Akamai’s widely cited bank-login figures describe activity observed from December 1, 2017, through November 30, 2019—not a verified surge in 2026. During that historical period, Akamai recorded 55,141,782 malicious login attempts against one financial-services firm on August 7, 2019. The attempts were not a count of successful account takeovers, nor a census of all attacks against banks.
What Akamai reported—and when
Akamai’s February 2020 announcement covered credential-abuse attempts observed across its infrastructure between December 1, 2017, and November 30, 2019. It reported 85,422,079,109 attempts overall, including attempts against identified API endpoints and financial-services organizations:
| Measure | Akamai-reported figure | What it covers |
|---|---|---|
| Credential-abuse attempts overall | 85,422,079,109 | Akamai-observed attempts across the reporting period |
| Attempts against identified API hostnames | 16,557,875,875 | Akamai-observed attempts across the reporting period |
| API attempts against financial-services organizations | 473,518,955 | Akamai-observed attempts across the reporting period |
| One financial-services incident | 55,141,782 | Attempts observed on August 7, 2019 |
These figures are attempts, not confirmed compromises. They reflect Akamai’s customer-facing infrastructure and detection methods, so they should not be read as a global total or as a measure of how many customers lost access to accounts. Akamai’s official announcement is available through PR Newswire.
Why APIs were part of the story
Akamai reported that as much as 75% of credential abuse against financial services targeted APIs during the period. SecurityWeek described spikes above 80% in May 2019 and above 75% in October 2019. Those are historical shares, not present-day estimates. Akamai said the move toward API endpoints became pronounced beginning in May 2019, potentially as attackers sought to get around defenses applied to other login routes.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
In a separate API-focused run on August 25, 2019, Akamai observed more than 19 million credential-abuse attempts. The figure is distinct from the 55.1 million attempts against a financial-services firm on August 7.
SecurityWeek also reported that, among financial-services web-application attacks in the period, 47% were Local File Inclusion, 36% SQL injection, and 7.7% cross-site scripting. Those are different attack categories; they should not be added to or confused with the credential-stuffing login counts. See SecurityWeek’s February 21, 2020 report.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What credential stuffing means
Credential stuffing is the automated testing of username-and-password pairs that attackers have already obtained, often from a breach at another service. It works because some people reuse passwords: a leaked pair for one site may also unlock an unrelated account. As Akamai put it in its 2019 report, “Recycled passwords are why credential stuffing attacks work.”
This differs from password guessing. Instead of trying arbitrary passwords from scratch, an attacker begins with known credential pairs and may also test variations. Automation lets attackers submit many attempts, while distributing traffic across targets or stretching activity over time can make a campaign less obvious than a burst of requests.
Rank #3
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to interpret Akamai’s counts
Akamai’s report used more than one way to identify credential-stuffing activity. It treated unsuccessful logins using email-address usernames as credential-stuffing attempts, and described both a volumetric method that counted login errors associated with an address and bot detections for known botnets and tools. The report cautioned that botnets can spread traffic across targets and time, potentially evading simple volume thresholds. The totals therefore depend on Akamai’s definitions, detection approach, and participating infrastructure; they are not a complete record of every attempt everywhere.
Akamai security researcher Steve Ragan, the report’s principal author, told SecurityWeek: “Criminals targeting the financial services industry pay close attention to the defenses used by these organizations, and adjust their attack patterns accordingly.” That comment and the figures describe the studied period, not a finding about banks’ current defenses or current attack volumes.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What bank security teams can take from the report
The historical findings point to several areas security teams can evaluate, without establishing which controls any particular bank uses today:
- Cover API and web login paths. A login defense focused only on browser-facing pages may miss abuse aimed at APIs.
- Look beyond simple volume thresholds. Detection should account for bot behavior and distributed or low-and-slow patterns, not just a high request count from one source.
- Use layered authentication defenses. Strong authentication, including multifactor authentication, can reduce the usefulness of a stolen password, while bot detection and monitoring address automated attempts.
The cited material does not provide a vendor-neutral comparison or a product efficacy test, so it cannot establish which commercial control performs best.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
How account holders can reduce risk
Use a unique password for your bank account rather than reusing one from other sites. If another service is breached, a unique password makes that exposed credential less useful for trying to enter your bank account. Where your bank offers multifactor authentication (MFA), enable it. MFA adds another authentication requirement if a password is compromised; it is not a guarantee against every kind of fraud or an explanation of any one bank’s security posture.
CISA’s archived “More than a Password” guidance recommends MFA for financial-services accounts. The page explains the added-factor principle, but it should be understood as general account-holder guidance rather than evidence that any single measure stops attacks on bank infrastructure.
Is there evidence of a bank-login attack surge now?
The cited figures are from a reporting period ending November 30, 2019, and were announced in 2020. They do not establish a 2026 surge. Without newer, comparable measurements, the historically striking Akamai numbers cannot show whether attack volumes have risen or fallen since then.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




