logo

Account Takeover: Expanding on Impact

ID: 10bf6919-a3c8-502f-9992-4e45ef37c92a

STIX ID: report--10bf6919-a3c8-502f-9992-4e45ef37c92a

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2020-07-27

Date Updated: 2026-04-29

...
...

Digital Shadows (now ReliaQuest) analyzed over 27 million exposed credentials collected from the open, deep, and dark web and found widespread plaintext passwords and weak hashing (predominantly MD5 and SHA1), high exposure across sectors (notably technology and food & beverage), and numerous credentials tied to sensitive departments. The report highlights how attackers use tools and services (e.g., Sentry MBA, OpenBullet, human CAPTCHA-solving and forum-sold methods) and techniques (SIM swapping, SS7 interception, malware like Cerberus) to enable account takeover, and recommends mitigations including non-SMS MFA, monitoring for leaked credentials and brand mentions, web application firewalls, secret-scanning for code repositories, and user awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.