Akamai Technologies, Inc. (AKAM)
NASDAQ: AKAM · Real-Time Price · USD
110.25
-0.50 (-0.45%)
Sep 10, 2026, 11:17 AM EDT - Market open
← View all transcripts

Investor Update

Oct 22, 2020

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Well, okay. It's actually two after, let's go ahead and get started. You are here to hear the Loyalty for Sale, Retail and Hospitality Fraud edition of the Akamai State of the Internet / Security report. Thank you all for joining. This will be recorded, the slides are available on the akamai.com site. If you have any questions, please put them in the Q&A. If you would like to use some of these slides in your own presentations, please feel free. We would love to see people using the slides from this report. I am Martin McKeay. I am the editorial director for Akamai's State of the Internet / Security team. We're responsible for the SOTI. We're responsible for other types of publications that come out of Akamai. Steve Ragan, who is the main writer and researcher for the report, works on my team.

Unluckily, he couldn't join us today because of this little thing called vacation. Instead, I'm joined by Patrick Sullivan, who many of you may have heard before. Patrick is our CTO in charge of global security strategy. How are you doing, Patrick?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Good morning, Martin. I'm doing really well. Thanks for having me. Looking forward to the session today.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

I'm also joined by Tony Lauro, who is Director of Security Technology and Strategy. Tony, what is it you really do? I don't think you're strategic, are you?

Tony Lauro
Director of Security Technology and Strategy, Akamai

I'm very strategic. Thanks for asking. Yes. It's kind of hard sometimes to figure out what I do, but I'm trying to basically help our customers figure out how to use our technology and see if it fits, as well as look at where they're going in the future to make sure that we're building new technology to match those needs. Again, just like Patrick said, thanks for having me here, and I'm looking forward to the talk.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

You're going to be doing part of the talk, so it's not like you can just sit back and listen. By the way, I fully understand. I've been in security for 20 years, but somehow I became somebody whose main job is actually going back and correcting spelling errors and putting commas and stuff in. I don't know where that came from. I wanted to start the conversation by just kind of letting people know what we're going to be talking about. We've been talking about credential abuse in different areas for quite some time. It's a really important thing. Among other things, please use two-factor authentication. In this case, we were kind of talking about two sides of the same query. We, as users, have a lot of loyalty programs that we subscribe to.

I could probably list 15 off the top of my head where I have an account at different shops, at different grocery stores, at different airlines. I'm sure that Tony and Patrick, who travel as much, if not more than I used to, have the same types of things. We, as consumers, are bouncing around between different types of accounts and have a lot of information in those. The main thrust of our actual research this time was looking at those accounts. Because if you've had an account compromise any site, there's a really good chance that at some point, that has been added to one of the lists that are out there. It's been tried against all of the different loyalty accounts.

What we're seeing is large amounts of people who have not necessarily compromised a retailer or compromised a hotel, but have some other list of passwords that have been compromised in the past, and they're trying them against your site. They're trying them against the other loyalty programs, and they compile these lists and resell them. That's kind of what we meant when we were talking about Loyalty for Sale. Patrick, do you have something to say on that?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

No, I think you nailed it, Martin. We've been kind of in hand-to-hand combat with bot operators conducting credential stuffing attacks for years. Obviously, this sector sees an outsized share of those type of attacks. I remember back in the early days of fighting credential stuffing, we first tried a WAF-based approach. I distinctly remember the first time I bumped into this was a retailer that had their own loyalty program, and they were experiencing fraud there. That's sort of where I began my journey in helping fight this type of fraud. I think this segment is a really interesting one in the battle against credential stuffing.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

That actually brings up a good point. Tony, where did you come to this from? You've had a lot of experience on this type of attack as well.

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah. I love that Loyalty for Sale, the title, sounds like an episode of "The Sopranos." Yeah, I've definitely come to this from a security operations perspective. Working over the years in financial services and mobile payments company, et cetera. Fraud and credential stuffing and even the more benign process of account creation, this is all kind of driving new ways for us to try to detect what's happening, right? The bot operators are trying to look as much like actual humans as possible. That sophistication has grown by leaps and bounds over the past four or five years. I'm coming at this from not just a technology perspective, but as I talk to CISOs and other security business leaders, they're talking about what's the adverse effect to our business, right?

If I'm a retailer and I'm selling product to bots, I'm still selling product, but there's a more nuanced business problem, which is I'm not selling product to actual users who want it. They're having to pay two or three times extra on the secondary market to buy this product. Just say it's a rare product or something that's low inventory. You're also missing out on the upsell and the relationship-building opportunity as a retailer that you might not normally get that unless you're actually communicating with the end user and not just a bot. There's a lot of different angles on this, but it's definitely something to keep an eye on, for sure.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

I wanted to finish off this part by talking about our guest essay from Jeff Borman. The fact that for us, security is a primary job skill. It is a primary concern. For many of the people who run loyalty programs, it's an extra cost. It's something they don't necessarily want to spend money and time on. That doesn't just apply to travel. That applies to anybody who's doing a lot of these types of programs. It's a little scary when, for us as security professionals, to think about it and know that, hey, this may be second or third-tier priority for a lot of companies who deal with it, but it really is something that needs more attention. Credential abuse is huge.

We're talking about, what, nearly 100 billion over two years for all of our customers, and 64 billion of those were directly related to commerce. If you're selling something, you're commerce. Even worse, 90% of the credential abuse attacks we saw against commerce were directly against retail customers. It's not a little problem. If you look at June 15th, you're seeing just against a commerce customer, or actually a set of commerce customers, 230 million credential stuffing attacks in that one day. Patrick, how do people actually even count that many attacks in one day if they're a merchant?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yeah, hopefully, they don't have to. I think this is an area where prevention is certainly preferred to a reactive approach. The volumes build over time. Every year, these grow. I think the important part is we're getting better telemetry. These may have been hidden years ago when these were taking place, and there weren't systems in place to be able to quantify the volume. I think that's maybe the optimistic look at this is we've got a much better tooling system to be able to see the, and track the volume, for an attack that maybe five, six years ago was not quantifiable for most organizations.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Part of the issue I think we need to do is, I actually forgot to define what we even mean by credential abuse or credential stuffing. Tony, does it have a few other names that you can think of, and what does that mean to you?

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah. Credential abuse is kind of a broad term. Credential stuffing or password stuffing, these are all different processes attackers use to validate if one of the credentials that they've downloaded from another previously exposed username and password list, if it works on the site that they're testing it against. All of this, the end goal, especially in hospitality, and even in retail, the end goal is ATO, account takeover, right? So, whereas, credential abuse and credential

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Stuffing

Tony Lauro
Director of Security Technology and Strategy, Akamai

validation, if you will, is what they should be calling it. Credential validation, that process might, for a certain group of attackers, that might be their main goal. They don't want to get into logging in as someone else and trying to steal loyalty points. They might just want to validate credentials. Now that I have a valid account on a travel site or a retail site or a hotel site, now I can sell that for five times as much as I bought the whole list for, right? That's part of the process. As you look at credential abuse in loose terms, it's essentially the process of validating accounts. The next step after validation is to log in as the user and then to commit fraud, some kind of fraud.

It's the first early stage, and that's why Patrick was saying detection is so huge here. Imagine with billions and billions of credential abuse attempts, if you were getting a Netcool alert or a SIEM alert every time there was a credential abuse attack, right? This can't be managed by your typical infosec processes. You've got to put automation in front of this because, frankly, the attackers are using automation as well.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Where do all these attacks.

Patrick Sullivan
CTO of Global Security Strategy, Akamai

This can-

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Oh, go ahead.

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yeah, just to build on something Tony said, I certainly remember, again, in the evolution here, years ago, we would often get a request for help from a customer, basically saying, "I'm under a DDoS attack." That's how this would manifest itself, where maybe a adversary was not savvy enough to throttle their attacks, and they would bring down the whole authentication service based on the intensity with which they were testing credentials. I think that kind of just speaks to the lack of visibility that the industry had at that time. I think these days people are more educated about the threat, and they know what to look for.

If we do get that call for help, it's much more frequently the correct diagnosis of the problem, where people are calling in saying, "Hey, we're having a credential validation or a credential stuffing attack," versus not understanding why the authentication service may have fallen down as the first indication of a problem.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Where is it all coming from? Quite frankly, most of it's coming from the U.S. What we're looking at here, by the way, I do want to be clear, we're looking at commerce attacks. U.S. is the greatest source, and it's often the greatest target of commerce attacks. You can see in the main column how many of these we're seeing just against commerce over two years. You also can see on the right, what we say here is global rank, but what we really mean is overall ranking. U.S., it's not just commerce, it's everywhere. China, it's not just commerce, it's everywhere. One last thing to be really clear about here, when Akamai is talking about the source of an attack, we're talking about the last hop before it hits Akamai servers.

We're talking about not necessarily who's in control of it, but where the traffic itself is coming from. Attribution, all of the things related to that are a conversation that, yeah, we probably don't have time for today or even this year, quite frankly, because of how complex it can get. Tony, can you give a couple hints of how complex attribution is in a case like this?

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah, it's definitely tricky. As you mentioned, this is not necessarily recording where the threat actor is located, but rather where the host that they've compromised that they're using for their attack is located. We've seen some interesting trends kind of rising over the past 18 months. One of them is the number of attacks that are originating from a single-use IP address. This is the first time we've seen it before. That makes it incredibly difficult to try to perform attribution, because really you're just seeing it for the first time. You've never built any kind of data set around what that activity has been from that particular host. Also, if I'm attacking a U.S.-based retailer, I certainly don't want to come from some random data center in Croatia. I want to be coming from where the customers are coming from, right, in the United States.

These hackers are building this infrastructure of proxy networks and different systems to use to look like real users. Another trend that's been kind of interesting to track is they're going so far as to compromising home-based IoT systems, right? Because these are all just running embedded Linux. If I'm an attacker and I'm coming from the home IP space of Tony Lauro in Dallas, Texas, for instance, on AT&T internet service, for instance, as a defender, it's much more difficult for me to positively say, "Hey, this is not Tony coming in trying to make a purchase," because it looks so much like a real user. Again, the attackers are really trying to look as much like a human, real user from the same geographies within the same system sets, and AS numbers that you would typically see real user traffic coming from.

Attribution is definitely very difficult. The other point there, the last point is, okay, you attribute this problem to a threat actor, and maybe you issue some kind of take down or whatever the case is. The problem is that there will always be more, there's always going to be new threat actors, and there's always going to be a new threat. You have to think of things, at least we do, certainly think of things from a big picture perspective. We're trying to stop the onslaughts, and if there's any other attribution that can be made from there, we're happy to help with that as well. Our goal is to stop the big problem that are facing our customers first.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

I had moved on the slide, and I just wanted to point out something that Tony has already kind of hit upon, which is the U.S. is the biggest target. We're also the biggest importer, if you will, of attack traffic. I also find it interesting that China is a big importer of attack traffic. They have more coming into China than they did going out of it. Again, as Tony said, this is where the companies are headquartered. Even though the servers might be all over the world, the company headquarters are in these different countries. Boy, does network analysis get really hard in the modern age. Moving on a little bit, let's actually get into specifics. We have here an actual, well, not live now, but this was one of the sales of credentials that was found as we were researching this.

Quite frankly, the criminals aren't picky. They'll sell anything. They'll test it against systems. The two things to really be aware of with this one is, first of all, look at exactly how cheap it is to buy these accounts. You can get an account that's guaranteed good for $6. This is not a super expensive account. There are some where you can get thousands of these accounts. In this case, it's one that's guaranteed. The other thing to notice is this merchant had been active for over a year at the time that we took the screenshot. This dark market has been shut down since then, so obviously they're not still active. Patrick, you have any thoughts on who's selling these things and what they're doing?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Well, to say that they're not still active, maybe qualify that with in this form, right? I think this is a profession

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

true.

Patrick Sullivan
CTO of Global Security Strategy, Akamai

for some of these folks. That's part of the business, right? There's destruction of infrastructure, and then they just move to the next piece. I think you nailed it. We don't want to overthink this. These are profit-motivated attacks. As Tony touched on, there's an ecosystem that often relies on different specializations. The people that were responsible for what we saw on the first screen, the massive billions of requests that validate those credentials, they're then selling that on to the next member of that ecosystem, right, in the life cycle of that attack.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Again, another example of how these are being sold. In this case, though, instead of selling an access to an account where people could order groceries and then go pick them up, they're offering up a discounted gas prices. The thing to be aware of here is that the buyer is taking on a certain amount of risk when they're doing this, because, well, they actually have to physically be there to take whatever gas or groceries. Yeah, that's a little bit of risk, I would say. You notice that's the same seller, by the way. Here's where it gets interesting is when we're talking about loyalty cards, where we're actually seeing it used for the points. 10,000 Hilton Honors points. Tony, do you travel much anymore? Do you have any idea of how many nights that you might be able to get for that?

It's only going to cost you $3 for the account.

Tony Lauro
Director of Security Technology and Strategy, Akamai

You typically can get a night's stay from 15,000 to maybe 30,000 for a really nice room, 35,000. This is definitely something where there's a direct benefit and a direct risk to the person who's using this, right? What we see is that many times the threat actors are basically trying to just be in part of this. Nobody wants to own this whole process of credential validation and then ATO and then obviously committing fraud. There are some people who are like, "Listen, you're never going to catch me. I'm in a country where it doesn't matter, and there's certainly hotels here that I can use. I'm just going to transfer these off." You can also, a lot of the loyalty points, you can transfer off to physical goods, right?

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Yeah.

Tony Lauro
Director of Security Technology and Strategy, Akamai

A gift card, products, et cetera. There's a lot of different ways that attackers can basically kind of money mule the loyalty points out of the system into something that's beneficial for them.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Yeah. What we don't show here is that there are accounts to buy that have 600,000 to a million points or more, and that's about $850. Yeah, this is lucrative for the seller. Moving on. This is where some of our discussion got really interesting because this goes beyond just selling the account. We have folks like this seller, Tetra Custom Hotel Bookings, where they're giving a 25%-35% discount on booking travel, booking hotels. They do it by either having transferred loyalty points, by abusing discount programs, having insider access, or third-party services are being abused. This is apparently, in some of the underground economies, this is really a big business. Patrick, do you hear concerns about this when you're out and about, and how much of this is going on?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

It's a large problem, right? I think Tony touched on it. There's easy ways to monetize this directly or leverage the portability that exists in these mature loyalty platforms. Maybe one other thing to think about, right? We see a variety. Anything with a login is subject to the type of abuse we're describing here. I guess maybe a difference if you were to go after credit cards versus going after loyalty. When you start dealing in moving credit cards, then you have the large fraud teams from the major credit card providers that are keeping an eye on you. Here, it's up to each individual owner of that loyalty account to track this and to combat this themselves. That also could be part of the calculation of why loyalty is so popular here.

It's not what we're talking about here today, specifically with the loyalty programs being compromised, but maybe the first cousin of that challenge is really around gift cards, right? Any retailer that offers gift cards, which are a popular choice, they face a very similar threat, where you have this automation that will attempt to identify a valid gift card that has some type of a balance so that somebody could then defraud the rightful owner of that gift card. That's also something that the folks in this space, a challenge that they all face as well.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Good point. How do they get a lot of this? Where are the attacks? What types of attacks are leading to some of these compromises that create these large groups of accounts? Quite frankly, more than anything, it's SQL injection attacks. Some of these sites might have some poor hygiene in their code, and that means that an attacker can get to them. SQL injection is almost 79% of all of the attacks that we saw against commerce. Commerce is, what? The single biggest group, I think, for this type of attack. 3.4 billion, that's just SQL injection attacks against commerce. Tony, you want to take a quick second and kind of explain how people use SQL injection to get to what's behind the site?

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah. What's interesting about this is that SQL injection has kind of always been one of the top attack types that we've seen. The OWASP Top 10 has included it for quite some time. What's interesting is closely following that is normally local file inclusion and remote file inclusion. One is gaining access to a file that you probably shouldn't have access to on a web server, and the other one is making the web server execute a remote file that exists somewhere else. All of this is really based on the principle of even if the database on the back end is secured, it's meant to take these SQL queries, right? Because that's what the front-end app is allowing it to do. Oh, yeah, that same database is probably being queried by other systems.

Even if another system's not exposed to the web or exposed to a particular vulnerability, if I can use SQL injection to query that database and get access to data that may be hidden behind another application that is more secured, now I've got the best of both worlds, right? That's why you see these things, SQL injection and LFI and RFI typically at the top, because it's really showing the attacker's mindset is they're trying to get access to something they're not supposed to have access to. That's typically why you see that as a top attack vector.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

I'm going to hit the next slide relatively quickly, because it shouldn't come as a surprise if you saw the earlier slides and heard what we said. The U.S. is the top target, period. This goes for web application attack as well as everything else. It's where many of the customers we have are headquartered. It's where many of the customers that are doing online. You see the growth in U.K. and Germany and other places. Where is it coming from? This one was a little surprising. Russia. We're seeing it coming out of Russia. We're seeing it out of the U.S. Seeing Russia take that top spot was a little surprising. I think that in large part, that comes back to what we call bulletproof hosting.

Either one of you want to take a stab at explaining what bulletproof hosting is, or should I go for it?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yeah, Martin, it's pretty straightforward. I think in many countries, if there's a complaint about an organization hosting nefarious activity, there's a process to decommission that activity. There are other areas where attackers, as long as they maybe don't attack targets in their own geography, they're protected, essentially, from those type of takedowns. Martin, maybe just to give a glass half full on the breakdown of these web app attacks, it's interesting that cross-site scripting has worked its way down the list. I think there's a bit of optimism there where what maybe that we're seeing is some of the IDEs and tools that developers leverage, as those are more automated today, some of those now will force a developer to use kind of a safe method.

If they use an unsafe method, in some cases, they have to actually explicitly include something in that language that acknowledges the danger there, right? That could be why some of these things are being addressed and they're declining in popularity from attackers. I do feel like we are making progress in the software development life cycle, and maybe we're seeing that play out in terms of the popularity of some of those mechanisms we see.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

In the same spirit of talking about the positives, the Netherlands used to be one of the single biggest offenders. I hate to say it that way, single biggest sources, and because of bulletproof hosting. Over the last few years, the law enforcement agencies there have done a lot of work to kind of shut some of those down. We're seeing, obviously they're not number one or two, which is where they used to be a few years ago, almost every single report. That's a good thing. One of the things that Tony mentioned earlier is, where are these attacks coming from? Let me stop here for just a second, saying, if you've got questions, please put them in the Q&A. We'd love to answer your questions.

We are kind of coming towards the end, so anything you want to know, let us know. Back to this particular issue. This is how it happens. This is the raw material for much of the ecosystem where ixigo got compromised. They lost 17.204 million records, and those are out. Again, as Tony mentioned, they get used to fuel attempts to log in and create validated databases. That's what this is all about. That's where this all starts. Tony, you want to elaborate on that a little bit?

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah. As I said before, I think what's interesting here is that there's no shortage of other organizations that are getting breached, right? I think one of the main goals is, and certainly from an Akamai perspective and our customers, we don't want your database, through SQL injection or whatever other means, to be compromised and end up as part of this list. One thing that's happened over the years, if you remember, you used to have a unique username, like ladiesman227, right? That wasn't mine, but just as an example. Now all of your usernames are generally standardized on your email address, right? Which is, of course, unique to you and your own email, but it's also not private. It's something that is freely shared to the world. Now, 50% of the username and password combination guess process is already done.

If you can take, and this is where password stuffing comes in, you could take a single email address and try the top 25 most used passwords, and if one of those hit, and certainly if you've used that email address and a specific password somewhere else, what are the odds that you're using the same password on this other site that the attacker's testing against? That's what the attackers are hoping for. Based on the results that we see, it works, right? People reuse passwords all the time, that's what's kind of fueling this in the first place. The question would be, what can you put on top of that authentication process to better secure the user account? That's the question that everyone's pointing at right now.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

I think this is where I say, please use multi-factor authentication wherever it's offered. Please use a password vault and randomize passwords anywhere you can. That's off my soapbox now. At the end here, we kind of wanted to take this a little bit different direction, because there's been a lot happening since we cut off the data for the SOTI. Extortion DDoS, ransom DDoS. Patrick, I'm going to hand it to you because I think you're better suited to explain what's been going on and what's happening on that than I am.

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yeah, absolutely. I think things have gotten really interesting on the DDoS front. Unfortunately, right after the interval here we had for the SOTI, so the data here probably won't reflect what's been happening. I think as we saw 2020 begin to emerge, there was a lot of concern for many of the organizations that I work with that we're really dependent on remote access now in a way that we weren't before. We want to make sure that that is protected with always-on DDoS mitigation. That seemed to be where everybody was focused. The good news is we haven't seen that become a major target, so we're not seeing targeted campaigns to take out remote access, even though organizations are more susceptible to that this year.

What we have seen is probably the most sustained and most organized DDoS extortion campaign that we've seen in years. Really, this is a really straightforward attack. It's send a sample DDoS attack or reference a successful DDoS attack that you've been able to commit against another organization. Follow that up with a note to the organization requesting some Bitcoin against the threat of those attacks persisting. When we say that this adversary is more organized, years ago, we would see the DDoS for Bitcoin campaigns, and the extortion attempt would come in on a chat session with a customer service representative who was ill-equipped to know what to do with that. The chances of that getting to the right team within the organization were low.

We see a lot of recon these days where they're clearly on LinkedIn, and the extortion note goes directly to somebody who can action that, who knows what that threat is all about. The attacks have been as high as the hundreds of gigabits a second. These aren't record-breaking attacks that are causing us to rewrite or redesign anything. They're pretty manageable if you have cloud protection. These are big enough that if you don't have robust DDoS mitigation services in place, 100 gigabits a second will do damage, particularly as they're mixing in nine or 10 different vectors as part of that. It's certainly not all bark and no bite from these campaigns. There's been follow-through. Maybe something else that's remarkable about it is just the breadth. Typically, we'll see these campaigns focus on one vertical.

We saw people using the same names as these groups purport to be two years ago, but they only went after a set of financial services organizations in a limited geography. This campaign has, according to the FBI, more than 1,000 organizations have been targeted. It's across verticals, across geographies. That has been remarkable to follow just how pervasive these adversaries have been.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Tony, you've been dealing with this a lot as well, haven't you?

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah. I remember in 2015, we saw a lot of activity from groups like OurMine and Armada Collective and DD4BC. Some of those groups are part of this current active campaign. What is kind of speaking to what Patrick mentioned, there is a lot of sophistication here. One, just it was really surprising to us that they're actually getting these emails directly to the people who need to see them. As Patrick mentioned, we kind of joke sometimes too, like, yeah, if you're sending an extortion note, you can't send it to someone who has no control over anything at the corporation. You have to send it to the people in charge or the people who are directly in that line of reporting. Sure enough, they've been doing that.

When you start to track the extortion process, like who's paid what to what Bitcoin wallet, et cetera, that's where it gets a little bit more interesting because, in some cases in the past, we saw an extortion note that was emailed out, and the groups were so disorganized. It's like, October 21st came and left, and we didn't get attacked. Well, it's because the extortion group forgot to come back and attack you as they promised. They're doing this to thousands of different people at the same time. They can't really manage that. This time around, it's been a lot more cooperative, so to speak, in terms of how they're working, assuming it's more than one person working this process across the group.

The other thing too is that there's no guarantee that if you pay, they're not going to attack you, or that if you pay, they're not going to say, "Hey, they've already paid. Maybe they'll pay us more if we threaten them again." You know what I mean? Also the copycat groups, it would be very easy for an attacker to say, "Hey, here's who we are," and points to some article that talks about an actual group that's doing DDoS extortion. Pay money to this Bitcoin wallet. Sure enough, if you track those as well, those people are getting paid from time to time.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Well, actually, Tony.

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

You bring up a very important point there, is they claim to be this group or that group that have historically done these types of attacks. We really don't know. They can claim to be anybody they want, whether they're the real attacker or they're the copycat you mentioned. We have no idea who is really behind it at this point. That's going to be something that law enforcement has to figure out.

Tony Lauro
Director of Security Technology and Strategy, Akamai

Yeah. Lots of times there's some tells, maybe in the email, and maybe in what they claim to know about the group, that if you've been tracking the group for a while, what you actually know about them. When you see big changes and discrepancies across what Bitcoin wallet address they're putting into the ransom note, that can also tell you sometimes if it's part of the same campaign. Maybe they just changed Bitcoin wallets, or maybe it's a copycat group just trying to piggyback. Yeah, you're right. It is difficult to track that at a large scale.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Patrick.

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yeah, one other thing.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Oh, go ahead.

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Just one more point there. Not necessarily attributing the attack to an individual, from a law enforcement and takedown perspective, but when you look at the attacks, there are TTPs you can see there. There are things that can give you some confidence that this shows all the hallmarks of being the same group based on the techniques and the type of attack that we're seeing when they follow through. There are things you can do there to build some confidence that this is indeed the same crew, because it's unlikely that somebody else would have an attack that would look so similar. There are some things you can get there from the attack perspective to build some profiles.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

And one of the

Patrick Sullivan
CTO of Global Security Strategy, Akamai

I cut you off, Martin. You had a question.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

All right. One of the other things that you said earlier that I really want to have you come back to and highlight a little bit more, which is when we saw this five years ago, seven years ago, it was mostly against finance. This, in some ways, started against finance, but then it's expanded. Could you talk a little bit about that and why it's not just one vertical, everybody's being targeted by these groups right now?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yeah. That's true. It's hard to speak to their motivation. I guess maybe some organizations go whale hunting. Maybe they assume that going after the world's largest financial services organizations could net them larger kind of single payouts. Based on the pervasiveness of this campaign, it seems like they're at this more from a volume perspective. Certainly they're going after those type of targets in finance, they quickly pivoted to other verticals, right? They appear almost to have a CRM, where they're so methodical, they're working kind of vertical by vertical. We've seen that in limited perspectives before. Typically, that kind of fizzles pretty quickly. We've watched where you'll start getting calls from a vertical, the next week it'll be a different vertical.

We've seen that in the past, but this one, just much broader in their targeting than we historically see.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

That actually brings us to the end of the general discussion. If you've had any questions, please type them in now and we'll answer what we can. As we're kind of closing this off, Tony, I'll let you go first. What are the thoughts you want people to take away from today's discussion?

Tony Lauro
Director of Security Technology and Strategy, Akamai

Well, I think the biggest thing for me is that the attacker toolset and tactics and ecosystem has continuously been growing. The types of attack tools, even in the case of DDoS, every once in a while, we'll see a very novel DDoS attack that has different attack vectors we haven't seen or maybe they're mixing multiple attack vectors, et cetera. When it comes to retail and hospitality, especially from the fraud perspective, it's a lot more bespoke. They're not trying to take down a system. In fact, what they're trying to do is interact with the system as though a normal user would. Right? There's one thing to say, "Hey, I want to get superuser access or root access on a system and download a database." That's one flaw.

More often than not, it's a more nuanced approach to trick you into thinking you're communicating with a valid user account. Right? This is where identity protection and multi-factor authentication and things like that kind of fit into this big picture, because just knowing if it's a bot or a user, heck, there's a lot of this communication that, especially for credential abuse, that happens over APIs. In fact, to a tune of four or five times the amount of credential abuse attacks, we've reported this in previous SOTIs, is targeting mobile APIs. The basic reason is, one, because you assume that the API traffic is machine to machine or application to machine traffic, from your mobile application, and you're logging into the loyalty site, for instance. The attackers take those calls, and they make something different happen over that API call.

As you look at how attackers are expanding that process, they're really trying to, again, integrate more with what a real user looks like and then take advantage of the things that they can under that assumption.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

We've got one question so far from Andre. "Can we discuss the recommendation for two-factor authentication methods for loyalty programs?" From my point of view, it's not necessarily that a consumer can enable this, but it's that if it's being enabled, we should be taking advantage of it as consumers. Patrick, I'm going to turn this over to you. What should the people responsible for the loyalty programs be looking at instantiating and making accessible for end users like you and me?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

This is where sort of the battle between user experience and security comes to a head, right? Certainly, application-based MFA is not perfect. It would certainly make things more difficult for the adversary. Many organizations may not want to do that for everybody. I think we're working with our customers to help give them signals around the risk of a request so that maybe you get into more of the model where maybe you start with sort of a risk-based step-up, where I typically am traveling 80% of the time, but the last couple of months, I am pretty much locked into a particular geography and network. If all of a sudden I were to pop up in a different location, that would be risky. Along with some of the indication, is it a human? Is it a bot?

I think that's where we're trying to partner with our customers to strike that balance between friction and applying that friction at a smart point of interaction selectively.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

But general mix

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Wherever we can introduce that MFA, that would be helpful along the way.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

Do you have any closing thoughts, Patrick, beyond that?

Patrick Sullivan
CTO of Global Security Strategy, Akamai

Yes. I think, looking at this report, Martin, I think you pulled together an interesting report, thank you and Steve for the research there. It correlates with other trends that I see. Everything we've talked about today has been attacks targeting the web front end of the business. Given everything that's happened in 2020, there's a lot of face-to-face interactions that can't take place, but everything web-related is off the charts, right? The traffic is breaking records. I think every one of the types of web attacks that we measure, as you highlighted here, they're all up. Sometimes we'll see these dips in credential stuffing where it slows down for a bit and then picks up, but we haven't really seen that cessation in attack volume occur. I think that correlates what we see.

The other thing that just jumps right out is if you look at the Verizon DBIR, it just seems like authentication is the preferred vulnerability or weak point that people are targeting, right? Account brute forcing, whether it's to get into the network for employees or on the consumer side that we're highlighting here, that's where the breaches tend to be occurring. It's no surprise that we're seeing the increase here.

Martin McKeay
Editorial Director of the State of the Internet / Security Team, Akamai

I'm always for giving props to the folks over on the DBIR team. They're friends. We help contribute to some of that data. Glad you brought that up. My closing thought, a lot of this goes back to the multi-factor authentication and the need for password vaults. It just does. That's from a consumer side. We can't necessarily rely on everybody to be good from the consumer side and use complex passwords. They should be using password vaults. I use one, you use one. Most of the people on this call probably use one. We need to encourage that more.

On the other side, we also need to encourage more companies to use multi-factor authentication of some form, even if it's just, "Hey, I'm sending your phone a text," which, yes, there's lots of ways to get around it, but even that is one more hurdle the bad guy has to overcome and makes it that much more expensive to compromise an account, and therefore makes it less likely that they're going to try those accounts. Retail and travel and hospitality are some of the biggest targets around. This is something that's indicative across multiple types of companies. As a career path, security professionals need to be pushing that at companies that have remote logins as much as possible.

gentlemen, thank you very much for joining me on the call today and sharing opinions with everybody. You can find more about the Akamai State of the Internet / Security report at akamai.com/soti. I was serious, we have put the slides out from this presentation. Please use them. We would love to see people using them themselves. Patrick, have a good rest of your day.