Company M: Cutting Credential Exploits by 91%
How one online retailer took exploited customer logins from more than 532,000 to fewer than 10,000.
What this case study covers:
- The attack
A systematically executed credential stuffing campaign against Company M between January and April, with far more credential pairs tested than distinct usernames.
- Why reuse makes ATO cheap
52% of US consumers reuse a password across two or more accounts; 13% use the same password everywhere. 22.6% of observed logins were ATO attempts.
- What screening changed
Exploits of compromised customer login credentials fell from more than 532,000 to fewer than 10,000 — a 91% reduction.
- The workplace-account multiplier
Why ATO costs rise sharply when the compromised account belongs to an employee rather than a consumer.
