{"id":3670,"date":"2018-11-07T12:42:50","date_gmt":"2018-11-07T16:42:50","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=3670"},"modified":"2018-11-07T12:42:50","modified_gmt":"2018-11-07T16:42:50","slug":"credential-stuffing-led-hsbc-data-breach","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/","title":{"rendered":"How Credential Stuffing Led to the HSBC Data Breach"},"content":{"rendered":"<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2734\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\" alt=\"How Credential Stuffing Led to the HSBC Data Breach\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-540x270.jpg 540w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-162x81.jpg 162w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Yesterday HSBC Bank publically disclosed what appears, on the surface, a relatively minor data breach. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Based in the U.K., HSBC Bank announced unauthorized users gained access to a host of financial and personal information. In an official statement to customers, HSBC Bank said: &#8220;The information that may have been accessed includes your full name, mailing address, phone number, email address, date of birth, account numbers, account types, account balances, transaction history, payee account information and statement history where available.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/solutionsreview.com\/identity-management\/identity-governance-and-administration-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"Identity Governance and Administration Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/01\/identity-governance-administration-speedbump-cta.jpg\" alt=\"Download Link to Identity Governance and Administration Buyer's Guide\" width=\"800\" height=\"225\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The accounts were illicitly accessed between October 4 and October 14 of this year. HSBC has taken steps to fortify their accounts since discovering the unauthorized access: &#8220;We responded to this incident by fortifying our log-on and authentication processes, and implemented additional layers of security for digital and mobile access to all personal and business banking accounts.\u201d HSBC Bank also suspended online access to prevent other unauthorized entries to affected accounts. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">They added: &#8220;HSBC regrets this incident, and we take our responsibility for protecting our customers very seriously. We have notified those customers whose accounts may have experienced [unauthorized] access, and are offering them one year of credit monitoring and identity theft protection service.&#8221; <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">HSBC stated less than one percent of their U.S. customer base was affected by the data breach, which may be only about 14,000 people. Compared to some of the most prominent breaches of the past two years, this breach does not compare in sheer number. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So why does data breach matter if so few people were affected? While it has not been definitively confirmed as of yet, the attack vector these hackers chose to access the HSBC bank accounts should matter a great deal to enterprises: credential stuffing.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">In a credential stuffing attack, previously stolen or leaked usernames, passwords, or other personal data are exploited to access users\u2019 other accounts on different sites, networks, or databases. This can create a cascade issue as more breaches mean more passwords exposed and thus more breaches in the future. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">About 232 million credential stuffing attacks afflict financial institutions daily and about 1 in 2,000 are successful, according to <\/span><a href=\"https:\/\/www.shapesecurity.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400\">Shape Security<\/span><\/a><span style=\"font-weight: 400\">. Also at particular risk of credential stuffing attacks are hospitality, airlines, and retail enterprises. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">At its core, credential stuffing exploits credential and password reuse. Of course, according to identity management best practices, users shouldn\u2019t reuse passwords and instead generate a unique password for every account. However, users continue to use repeated passwords quite frequently despite the warnings. Credential stuffing can severely harm your business, as users may reuse passwords to access their work accounts&#8230;including access to your most sensitive digital assets. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The HSBC data breach was relatively minor. However, a credential stuffing attack on your enterprise might not be as inconsequential. You need to take the steps to prevent such an attack from affecting your business: <\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Train your employees on the importance of secure authentication practices, and how they can participate in your identity security policies.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Ensure your employees and privileged users understand the dangers of repeated passwords. \u00a0<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Enforce a \u201cunique password\u201d culture in your enterprise, and prevent reused passwords on your employee&#8217;s accounts when possible. <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Make access management and secure passwords a consideration in any employees promotion or raise discussions. <\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Credential stuffing is the digital equivalent of thieves kicking in the door. Every reused password weakens your door all the more. Every unique password, on the other hand, can reinforce the door&#8230;and keep your valuables safe.<\/span><\/p>\n<p style=\"text-align: justify\"><strong>Other Resources:\u00a0<\/strong><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/access-creep-can-prevent\/\" target=\"_blank\" rel=\"noopener\">What is Access Creep? And How Can You Prevent It?<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/17-best-identity-governance-and-administration-platforms\/\" target=\"_blank\" rel=\"noopener\">The 17 Best Identity Governance and Administration Platforms of 2018<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/10-coolest-identity-security-ceo-leaders\/\" target=\"_blank\" rel=\"noopener\">The 10 Coolest IAM and Identity Security CEO Leaders<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/2018-gartner-critical-capabilities-identity-governance-administration-key-takeaways\/\" target=\"_blank\" rel=\"noopener\">2018 Gartner Critical Capabilities for Identity Governance and Administration: Key Takeaways<\/a><\/li>\n<li style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/reflection-2018-gartner-magic-quadrant-identity-governance\/\" target=\"_blank\" rel=\"noopener\">Reflection on the 2018 Gartner Magic Quadrant for Identity Governance<\/a><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><br \/>Widget not in any sidebars<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yesterday HSBC Bank publically disclosed what appears, on the surface, a relatively minor data breach. Based in the U.K., HSBC Bank announced unauthorized users gained access to a host of financial and personal information. In an official statement to customers, HSBC Bank said: &#8220;The information that may have been accessed includes your full name, mailing [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":2734,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,6],"tags":[142,125,16,112,904,905,62,76,286,397,188,70,91],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How Credential Stuffing Led to the HSBC Data Breach<\/title>\n<meta name=\"description\" content=\"HSBC Back reported a data breach which only affected a small percentage of their customers. But what can it teach us about credential stuffing?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/\",\"name\":\"How Credential Stuffing Led to the HSBC Data Breach\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\",\"datePublished\":\"2018-11-07T16:42:50+00:00\",\"dateModified\":\"2018-11-07T16:42:50+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"HSBC Back reported a data breach which only affected a small percentage of their customers. But what can it teach us about credential stuffing?\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg\",\"width\":800,\"height\":400,\"caption\":\"How to Prevent Account Takeovers in Your Business\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Credential Stuffing Led to the HSBC Data Breach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How Credential Stuffing Led to the HSBC Data Breach","description":"HSBC Back reported a data breach which only affected a small percentage of their customers. But what can it teach us about credential stuffing?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/","url":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/","name":"How Credential Stuffing Led to the HSBC Data Breach","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg","datePublished":"2018-11-07T16:42:50+00:00","dateModified":"2018-11-07T16:42:50+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"HSBC Back reported a data breach which only affected a small percentage of their customers. But what can it teach us about credential stuffing?","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/04\/password-behaviors-mod.jpg","width":800,"height":400,"caption":"How to Prevent Account Takeovers in Your Business"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/credential-stuffing-led-hsbc-data-breach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"How Credential Stuffing Led to the HSBC Data Breach"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/3670"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=3670"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/3670\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/2734"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=3670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=3670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=3670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}