Security

Credential Theft


Credential theft is a high risk for organizations today. Forgotten passwords, phishing E-Mails and more can lead to credential theft. Read more to find out how to mitigate this risk.

The theft of credentials is one of today’s risks to information security that significantly increased with the rise of social engineering. Cybercriminals use credentials to intrude the infrastructure of organizations. They can then leverage this access to deal more damage.

The interactive version of Verizon’s Data Breach Investigations Report (DBIR) illustrates that credentials were the #2 data type that led to data breaches in 2021. The usage of stolen credentials is one of the top attack vectors across espionage, financial, and other motives of cybercriminals [1].

A line graph about Breaches By Data Type Over Time. The x-axis displays years from 2010 to 2021. The y-axis displays percentages from 0% to 80%. There are 15 breach types listed: Bank, Classified, Copyrighted, Credentials, Digital certificate, Internal, Medical, Other, Payment, Personal, Potentially, Secrets, Source code, System, Virtual currency. There is text that states "If a breach is defined as an incident that results in the confirmed disclosure - not just potential exposure - of data to an unauthorized party, then a variety of data types must be involved. Understanding what varieties are being breached can give us insights of what types of data we most need to protect in our own organization." Most breaches start at below 20% and fluctuate over the years ending at still below 20%. Payment type starts at 80% and descends rapidly over the years to end up under 10% in 2021. Credential type starts at 35% and fluctuates before spiking after 2016 and ending at 45%. Personal types start at 25% and spikes in 2015 ending ay 45% in 2021.

Information Security Awareness

Organizations should train their employees to be aware of their responsibilities towards information security. Teaching employees to detect social engineering attempts like phishing or vishing will increase their protection from credential theft on a personal level. Explore our free courses about Awareness.

Multi-Factor Authentication

Organizations, as well as employees as private persons, should not rely on passwords as a single factor to authenticate a service or account. Instead, using a strong authentication involving two factors of different categories (e.g., a password plus an authentication token or a PIN plus a fingerprint) is highly recommended. This way, a cybercriminal needs to circumvent an additional protection level even when he was able to steal credentials.

According to the Microsoft Digital Defense Report 2021, multi-factor authentication (MFA) prevents 99% of credential theft attacks [2]. However, the latest phishing campaign targeting Microsoft customers might put a damper on this statement [3].

Identity Threat Detection and Response

Organizations could reduce the attack surface for credential theft by safeguarding systems, accounts, and credentials with an identity threat detection and response (ITDR) solution. Highlighted as a 2022 trend by Gartner [4], these solutions can provide fake credentials on endpoint level and conceal real data. They can also provide detection abilities in case cybercriminals are already exploiting stolen credentials or misuse privileges. ITDR tools are especially helpful in organizations with a high number of non-human identities to manage.

Recommendation

Check if your organization is well prepared for credential theft:

  • Are cybersecurity awareness trainings regarding social engineering (e.g., test phishing mails) embedded in every employee's daily work?
  • Is a multi-factor authentication established for all critical accounts and services?
  • Are your identities managed across on-premises and cloud assets, including users, applications, serverless functions, and containers?

Need help mitigating the risk of credential theft for your organization? Contact us for more information.

Sources

Micaela
October 23, 2023