ARTICLE
7 January 2022

NY Attorney General Recommends Safeguards Against "Credential Stuffing" Cyberattacks

CW
Cadwalader, Wickersham & Taft LLP

Contributor

Cadwalader, established in 1792, serves a diverse client base, including many of the world's leading financial institutions, funds and corporations. With offices in the United States and Europe, Cadwalader offers legal representation in antitrust, banking, corporate finance, corporate governance, executive compensation, financial restructuring, intellectual property, litigation, mergers and acquisitions, private equity, private wealth, real estate, regulation, securitization, structured finance, tax and white collar defense.
The New York Attorney General recommended safeguards to defend against "credential stuffing" after an investigation found widespread cyberattacks impacting more than 1.1 million consumers.
United States Corporate/Commercial Law
To print this article, all you need is to be registered or login on Mondaq.com.

The New York Attorney General recommended safeguards to defend against "credential stuffing" after an investigation found widespread cyberattacks impacting more than 1.1 million consumers.

In the report, the Office of the Attorney General ("OAG") investigated "credential stuffing" attacks against businesses and consumers, in which hackers attempt to access customer accounts by utilizing stolen usernames and passwords from other online services. According to the OAG, credential stuffing is a common form of cyberattack. One content delivery network reported more than 193 billion attacks in 2020.

The OAG found more than 1.1 million account credentials from compromised accounts at 17 well-known online retailers. The companies were alerted and, at the urging of the OAG, took steps to investigate and protect impacted customers.

The OAG recommended safeguards designed to (i) defend against credential stuffing attacks, (ii) detect credential stuffing breaches, (iii) prevent fraud and the misuse of customer information, and (iv) respond to credential stuffing incidents. As a result of the investigation and subsequent cooperation with the OAG, nearly all of the companies implemented additional customer safeguards. The OAG also highlighted:

  • the effectiveness of multi-factor and "passwordless" authentication and bot-detection services;
  • the importance of breach-detection systems with respect to successful attacks that compromise customer accounts; and
  • the need to have a written incident response plan for responding to credential stuffing attacks.

Primary Sources

  1. NYAG Press Release: Attorney General James Alerts 17 Companies to "Credential Stuffing" Cyberattacks Impacting More than 1.1 Million Consumers
  2. NYAG Report: Business Guide for Credential Stuffing Attacks

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More