Okta Study Finds Fraudulent Registrations and Credential Stuffing to be Top Threats to Digital Identities
- Written by Reporters
Robust and resilient Customer Identity and Access Management (CIAM) exists at the vanguard of identity security
IMG { cursor: pointer } SINGAPORE - Media OutReach - 1 February 2023 - Okta, Inc. (NASDAQ: OKTA),the leading independent identity provider, today unveiled the APAC findings of its second annual State of Secure Identity Report highlighting key areas of concern for security professionals tasked with managing digital identities, including the exponential rise of fraudulent registration, credential stuffing attacks, and the widespread use of breached credentials. Based on the data across the world from Okta Customer Identity Cloud, powered by Auth0, this report presents trends, examples, and real-world observations from the billions of identity attacks at various authentications touchpoints. Research into these Okta global customers found the following key facts and figures:- Fraudulent registrations are an ever-present and growing threat: In the first 90 days of 2022, Okta observed almost 300 million fraudulent account creation attempts, accounting for about 23% of signup attempts, up from 15% in the same period last year. Energy/Utilities and Financial Services experienced the highest proportion of signup attacks, with such threats accounting for most of the registration attempts in those two industries.
- Credential stuffing is on a record pace: Credential stuffing attacks are the most common threats to Retail/eCommerce (more than 80% login activity), Financial Services and Entertainment verticals. In the first 90 days of 2022, the platform detected almost 10 billion credential stuffing events, representing some 34% of overall traffic or authentication events. In Southeast Asia, which was buoyed by several large-scale attacks, credential stuffing accounts for the majority of identity events. The situation in Australia and New Zealand was more sanguine — normal traffic represents the majority of login events (63%), and only during a large attack does credential stuffing overtake legitimate traffic.
- Threat actors are targeting multi-factor authentication (MFA): In Asia Pacific, MFA bypass attacks are responsible for more events than signup attacks. Because of its proven merits, more application and service providers are recommending or requiring MFA. As attackers become more sophisticated at targeting this important defensive measure, it's critical that MFA be implemented correctly and that strong secondary factors are chosen.
- Every company faces unique challenges. The threats facing any particular application or service vary enormously by geography, industry, and brand prominence, among other factors. At the same time, different organizations have different risk appetites and exposures. The appropriate level of friction introduced by security measures will therefore vary on a company-to-company basis.
- Implement defence-in-depth tools that work in combination across the user, application, and network layers
- Continually monitor their applications for signs of attacks and changes in TTPs; and
- Make adjustments (e.g., tune parameters, tighten restrictions, introduce new tools, etc.) as needed.
The issuer is solely responsible for the content of this announcement.
About Okta
Okta is the World's Identity Company. As the leading independent Identity partner, we free everyone to safely use any technology—anywhere, on any device or app. The most trusted brands trust Okta to enable secure access, authentication, and automation. With flexibility and neutrality at the core of our Okta Workforce Identity and Customer Identity Clouds, business leaders and developers can focus on innovation and accelerate digital transformation, thanks to customizable solutions and more than 7,000 pre-built integrations. We're building a world where Identity belongs to you. Learn more at okta.com.
Source https://www.media-outreach.com/news/singapore/2023/02/01/196157/

