Friday, June 27, 2025

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Application Security Security Bloggers Network 

Home » Cybersecurity » Application Security » Buyer Beware! Account Takeover Attacks Surging This Shopping Season

SBN

Buyer Beware! Account Takeover Attacks Surging This Shopping Season

by Erez Hasson on December 19, 2022

The prevalence of Account Takeover (ATO) attacks continues to rise, as the threat creeps its way to the top of the list of security concerns for organizations today. Last year, Imperva recorded a staggering 148% increase in Account Takeover attacks, as reported in the 2022 Bad Bot Report. And before we dive deep into analyzing the data from this year (look forward to that in the upcoming 2023 Bad Bot Report), let’s review two major events that have taken place recently, shaping the threat landscape as we near the end of the year.

Holiday shopping season

It would be difficult to find an online retailer, or any retailer for that matter, that did not offer some sort of special discounts during the past few weeks. Be it Singles Day, Black Friday, Cyber Monday or any other name retailers might choose for their “biggest savings” event, this is clearly the year’s peak shopping season and it has become a worldwide phenomenon. With all of these events now in our rearview mirror and the holiday shopping season just about done, it is time to take a look at how bad actors have been spending this festive time of the year. 

Techstrong Gang Youtube
AWS Hub

To no one’s surprise, they’ve been busy exploiting the high volume of traffic and transactions on retailers’ websites to commit online fraud, with account-based fraud being prevalent. And as the explosive growth in usage of Buy Now, Pay Later (BNPL) solutions persists, the risk is bigger than ever. Attackers can target a user’s BNPL account directly or choose to target a user account with a business that is authorized to charge their BNPL account, essentially doubling their chances of success. In fact, according to research by PaymentsJournal, From 2020 through 2021, payment fraud rates over Black Friday weekend increased 66% for BNPL specifically.

Throughout the entire duration of the holiday shopping season, Imperva has recorded elevated levels of Account Takeover events, rising 12% in October and culminating on Black Friday (November 25th), with a 66% increase in Account Takeovers. Another notable increase was recorded on October 26th, just a month ahead of Black Friday, as Account Takeovers increased by 29%. Combined with the overall rise in events that began in early October, this further demonstrates one of the key trends highlighted in Imperva’s The State of Security Within eCommerce in 2022 Report – early holiday shopping. The report predicted attackers will catch up with shoppers looking for early holiday savings and a better selection of items, and that in turn, we will see an increase in attacks around mid to late October.

ATO Retail Events Per Day

It wasn’t all about shopping

Another major event that has captured the attention of millions around the globe is the World Cup football tournament. As is the case with many other major sporting events, sports betting websites are bound to see an increase in user activity and transactions – Forbes has reported that gamblers are expected to wager more than $160 billion during the tournament. This makes sports betting websites a hot target for bad actors attempting to take over user accounts for the various forms of currency stored within them.

While the games have only officially kicked off on Sunday, November 20th, Account Takeover attacks have been rampant as early as the first week of November, as can be seen represented by the spikes in the chart below. As we neared the kickoff date, the frequency of attacks has increased, and so has their intensity, spiking some 27% on November 21st and peaking on November 25th.

ATO Sports Betting Events Per Day

Mitigate the risk of Account Takeover with Imperva

Imperva provides login protection without affecting your legitimate user traffic and with no added latency. Account Takeover Protection enables fraudulent behavior investigation and detection by bringing the focus to the login functionality as a whole. Utilizing a proprietary, multilayered detection process, it accurately determines if the interactions with your website have the characteristics of an account takeover attempt with pinpoint accuracy, stopping malicious account takeover attacks before they even have a chance to reach your infrastructure. The intuitive dashboards provide clear visibility and actionable insights into attack attempts, leaked user credentials, compromised user accounts, and successful login attempts, while user behavior anomaly detection points out accounts at risk of fraudulent activity.

Account Takeover Protection is part of Imperva’s market-leading Web Application & API Protection (WAAP) solution. Start your Application Security Free Trial today to protect your login pages.

 

WORLD CUP™ is a trademark of the Federation Internationale de Football Association (“FIFA”).

The post Buyer Beware! Account Takeover Attacks Surging This Shopping Season appeared first on Blog.

*** This is a Security Bloggers Network syndicated blog from Blog authored by Erez Hasson. Read the original post at: https://www.imperva.com/blog/buyer-beware-account-takeover-attacks-surging-this-shopping-season/

December 19, 2022December 19, 2022 Erez Hasson Account Take Over, advanced bot protection, Application Security, bad bots, Shopping
  • ← Lessons Learned in 2022
  • Ostrich Cyber-Risk Welcomes Chip Whitmer as Vice President of Software Development  →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Securing Vibe Coding: Addressing the Security Challenges of AI-Generated Code
How to Spot and Stop Security Risks From Unmanaged AI Tools

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

Scattered Spider Targets Aflac, Other Insurance Companies
WhatsApp BANNED by House Security Goons — But Why?
N. Korean Group BlueNoroff Uses Deepfake Zoom Calls in Crypto Scams
Heightened Cyber Threat from Iran Sparks Urgent Calls for Vigilance and Mitigation
WormGPT Variants Powered by Grok and Mixtral Have Emerged 
JWT Security in 2025: Critical Vulnerabilities Every B2B SaaS Company Must Know
Black Hat SEO Poisoning Search Engine Results For AI to Distribute Malware
Feel Reassured with Advanced Secrets Scanning Technologies
Threat Casting a Nation State Attack on Critical Infrastructure Scenario at CognectCon2025
OpenAI Used Globally for Attacks – FireTail Blog

Industry Spotlight

WhatsApp BANNED by House Security Goons — But Why?
Application Security Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security DevOps Endpoint Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

WhatsApp BANNED by House Security Goons — But Why?

June 24, 2025 Richi Jennings | 3 days ago 0
Scattered Spider Targets Aflac, Other Insurance Companies
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Industry Spotlight Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence 

Scattered Spider Targets Aflac, Other Insurance Companies

June 22, 2025 Jeffrey Burt | 4 days ago 0
US Pig Butchering Victims ‘Will’ Get Refunds — Feds Seize $225M Cryptocurrency
Analytics & Intelligence Blockchain Cyberlaw Cybersecurity Data Privacy Digital Currency Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence Threats & Breaches 

US Pig Butchering Victims ‘Will’ Get Refunds — Feds Seize $225M Cryptocurrency

June 20, 2025 Richi Jennings | Jun 20 0

Top Stories

Abstract Security Adds Data Lake to Reduce Storage Costs
Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Abstract Security Adds Data Lake to Reduce Storage Costs

June 27, 2025 Michael Vizard | 11 hours ago 0
N. Korean Group BlueNoroff Uses Deepfake Zoom Calls in Crypto Scams
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Malware Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence 

N. Korean Group BlueNoroff Uses Deepfake Zoom Calls in Crypto Scams

June 26, 2025 Jeffrey Burt | Yesterday 0
Fortanix Adds Dashboard to Better Prioritize Remediation Efforts for PQC Era
Cybersecurity Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Fortanix Adds Dashboard to Better Prioritize Remediation Efforts for PQC Era

June 25, 2025 Michael Vizard | 2 days ago 0

Security Humor

Randall Munroe’s XKCD ‘Interoperability’

Randall Munroe’s XKCD ‘Interoperability’

Download Free eBook

The Dangers of Open Source Software and Best Practices for Securing Code

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2025 Techstrong Group Inc. All rights reserved.
×