ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Okta warns of surge in credential stuffing attacks

Okta, a prominent identity and access management (IAM) services provider, has issued a cautionary advisory regarding a notable escalation in the frequency and scale of credential-stuffing attacks targeting online services. The company highlights that these unprecedented attacks, observed within the past month, have been facilitated by the widespread availability of residential proxy services, lists containing previously compromised credentials (referred to as ’combo lists’), and scripting tools.

 

The alert follows a recent advisory from Cisco, which underscored a global surge in brute-force attacks targeting various devices, including Virtual Private Network (VPN) services, web application authentication interfaces, and SSH services, dating back to March 18, 2024. In its observations, Talos noted that these attacks predominantly originate from TOR exit nodes and various anonymizing tunnels and proxies, affecting VPN appliances from multiple vendors and routers from notable manufacturers.

 

Okta’s Identity Threat Research detected a significant increase in credential stuffing activity against user accounts from April 19 to April 26, 2024, likely originating from similar infrastructure. Credential stuffing, a cyber attack method, involves using credentials from one data breach to access unrelated services. Okta emphasized that the common feature across recent attacks is the reliance on requests routed through anonymizing services such as TOR, with millions of requests also funneled through residential proxies, including NSOCKS, Luminati, and DataImpulse.

 

Residential proxies (RESIPs) are networks of legitimate user devices misused to route traffic, often by installing proxyware tools on devices, effectively enlisting them into a botnet. Okta elaborated that malicious activities can ensue when users consciously download proxyware or when their devices are infected with malware without their knowledge, turning them into unwitting participants in botnets.

 

HUMAN’s Satori Threat Intelligence team recently disclosed over two dozen malicious Android VPN apps that transform mobile devices into RESIPs via an embedded software development kit (SDK) featuring proxyware functionality.

 

In response to these threats, Okta advises organizations to enforce strong passwords, enable two-factor authentication (2FA), deny requests from suspicious locations or IP addresses with poor reputations, and support passkeys to mitigate the risk of account takeovers.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543