a>.<\/p>\n<p>In their analysis, Kasada alleges some customers of Guzman y Gomez, Dan Murphy\u2019s, Binge, TVSN and Event Cinemas have had their online accounts compromised.<\/p>\n<p>This comes just a week after the news that online retailer,\u00a0<a href=\"https:\/\/www.smh.com.au\/business\/companies\/the-iconic-promises-to-issue-refunds-to-hacked-customers-20240109-p5ew1c.html\" target=\"_blank\" rel=\"noopener\">The Iconic had been breached<\/a>, causing some customers to lose thousands of dollars and have their user details breached.<\/p>\n<p>In these attacks, cyber criminals are using a scam called \u201ccredential stuffing\u201d to gain access to an individual\u2019s online account and make fraudulent transactions.<\/p>\n<p>As a small business, if you trade online using an eCommerce store or you purchase online \u2014 here\u2019s what you need to know.<\/p>\n<\/div>\n<\/div>\n<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b92671e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b92671e\" data-element_type=\"section\">\n<div class=\"elementor-container elementor-column-gap-default\">\n<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6110dd4\" data-id=\"6110dd4\" data-element_type=\"column\">\n<div class=\"elementor-widget-wrap elementor-element-populated\">\n<div class=\"elementor-element elementor-element-fc0b28c elementor-widget elementor-widget-heading\" data-id=\"fc0b28c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What is credential stuffing?<\/h3>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2079d88 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2079d88\" data-element_type=\"section\">\n<div class=\"elementor-container elementor-column-gap-default\">\n<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3a023e2\" data-id=\"3a023e2\" data-element_type=\"column\">\n<div class=\"elementor-widget-wrap elementor-element-populated\">\n<div class=\"elementor-element elementor-element-6428511 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"6428511\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n<div class=\"elementor-widget-container\">\n<p><b>Credential stuffing\u00a0<\/b>is a type of cyber attack that targets people who have previously had their usernames, emails or passwords stolen in a data breach. They are then more vulnerable to a second, more dangerous attack where cyber criminals reuse the email and password combinations to get access to more of your accounts, and more of your personal data.<\/p>\n<p>It might help to think of credential stuffing like a cyber criminal game of bingo. Hackers will take your previously stolen passwords and try to crack your other accounts using the same details. This is why people who reuse the same passwords when shopping online are more at-risk of an attack.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9e23cb5 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9e23cb5\" data-element_type=\"section\">\n<div class=\"elementor-container elementor-column-gap-default\">\n<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b0f78ec\" data-id=\"b0f78ec\" data-element_type=\"column\">\n<div class=\"elementor-widget-wrap elementor-element-populated\">\n<div class=\"elementor-element elementor-element-f03b5e5 elementor-widget elementor-widget-heading\" data-id=\"f03b5e5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What are credential stuffing shopping scams?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4893d10 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"4893d10\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n<div class=\"elementor-widget-container\">\n<p>When cyber criminals successfully use credential stuffing to guess your password on a online shopping account then they have the ability to place orders, and charge them back to your previously used credit card!<\/p>\n<div class=\"elementor-element elementor-element-2a030e5 elementor-widget elementor-widget-heading\" data-id=\"2a030e5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">How do I know if my details have been hacked?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-ecb32be elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"ecb32be\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n<div class=\"elementor-widget-container\">\n<p>Kasada, who has been analysing the attacks, says that 15,000 Australian accounts have been hacked in the past three months, as at January 2023, with that number growing daily.<\/p>\n<p>People who use the same passwords across many accounts are most vulnerable to a credential stuffing cyber attack, especially if they have previously had their usernames stolen in an unrelated data breach.<\/p>\n<p>If you are unsure if you have previously had your data leaked online you can check by visiting the website \u2018<b><a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener\">Have I been pwnd<\/a>\u2019\u00a0<\/b>which checks your email against known data leaks. If the email you usually shop with is in on this list it means\u00a0 you can be targeted with a credential stuffing attack.<\/p>\n<p>Because credential stuffing cyber attacks impersonate legitimate shoppers using real passwords and real usernames, it makes it very difficult for online businesses to identify the scam.<\/p>\n<p>While many companies are still learning or investigating the attacks, we encourage you to review your bank statements and look out for any suspicious transactions.<\/p>\n<p>If you think you have been hacked, you can\u00a0<a href=\"https:\/\/www.cyber.gov.au\/report-and-recover#report\" target=\"_blank\" rel=\"noopener\">make a report to the ACSC.<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<p><a href=\"https:\/\/cyberwardens.com.au\/blog\/what-is-credential-stuffing\/\">https:\/\/cyberwardens.com.au\/blog\/what-is-credential-stuffing\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Thousands of people across Australia have woken up to the news that they might be victims of ongoing online scams. Cyber security company, Kasada, has been investigating cyber attacks and found a number of well-known retailers might have been compromised, according to the\u00a0Sydney Morning Herald. In their analysis, Kasada alleges some customers of Guzman y &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.tomgrimshaw.com\/tomsblog\/?p=49077\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Credential Stuffing&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,10],"tags":[],"class_list":["post-49077","post","type-post","status-publish","format-standard","hentry","category-general-interest","category-wealth-tips"],"_links":{"self":[{"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=\/wp\/v2\/posts\/49077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=49077"}],"version-history":[{"count":1,"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=\/wp\/v2\/posts\/49077\/revisions"}],"predecessor-version":[{"id":49079,"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=\/wp\/v2\/posts\/49077\/revisions\/49079"}],"wp:attachment":[{"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=49077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=49077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tomgrimshaw.com\/tomsblog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=49077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}