Are you Protected from Credential Stuffing?

11 October 2019 by National Bank
Credential stuffing

Are you familiar with credential stuffing? It’s a kind of cyberattack in which fraudsters use hacked credentials and automation to access your online accounts, in order to obtain your logins. This information is then sold to other criminals.

What is credential stuffing?

It’s a form of cyberattack that’s on the rise. Rather than your personal information, fraudsters target your online login credentials.

“Credential stuffing is a way to hack your online accounts. Stolen login credentials are reused in an attempt to log into different websites, in case people have used the same passwords more than once – which unfortunately happens often,” explains Marc-André Gagnon, Advisor, Cyber Threat Intelligence at the National Bank.

Fraudsters will even go so far as to automate their login attempts until they manage to find one or more winning combinations. This will allow them to steal your identity across various accounts, change your passwords and complete transactions, for their own purpose, under your name.

Who could be targeted?

“No one is safe from credential stuffing. People are wrong to think that fraudsters wouldn’t be interested in them,” adds Marc-André Gagnon. “There is interest in all data. Fraudsters aren’t interested in who you are; they’re interested in your identity. And the more an identity is used across the board, the more coveted it will be. Fraudsters want credentials that won’t attract attention when they try to open a phone account, or to resell them on the dark web, for example.”

The dark web is the part of the Internet the general public has little access to. It’s where illegal goods, such as weapons and drugs, are sold. If you’re not careful enough, your personal information could go up for sale there too.

How can I protect myself?

Rest assured, there are simple ways to protect yourself against credential stuffing.

Avoid reusing the same password. You should use a different password for each website and each platform. “It’s a really effective way to protect yourself,” confirms Marc-André Gagnon.

“These days it may seem difficult, because we all have so many accounts. That’s what password managers are for. They’re handy and easy to use: you choose a master password, and the manager memorizes the passwords for each of your accounts.”

Finally, make sure your inbox is safe by using two-factor authentication. “It’s a good way to strengthen your account security. It’s more likely to dissuade criminals. Enabling this option for your accounts should protect you by directing fraudsters elsewhere,” adds Marc-André Gagnon.

Credential stuffing isn’t the only cyberattack on the rise. Learn more about phishing and find out how to protect yourself. The more understand how fraud works, the better you’ll be at protecting yourself.

Several measures exist to protect you from fraud.

Back
Terms of use
National Bank’s virtual assistant

When using our Virtual Assistant Service (the "Chatbot"), you accept these Terms of Use, which are subject to change without notice. Furthermore, you agree to consult these Terms of Use from time to time and acknowledge that your continuing use of the Chatbot means that you have accepted any changes that may have been made. Your continued use of the Chatbot means that you’ve read, understand and agree to these Terms of Use, the Terms of Use for our website, our Online transaction services, and to our privacy policy. You also understand any other agreements that you have with us will continue to apply when you use the Chatbot.

1. Our Services and your responsibilities

The Chatbot is an automated service which is integrated into our online banking platform.

The Chatbot is preprogrammed to answer general questions concerning the use of our online banking platform solely for informational purposes. The Chatbot is not able to answer questions on personal monetary transactions or products you hold with us.

By using the Chatbot, you understand and agree that:

  • The Chatbot does not provide financial advice or financial planning services.
  • The Chatbot does not conduct any banking transactions.
  • The Chatbot may not be able to answer all your questions. Therefore, it may not be able to provide you with the information you require. You must judge whether the answer provided responds to your question accurately. In the case of uncertainty, a customer service representative would be happy to help you. You can call us toll free at 1-888-483-5628 or 514-394-5555.
  • The Chatbot is not a complaint service. You cannot use the Chatbot to file complaints. If you have any complaints, you can contact us at the number indicated above.
  • We monitor, record and store the discussion that you have with the Chatbot to improve our interactions with our clients.
  • You will not provide the Chatbot with any confidential, personal, or private information. For example, you will not provide the Chatbot with your login information, PIN or other personal banking information.

2. Limitation of Liability

You acknowledge that we won’t be liable for any losses or damages that you may suffer as a result of your use of the Chatbot, including if the Chatbot is unavailable for any reason.

We cannot guarantee that the results obtained via the Chatbot will be accurate and reliable and that the answers provided will meet your expectations.

We will not be held liable for damages you incur as a result of:

  • Any delay, error, interruption or omission on our part or any other event beyond our control.
  • Any deficiency or technical error or any unavailability of our systems and wireless networks.
  • Your failure to meet any of your obligations.
  • Any amendment to or suspension, refusal or blockage of the Chatbot.
  • Any decision or measure you take in response to information and data obtained via the Chatbot.
  • Any other damages you may incur that are not caused by negligence on our part.

3. Language

You have requested that these Terms of Use, and related documents be drawn up in English.

4. Governing Law

These Terms of Use are governed and must be interpreted in accordance with the laws in force in the province or territory where you reside. If you reside outside Canada, the laws in force and the courts of competent jurisdiction are those of the province of Quebec.

Virtual assistant