October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Akamai’s 2020 Report on Fraudulent Bank Login Attacks: What the Data Shows

Akamai’s headline figure—55,141,782 login attempts in one day—was observed in 2019. Here’s what its historical credential-stuffing data means for banks and account holders.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Akamai’s widely cited bank-login figures describe activity observed from December 1, 2017, through November 30, 2019—not a verified surge in 2026. During that historical period, Akamai recorded 55,141,782 malicious login attempts against one financial-services firm on August 7, 2019. The attempts were not a count of successful account takeovers, nor a census of all attacks against banks.

What Akamai reported—and when

Akamai’s February 2020 announcement covered credential-abuse attempts observed across its infrastructure between December 1, 2017, and November 30, 2019. It reported 85,422,079,109 attempts overall, including attempts against identified API endpoints and financial-services organizations:

Measure Akamai-reported figure What it covers
Credential-abuse attempts overall 85,422,079,109 Akamai-observed attempts across the reporting period
Attempts against identified API hostnames 16,557,875,875 Akamai-observed attempts across the reporting period
API attempts against financial-services organizations 473,518,955 Akamai-observed attempts across the reporting period
One financial-services incident 55,141,782 Attempts observed on August 7, 2019

These figures are attempts, not confirmed compromises. They reflect Akamai’s customer-facing infrastructure and detection methods, so they should not be read as a global total or as a measure of how many customers lost access to accounts. Akamai’s official announcement is available through PR Newswire.

Why APIs were part of the story

Akamai reported that as much as 75% of credential abuse against financial services targeted APIs during the period. SecurityWeek described spikes above 80% in May 2019 and above 75% in October 2019. Those are historical shares, not present-day estimates. Akamai said the move toward API endpoints became pronounced beginning in May 2019, potentially as attackers sought to get around defenses applied to other login routes.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

In a separate API-focused run on August 25, 2019, Akamai observed more than 19 million credential-abuse attempts. The figure is distinct from the 55.1 million attempts against a financial-services firm on August 7.

SecurityWeek also reported that, among financial-services web-application attacks in the period, 47% were Local File Inclusion, 36% SQL injection, and 7.7% cross-site scripting. Those are different attack categories; they should not be added to or confused with the credential-stuffing login counts. See SecurityWeek’s February 21, 2020 report.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What credential stuffing means

Credential stuffing is the automated testing of username-and-password pairs that attackers have already obtained, often from a breach at another service. It works because some people reuse passwords: a leaked pair for one site may also unlock an unrelated account. As Akamai put it in its 2019 report, “Recycled passwords are why credential stuffing attacks work.”

This differs from password guessing. Instead of trying arbitrary passwords from scratch, an attacker begins with known credential pairs and may also test variations. Automation lets attackers submit many attempts, while distributing traffic across targets or stretching activity over time can make a campaign less obvious than a burst of requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to interpret Akamai’s counts

Akamai’s report used more than one way to identify credential-stuffing activity. It treated unsuccessful logins using email-address usernames as credential-stuffing attempts, and described both a volumetric method that counted login errors associated with an address and bot detections for known botnets and tools. The report cautioned that botnets can spread traffic across targets and time, potentially evading simple volume thresholds. The totals therefore depend on Akamai’s definitions, detection approach, and participating infrastructure; they are not a complete record of every attempt everywhere.

Akamai security researcher Steve Ragan, the report’s principal author, told SecurityWeek: “Criminals targeting the financial services industry pay close attention to the defenses used by these organizations, and adjust their attack patterns accordingly.” That comment and the figures describe the studied period, not a finding about banks’ current defenses or current attack volumes.

Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What bank security teams can take from the report

The historical findings point to several areas security teams can evaluate, without establishing which controls any particular bank uses today:

  • Cover API and web login paths. A login defense focused only on browser-facing pages may miss abuse aimed at APIs.
  • Look beyond simple volume thresholds. Detection should account for bot behavior and distributed or low-and-slow patterns, not just a high request count from one source.
  • Use layered authentication defenses. Strong authentication, including multifactor authentication, can reduce the usefulness of a stolen password, while bot detection and monitoring address automated attempts.

The cited material does not provide a vendor-neutral comparison or a product efficacy test, so it cannot establish which commercial control performs best.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

How account holders can reduce risk

Use a unique password for your bank account rather than reusing one from other sites. If another service is breached, a unique password makes that exposed credential less useful for trying to enter your bank account. Where your bank offers multifactor authentication (MFA), enable it. MFA adds another authentication requirement if a password is compromised; it is not a guarantee against every kind of fraud or an explanation of any one bank’s security posture.

CISA’s archived “More than a Password” guidance recommends MFA for financial-services accounts. The page explains the added-factor principle, but it should be understood as general account-holder guidance rather than evidence that any single measure stops attacks on bank infrastructure.

Is there evidence of a bank-login attack surge now?

The cited figures are from a reporting period ending November 30, 2019, and were announced in 2020. They do not establish a 2026 surge. Without newer, comparable measurements, the historically striking Akamai numbers cannot show whether attack volumes have risen or fallen since then.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.