-

Auth0 Releases State of Secure Identity Report, Highlighting the Most Pervasive Threats to Digital Identities

Inaugural report reveals insidious trends and provides mitigation strategies for security professionals

BELLEVUE, Wash.--(BUSINESS WIRE)--Auth0, the modern identity platform, today announced the launch of its inaugural security report: The State of Secure Identity. This detailed report highlights key areas of concern for security professionals responsible for managing digital identities, including the exponential rise of credential stuffing attacks (automated attempts to compromise a large number of user accounts with stolen credentials), fraudulent registrations, and the widespread use of breached credentials.

Recent headlines and high-profile cyber attacks give today’s security professionals a wide swath of serious threats to worry about. The primary goal of cybercriminal activity is to access critical resources, systems, and personal data, yet systems that can be put into place to minimize the risk of attack — like identity management — often get deprioritized. Lack of budget, resourcing, or attention on managing digital identities give threat actors a prime opportunity to take advantage of these discrepancies and surreptitiously execute their attacks.

Research into Auth0’s global customers over the past year found these key facts and figures:

  • In the first 90 days of 2021, credential stuffing accounted for 16.5% of attempted login traffic on its platform, with a peak of over 40% near the end of March — all of which Auth0 detected and prevented.
  • Travel & leisure and retail are the top two industries most affected by credential stuffing attacks.
  • The number of fraudulent registrations vary by industry vertical, but roughly 15% of all attempts to register a new account can be attributed to bots.
  • In the first 90 days of 2021, the Auth0 platform detected breached passwords at an average of more than 26,600 per day, with a minimum of just under 7,300 and a high on Feb. 9, 2021 exceeding 182,000.

“Securing customers’ identities is made more difficult by industry-wide failures to protect data. The prevalence of breached passwords and the availability of automated attack tools makes the humble password a protective measure from the past,” said Duncan Godfrey, VP of Security Engineering, Auth0. “The State of Secure Identity Report is designed to share our unique identity security insights and recommendations with the industry so that application builders and developers at any organization can take the steps they need to improve their overall security posture, and make things more secure for end users.”

The most prevalent threats detailed in the report include Credential Stuffing (the most common threat observed by Auth0); Fraudulent Registrations; Multi-factor Authentication Bypass; Breached Password Usage; and other common identity attacks. The complete Auth0 State of Secure Identity Report, which includes additional key findings and recommendations on how organizations can improve their identity security posture, can be downloaded here. Auth0 will also be hosting an online meetup to examine these insights in greater detail on Thursday June 24 at 8:00 AM PDT.

Auth0, recently acquired by Okta, provides a modern identity platform that helps organizations meet the security, privacy, and convenience needs of their users. Please visit the Auth0 identity OS to learn more.

About Auth0

Auth0’s modern approach to identity enables organizations to provide secure access to any application, for any user. The Auth0 platform is a highly customizable identity operating system that is as simple as development teams want and as flexible as they need. Safeguarding billions of login transactions each month, Auth0 delivers convenience, privacy, and security so customers can focus on innovation. For more information, visit https://auth0.com.

Contacts

Global Communications
Auth0
Jeana Tahnk
press@auth0.com

Matter for Auth0
Hannah Carroll
auth0@matternow.com

Auth0



Contacts

Global Communications
Auth0
Jeana Tahnk
press@auth0.com

Matter for Auth0
Hannah Carroll
auth0@matternow.com

More News From Auth0

Auth0 Credential Guard Detects Breached Passwords Faster to Prevent Account Takeover

BELLEVUE, Wash.--(BUSINESS WIRE)--Auth0, a product unit within Okta (NASDAQ: OKTA), today announced the general availability of Credential Guard, a new security feature that helps enterprises prevent account takeover attacks by detecting and resetting stolen passwords faster. Credential Guard upgrades Auth0’s existing breached password detection with a dedicated security team, and support for more than 35 languages and 200+ countries and territories to reduce breach detection time. Credential G...

Auth0 Public Sector Index Shows Governments Struggle to Provide Trustworthy Online Citizen Services

BELLEVUE, Wash.--(BUSINESS WIRE)--Auth0, a product unit within Okta (NASDAQ: OKTA), today released the findings of its first Public Sector Identity Index, a global research report that provides government technology leaders with insight into the identity maturity of public sector organizations around the world. The report highlights the importance of a centralized identity strategy in putting safe and accessible services into the hands of citizens faster. Over the past two years, many public se...

Auth0 Expands Reach to Mexico with TEC360 Partnership

BUENOS AIRES, Argentina--(BUSINESS WIRE)--The Auth0 Identity Platform, a product unit within Okta (NASDAQ: OKTA), announced today a new partnership with TEC360, a leading provider of cloud solutions for enterprises in Mexico and Latin America (LATAM). TEC360 is Auth0’s first partner in Mexico, and together, the two companies are helping enterprises across the region meet their evolving identity management and security goals. TEC360 operates in Mexico and LATAM, and provides cloud solutions for...
Back to Newsroom