Akamai: 43% of 17B login requests tracked via Akamai platform in November and December involved credential abuse, with bots using stolen login credentials
Phil Muncaster / Infosecurity Magazine :
Context & Ripple Effects
Akamai sits in a rare vantage point for this number: its platform processed 17 billion login requests over November and December alone, and bots replaying stolen credentials accounted for 43% of them. The finding lands months after a Google and UC Berkeley study quantified where those credentials come from — billions leaked via third-party breaches, millions more via phishing and keyloggers — closing the loop between credential theft at scale and automated abuse of login endpoints.
Akamai kept measuring: by mid-2019 it counted 55 billion credential stuffing attacks between November 2017 and March 2019, confirming this was not a seasonal spike but the baseline shape of attack traffic against login forms.
First-order effects
- Enterprises running consumer login flows face a majority-abuse traffic mix, forcing authentication infrastructure to distinguish humans from credential-replay bots on every request rather than treating logins as trusted events.
- Akamai's own security business gains the proof point: platform-scale telemetry is the sales asset, positioning it against point-solution bot vendors for web application defense budgets.
Second-order effects
- As login endpoints harden, attackers shift upstream to where credentials are harvested — phishing kits and info-stealer distribution — which Akamai's later DNS telemetry on USPS phishing sites outdrawing the real site shows becoming industrialized.
- A liquid resale market for stolen logins emerges downstream: with studies finding 15 billion credentials circulating on hacker forums, pricing per financial-services login turns breaches into a supply chain feeding stuffing operations like this one.
Third-order effects
- If most login traffic is hostile by default, password-based authentication structurally loses viability as a trust signal, pushing the industry toward breach-corpus screening, multi-factor defaults, and behavioral bot detection as table stakes.
- IBM's 2024 finding that intrusions increasingly start with legitimate credentials rather than network exploits suggests the endpoint of this arc: identity itself becomes the primary attack surface, and defense spending migrates from perimeter tools to identity threat detection.
The trend: Attack economics are shifting from breaking into networks to logging in with stolen identities, making credential abuse measurement a recurring headline metric for edge providers like Akamai.