• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

SSO Credentials From a Quarter of S&P 500 Companies for Sale on Dark Web: Report

September 23, 2022

SSO Credentials From a Quarter of S&P 500 Companies for Sale on Dark Web: Report

A quarter of the S&P 500 companies may be compromised in their cybersecurity posture, suggests new research from BitSight, a specialist in cybersecurity ratings. Recent analysis from the company found that 25 percent of S&P 500 companies have at least one Single Sign-On credential for sale on the dark web, a security vulnerability affecting half of the top 20 most valuable public US companies.

BitSight began its analysis in January of this year, and says it has since “observed steady growth” in the number of public companies whose SSO credentials have appeared for sale on dark web channels. To be clear, the credentials have not all been tested by BitSight; but even if only a tenth of them are legitimate, that represents a serious cumulative security threat against a huge attack surface of the US economy.

Breaking down the affected organizations by industrial sector, BitSight found that the technology sector was the biggest victim, accounting for over a quarter of exposed SSO credentials. Manufacturing was a distant second.

“Credentials can be relatively trivial to steal from organizations, and many organizations are unaware of the critical threats that can arise specifically from stolen SSO credentials,” commented BitSight co-founder and CTO Stephen Boyer. “These findings should raise awareness and motivate prompt action to become better acquainted with these threats.”

As for how to counter the threats, BitSight offers a number of recommendations, including the use of adaptive multi-factor authentication that dynamically changes authentication requirements based on contextual parameters such as geolocation; and the use of U2F security keys. Businesses should also be careful to assess the security posture of their third-party vendors, which themselves can become an attack vector through their own cybersecurity vulnerabilities.

Source: BitSight

Filed Under: Carousel, Industry News Tagged With: BitSight, corporate security, cybersecurity, dark web, digital security, multi-factor authentication, phishing, reports, Single Sign-On, SSO

Related News & Articles

FBI Advises Beijing Olympics Athletes to Leave Personal Phones at Home

Zwipe Orders 300,000 IDEX Sensors for Biometric Cards Platform

Sensory Turns Always-Listening Tech to Home Security

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event
  • Mobile ID Comes to Another US Campus

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld