Gaming

Akamai reveals hackers targeted the gaming industry with over 12 billion attacks in 17 months

According to the Akamai 2019 State of the Internet / Security Web Attacks and Gaming Abuse Report, hackers have targeted the gaming industry by carrying out 12 billion credential stuffing attacks against gaming websites within the 17-month period analysed in the report (November 2017 – March 2019). This puts the gaming community among the fastest rising targets for credential stuffing attacks and one of the most lucrative targets for criminals looking to make a quick profit. During the same time period, Akamai saw a total of 55 billion credential stuffing attacks across all industries.

The report also reveals that SQL Injection (SQLi) attacks now represent nearly two-thirds (65.1%) of all web application attacks, with Local File Inclusion (LFI) attacks accounting for 24.7%. The report’s data shows that SQLi attacks have continued to grow at an alarming rate as an attack vector, with a spike in activity during the 2018 holiday shopping season and a continued elevated trend since that time. In the first quarter of 2017, SQLi attacks accounted for 44% of all application layer attacks.

The bridge between SQLi and credential stuffing attacks is almost a direct line. The majority of the credential stuffing lists circulating on the darknet and on various forums use data that originated from some of the world’s largest data breaches, and many of them have SQLi as a root cause. In fact, earlier this year Akamai researchers discovered a video where viewers were instructed on how to conduct SQLi attacks against vulnerable websites, and then use the credentials obtained to generate lists that can be leveraged in credential stuffing attacks against a popular online game.

“One reason that we believe the gaming industry is an attractive target for hackers is that criminals can easily exchange in-game items for profit,” said Martin McKeay, Security Researcher at Akamai and Editorial Director of the State of the Internet / Security Report. “Furthermore, gamers are a niche demographic known for spending money, so their financial status is also a tempting target.”

In one example of these attacks, criminals target popular games looking for valid accounts and unique skins, which are used to change the appearance of an item in a video game. Once a player’s account is successfully hacked, it can then be traded or sold.

Hackers place more value on compromised accounts connected to a valid credit card

Hackers appear to place more value on compromised accounts that are connected to a valid credit card or other financial resources. Once these accounts are compromised, the criminal can purchase additional items, such as currency used within the game, and then trade or sell the hijacked account at a mark-up.

“While gaming companies continue to innovate and improve their defences, these organizations must also continue to help educate their consumers on how to protect and defend themselves,” said McKeay. “Many gamers are young, and if they are taught best practices to safeguard their accounts, they will incorporate those best practices for the rest of their lives.”

Geographic highlights from the Akamai 2019 State of the Internet / Security Web Attacks and Gaming Abuse Report include:

– Nearly 67% of application layer attacks target organisations based in the United States.
– Russia is the second largest source of application attacks, but nowhere to be found in the top 10 target countries. – Similarly, China is ranked as the fourth highest source country, but not among the top 10 target countries.
– Conversely, the United Kingdom is the second highest targeted country, but only tenth on the source country list. – – Japan, Canada, Australia and Italy are all also among the countries most targeted, but not on the top 10 source list.
– While the United States is overwhelmingly the top source country for credential stuffing attacks across all verticals, Russia and Canada take the top two spots targeting the gaming sector.
– While not among the top 10 source countries for application layer attacks, Canada is the fourth highest source country for credential stuffing attacks
– Vietnam is the ninth largest source country for credential stuffing attacks but ranks fourth when targeting the gaming sector.

The Akamai 2019 State of the Internet / Security Web Attacks and Gaming Abuse Report is available for download here. For additional information about credential abuse – specifically credential stuffing – and advice for organizations facing these types of attacks, visit Akamai’s resource site.

Irish Tech News

Recent Posts

Why You Must Prioritise AI Empowerment in 2026

Most leadership teams are trying to be responsible about AI. They want clearer rules and…

2 hours ago

AI FORWARD > Supercomputing the Future: Rare Open Day at Ireland’s Most Advanced AI Infrastructure

CloudCIX, in conjunction with AlloComp, will host AI FORWARD > Supercomputing the Future, a one-day…

22 hours ago

MTU to Host National Workshop on Strengthening Rural Life and the Future of Farming

Munster Technological University (MTU) will host a major stakeholder workshop exploring the future of rural…

24 hours ago

Pendulum Summit returns Friday, January 23rd

Pendulum Summit kicks off this Friday for the 12th year, founded by Irish International rugby…

1 day ago

Accelerating Clean Transport: Tyndall Researchers Driving New Research to Integrate Electric Buses in Ireland

Tyndall National Institute was awarded six projects from SEAI’s National Energy Research, Development & Demonstration…

1 day ago

More about Irish Tech News


Irish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.


You can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news


If you’d like to be featured in an upcoming Podcast email us at Simon@IrishTechNews.ie now to discuss.


Irish Tech News have a range of services available to help promote your business. Why not drop us a line at Info@IrishTechNews.ie now to find out more about how we can help you reach our audience.


You can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.