Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The Rise of the Machines: Cybercriminals are cashing in on their ‘Bot Army’ as attacks hit record high

by The Gurus
May 20, 2016
in Editor's News
Share on FacebookShare on Twitter

Cybercriminals are driving up fraud levels to a record high by creating substantial armies of automated cyber robots – otherwise known as Bots. ThreatMetrix, The Digital Identity Company, has today released its Q1 Cybercrime Report revealing that 311 million Bot attacks were detected and stopped over a 90 day period.
Although around for some time, Botnet attacks have become more complex, sophisticated and harder to predict than ever before. In many cases, they are mirroring the activity of normal consumers transacting online – be that banking or online shopping. Alongside the loud and fast hacks we are now used to hearing about in the news, The ThreatMetrix Network is now also seeing ‘low and slow attacks’ that are designed to evade any protection measures in place, and appear more like normal user traffic. This is making it ever-increasingly difficult for businesses to distinguish between real customers and cybercriminals and leading to millions, if not billions, of pounds of lost business in the UK.
The UK, alongside Germany and the US, remains one of the most attacked nations in the world.
How are these armies created?
When fraudsters get a new list of user credentials from the dark web, they launch a series of massive credential testing sessions that cause huge transaction spikes over a couple of days. Once a successful hit is made, those curated lists of known password and login combinations are taken to other sites to launch slower velocity attacks, which are harder to detect. A staggering 264 million attacks were detected specifically across e-commerce merchants in this last quarter alone putting online shoppers and retailers hugely at risk of a serious breach.
“These attacks are particularly hard to detect because they aren’t always picked up by traditional rate control measures. Our normal lines of defense just aren’t working. Businesses need a smarter approach that can differentiate between a human and a bot the moment they start to transact,” commented Vanita Pandey, vice president, strategy and product marketing at ThreatMetrix.
“Consumer data is everywhere. Fraudsters can create pitch-perfect attacks because they know so much about us. Businesses must become smarter at detecting the full spectrum of possible attacks, from huge automated identity testing sessions, to advanced social engineering attacks that hijack individual accounts. This starts with really understanding the digital identities of consumers so that high-risk behaviour can be detected in real-time.”
New Forms of Identity and Credential Testing
In addition to botnets testing the validity of stolen identities, The Network is seeing new ways to test credentials obtained through the dark web. Online businesses are inadvertently providing a perfect way for fraudsters to anonymously test stolen payment credentials, such as credit cards, before making a big ticket purchase.
Industries with low digital sophistication are easy targets. ThreatMetrix detected a series of £5 payments made with stolen credit cards targeting the charity sector.
Identity spoofing was also a strong attack vector in the FinTech space with fraudsters using cloaking technologies such as proxies or spoofed locations to mask their true identities and locations. This has given rise to an increase in fraudulent new loan applications.
“The challenge for digital businesses today is that cybercriminals are becoming so sophisticated at building convincing identities using a jigsaw of stolen credential pieces, it is becoming harder than ever to distinguish them from legitimate customers,” continued Pandey. “It is only by looking holistically at the context of the transaction, along with all the information we know about the user, that organisations have the power to stop fraudsters in their tracks.”    
Digital Identities, Powered by The Network
The ThreatMetrix Digital Identity Network analyses the myriad connections between a user’s devices, locations and anonymised personal information as they transact online. This builds a unique and trusted digital identity that fraudsters can’t fake. Leveraging the power of digital identities to establish trusted user behavior is the best way to authenticate user identity.
 
To learn more, download the “ThreatMetrix Cybercrime Report: Q1 2016” here.

ShareTweet
Previous Post

LinkedIn breach way bigger than expected – industry reaction

Next Post

7 modern security problems solved with Encrypted Traffic Management (ETM)

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol