The Federal Bureau of Investigation (FBI) warns of a rising trend of cybercriminals using residential proxies to conduct large-scale credential stuffing attacks without being tracked, flagged, or blocked.
The warning was issued as a Private Industry Notification on the Bureau's Internet Crime Complaint Center (IC3) late last week to raise awareness among internet platform admins who need to implement defenses against credential stuffing attacks.
Credential stuffing is a type of attack where threat actors use large collections of username/password combinations exposed in previous data breaches to try and gain access toother online platforms.
Because people commonly use the same password at every site, cybercriminals have ample opportunity to take over accounts without cracking passwords or phishing any other information.
"Malicious actors utilizing valid user credentials have the potential to access numerous accounts and services across multiple industries to include media companies, retail, healthcare, restaurant groups and food delivery to fraudulently obtain goods, services, and access other online resources such as financial accounts at the expense of legitimate account holders," details the FBI's announcement.
Because credential stuffing attacks carry specific characteristics that differentiate them from regular login attempts, websites can easily detect and stop them.
To override basic protections, the FBI warns that threat actors are using residential proxies to hide their actual IP address behind ones commonly associated with home users, which are unlikely to be present in blocklists.
Proxies are online servers that accept and forward requests, making it appear like a connection is from them rather than the actual initiator (attacker).
Residential proxies are preferable over data center-hosted proxies because they make it harder for protection mechanisms to discern between suspicious and regular consumer traffic.
Typically, these proxies are made available to cybercriminals by hacking legitimate residential devices such asmodems or other IoTsorthrough malwarethat converts a home user's computer into a proxy without their knowledge.
Using these tools, cybercriminals automate credential stuffing attacks, with bots attempting to log in across numerous sites using previously stolen login credentials.
Moreover, some of these proxy tools offer the option to brute-force account passwords or include "configs" that modify the attack to accommodate particular requirements, like having a unique character, minimum password length, etc.
The FBI says credential stuffing attacks are not limited to websites and have been seen targeting mobile applications due to their poor security.
"Cyber criminals may also target a companys mobile applications as well as the website," warns the FBI advisory.
"Mobile applications, which often have weaker security protocols than traditional web applications, frequently permit a higher rate of login attempts, known as checks per minute (CPMs), facilitating faster account validation."
In a joint operation involving the FBI and the Australian Federal Police, the agencies investigated two websites that contained over 300,000 unique sets of credentials obtained through credential stuffing attacks.
The FBI says these websites counted over 175,000 registered users and generated over $400,000 in sales for their services.
FBI's advisory urges administrators to follow certain practices to help protect their users from losing their accounts to credential stuffing attacks, even when they use weak passwords.
The key points include:
Regular users can protect themselves by activating MFA on their accounts, using strong and unique passwords, and remaining vigilant against phishing attempts.
Read more:
FBI warns of residential proxies used in credential stuffing attacks - BleepingComputer
- Letters to the Editor, June 27 - Toronto Sun [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- A Lost Decade: Where the trajectory of today will take us by 2030 if we fail to alter course - Milwaukee Independent [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- From the Middle East to Minnesota, everything is our fault - Jewish News [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- Summer in virus shadow: Drones and CCTV: surveillance for safety on the sand in Spain - RTL Today [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- Trump Administration: Social Media Platforms Need to Police Calls for Violence That Arent the Presidents - Gizmodo Australia [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- The PACT Act would force platforms to disclose shadowbans and demonetizations - The Verge [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- Trump fans are flocking to the social media app Parler its CEO is begging liberals to join them - CNBC [Last Updated On: June 28th, 2020] [Originally Added On: June 28th, 2020]
- Core Update? YouTube Is Shadow-banning Bitcoin Related Videos, According To Popular Crypto Channels - CryptoPotato [Last Updated On: June 30th, 2020] [Originally Added On: June 30th, 2020]
- Trump Administration: Social Media Platforms Need to Police Calls for Violence That Aren't the President's - Gizmodo [Last Updated On: June 30th, 2020] [Originally Added On: June 30th, 2020]
- Meet the Next Generation of Black Lives Matter Activists Who Are Using TikTok To Create Change - Well+Good [Last Updated On: June 30th, 2020] [Originally Added On: June 30th, 2020]
- Drones and CCTV: Surveillance for safety on the sand in Spain - The Jakarta Post - Jakarta Post [Last Updated On: June 30th, 2020] [Originally Added On: June 30th, 2020]
- Lisa Nandy urges ban on imports of West Bank goods - The Guardian [Last Updated On: June 30th, 2020] [Originally Added On: June 30th, 2020]
- Reddit bans r/The_Donald and 2000 other hateful subreddits because it was about time - Best gaming pro [Last Updated On: June 30th, 2020] [Originally Added On: June 30th, 2020]
- Section 230 is Essential and Broadly Misunderstood, Say Panelists at Broadband Breakfast Live Online Event - BroadbandBreakfast.com [Last Updated On: July 10th, 2020] [Originally Added On: July 10th, 2020]
- Instagram Reels Is Now Available in India, but Can It Replace TikTok? - Gadgets 360 [Last Updated On: July 10th, 2020] [Originally Added On: July 10th, 2020]
- Olympics: IOC boss Thomas Bach reluctant to hold Tokyo Games behind closed doors - The Straits Times [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- Huawei 5G kit must be removed from UK by 2027 - BBC News [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- TikTok Is Wonderful. I Still Dont Want It on My Phone. - The New York Times [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- TikTok Shadowbanned: What It Is, Examples, & How to Get Unshadowbanned - Screen Rant [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- US Senator wants answers from Dorsey on Twitter breach that appears to be inside job - The Sociable [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- New paper calls on Instagram to do more to protect women and vulnerable users online - City, University of London [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- Twitter 'Blacklists' Lead the Company Into Another Trump Supporter Conspiracy - VICE [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- What Is Shadow Banning & Why Are TikTokers Complaining About It? - Refinery29 [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- Leaked screenshots appear to show internal Twitter tool that can blacklist users from search and trends - Reclaim The Net [Last Updated On: July 18th, 2020] [Originally Added On: July 18th, 2020]
- Hacking reveals the bitter truth about Twitter - OneNewsNow [Last Updated On: July 20th, 2020] [Originally Added On: July 20th, 2020]
- New Research Calls On Instagram To Protect Women And Vulnerable Users - TechRound [Last Updated On: July 21st, 2020] [Originally Added On: July 21st, 2020]
- Black creators say TikTok is still secretly blocking their content - Digital Trends [Last Updated On: July 21st, 2020] [Originally Added On: July 21st, 2020]
- What Is Shadow Banning & Why Are TikTokers Complaining ... [Last Updated On: July 21st, 2020] [Originally Added On: July 21st, 2020]
- Shadow banning: What it is -- and what it isn't - CNET [Last Updated On: July 21st, 2020] [Originally Added On: July 21st, 2020]
- Conservatives skeptical of Twitters latest shadow-banning ... [Last Updated On: July 22nd, 2020] [Originally Added On: July 22nd, 2020]
- Bitcoin applications used to archive hacked tweets - CoinGeek [Last Updated On: July 22nd, 2020] [Originally Added On: July 22nd, 2020]
- National security wrap | The Strategist - The Strategist [Last Updated On: July 23rd, 2020] [Originally Added On: July 23rd, 2020]
- Judge orders Michael Cohen released from prison, cites retaliation over book about Trump - STLtoday.com [Last Updated On: July 23rd, 2020] [Originally Added On: July 23rd, 2020]
- Big Tech Unmasked as Anti-conservative by Project Veritas - Newsmax [Last Updated On: July 24th, 2020] [Originally Added On: July 24th, 2020]
- Shadow of second wave of the virus hangs over efforts by world leaders to restore normalcy - Economic Times [Last Updated On: July 25th, 2020] [Originally Added On: July 25th, 2020]
- What Is Shadow Banning on Twitter? - Lifehacker [Last Updated On: July 25th, 2020] [Originally Added On: July 25th, 2020]
- Twitter bans Project Veritas ads over old video exposing ... [Last Updated On: July 25th, 2020] [Originally Added On: July 25th, 2020]
- Tories lurch to the left - 15 of Labour's 2015 manifesto pledges actioned by Conservatives - Daily Express [Last Updated On: July 27th, 2020] [Originally Added On: July 27th, 2020]
- Latest Covid-related mess overshadows the PMs plan to curb obesity - LabourList [Last Updated On: July 27th, 2020] [Originally Added On: July 27th, 2020]
- Unhealthy foods and checkout snacks targeted in obesity crackdown | ITV News - ITV News [Last Updated On: July 27th, 2020] [Originally Added On: July 27th, 2020]
- AP Explains: What is shadow banning? [Last Updated On: July 27th, 2020] [Originally Added On: July 27th, 2020]
- UK fights obesity with ad bans, more calorie labels - The Straits Times [Last Updated On: July 27th, 2020] [Originally Added On: July 27th, 2020]
- Rep. Matt Gaetz Says Zuckerberg Lied Under Oath About Facebook Conservative Censorship, calls on DOJ to Open Criminal Investigation - The Jewish Voice [Last Updated On: July 27th, 2020] [Originally Added On: July 27th, 2020]
- 50 Cent Reveals He's Been Shadow-Banned By Instagram - HotNewHipHop [Last Updated On: July 28th, 2020] [Originally Added On: July 28th, 2020]
- The truth about 'anti-conservative bias' at Facebook and Twitter - Mashable [Last Updated On: July 28th, 2020] [Originally Added On: July 28th, 2020]
- Outta Control: 50 Cent Accuses Instagram Of Shadow Banning ... [Last Updated On: July 29th, 2020] [Originally Added On: July 29th, 2020]
- 50 Cent's Shadow Ban Instagram Accusation Is His Latest IG ... [Last Updated On: July 29th, 2020] [Originally Added On: July 29th, 2020]
- ACL says conversion therapy a 'myth', fights ban in South Australia - OUTinPerth [Last Updated On: July 29th, 2020] [Originally Added On: July 29th, 2020]
- The New Big Three Revived the News Monopoly We Busted - Rush Limbaugh [Last Updated On: July 29th, 2020] [Originally Added On: July 29th, 2020]
- Big Tech must be brought to heel over election influencing: Devine - New York Post [Last Updated On: July 30th, 2020] [Originally Added On: July 30th, 2020]
- From the renegade to Black Lives Matter: How Black creators are changing TikTok culture - NBC News [Last Updated On: July 30th, 2020] [Originally Added On: July 30th, 2020]
- 'Most dangerous election interference organization': Matt Gaetz accuses Google of trying to turn US into China - Washington Examiner [Last Updated On: July 30th, 2020] [Originally Added On: July 30th, 2020]
- LGBTQ Advocates React to Trump's Ridiculous "Delay the Election" Tweet - NewNowNext [Last Updated On: July 30th, 2020] [Originally Added On: July 30th, 2020]
- Coronavirus lockdown tightened in Greater Manchester and parts of north | ITV News - ITV News [Last Updated On: July 30th, 2020] [Originally Added On: July 30th, 2020]
- Parts of Northern England banned from meeting others indoors after spike - Telegraph.co.uk [Last Updated On: July 30th, 2020] [Originally Added On: July 30th, 2020]
- Is there any merit in the government's new crackdown on HFSS ads? - Campaign US [Last Updated On: July 31st, 2020] [Originally Added On: July 31st, 2020]
- A Turkish Women's Rights Activist Explains the Importance of the 'Challenge Accepted' Campaign to Stop Femicide - Global Citizen [Last Updated On: July 31st, 2020] [Originally Added On: July 31st, 2020]
- New podcast: What did those Big Tech hearings have to do with religious life in America? - GetReligion [Last Updated On: July 31st, 2020] [Originally Added On: July 31st, 2020]
- Welcome to VPN World, will Trump's TikTok ban in the US see a surge in proxy use? - MEAWW [Last Updated On: August 1st, 2020] [Originally Added On: August 1st, 2020]
- Big Tech CEOs will face 'anti-conservative bias' claims at hearing. They're BSand dangerous. - Mashable SE Asia [Last Updated On: August 1st, 2020] [Originally Added On: August 1st, 2020]
- The Maine Idea: If Lives Matter, Then Names Matter, Too - Press Herald [Last Updated On: August 3rd, 2020] [Originally Added On: August 3rd, 2020]
- Mastermind Florida teen behind Twitter hack arrested and facing 30 felony charges - 9to5Mac [Last Updated On: August 3rd, 2020] [Originally Added On: August 3rd, 2020]
- CGTN rehires former Ofcom and Sky News head as pressure mounts - Digital TV Europe [Last Updated On: August 4th, 2020] [Originally Added On: August 4th, 2020]
- What TikTok Hides Beneath Its Addicting Little Videos Should Scare You - The Federalist [Last Updated On: August 4th, 2020] [Originally Added On: August 4th, 2020]
- How to Remove Shadow And HWID Ban In Call of Duty Warzone ... [Last Updated On: August 4th, 2020] [Originally Added On: August 4th, 2020]
- Instagrams Shadow Ban On Vaguely Inappropriate Content ... [Last Updated On: August 4th, 2020] [Originally Added On: August 4th, 2020]
- Baffling new Northern lockdown rules mean couples who dont live together can have sex in a hotel but not in t - The Sun [Last Updated On: August 4th, 2020] [Originally Added On: August 4th, 2020]
- Northern England lockdown rules mean sex banned in homes if you dont live together - The Scottish Sun [Last Updated On: August 5th, 2020] [Originally Added On: August 5th, 2020]
- Exclusive: Parler Rejects 'Hate Speech' Bans, Will Fix 'Awkward' 'Fighting Words' Rule - CNSNews.com [Last Updated On: August 5th, 2020] [Originally Added On: August 5th, 2020]
- Devin Nunes to Newsmax TV: Social Media Biggest Threat for Republicans This Election - Newsmax [Last Updated On: August 5th, 2020] [Originally Added On: August 5th, 2020]
- Wong's fascinating discovery of Twitter's unrevealed feature - Digital Information World [Last Updated On: August 7th, 2020] [Originally Added On: August 7th, 2020]
- Banning TikTok gives Trump cheap anti-China points but undermines his free speech chops in war with Twitter and Google - RT [Last Updated On: August 8th, 2020] [Originally Added On: August 8th, 2020]
- Instagram shadowban: What does it mean for Tacha and her brand? - Vanguard [Last Updated On: August 9th, 2020] [Originally Added On: August 9th, 2020]
- How to ensure your content is not being shadow banned on ... [Last Updated On: August 9th, 2020] [Originally Added On: August 9th, 2020]
- Malaysian allegedly involved in organ trafficking, says UK paper - The Straits Times [Last Updated On: August 9th, 2020] [Originally Added On: August 9th, 2020]
- Meghan Markle, Prince Harry, and Prince Andrew's Social Media Accounts Were Removed From the Royals' Website - Yahoo Lifestyle [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- Wicker: Time to address online censorship - The Vicksburg Post - Vicksburg Post [Last Updated On: August 10th, 2020] [Originally Added On: August 10th, 2020]
- US ban on TikTok could cut it off from app stores, advertisers: White House document - The Straits Times [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- [Managed] Shadow IT: The oxymoron you never knew about - ITProPortal [Last Updated On: August 12th, 2020] [Originally Added On: August 12th, 2020]
- Queensland government passes ban on 'conversion therapy' - QNews [Last Updated On: August 15th, 2020] [Originally Added On: August 15th, 2020]