Credential-stuffing infrastructure staged against EU retail banking
- High
We have observed infrastructure being provisioned and tested ahead of a credential-stuffing campaign against retail banking portals in the EU. The staging pattern — residential proxy pools, rotating device fingerprints, and low-and-slow validation runs — is consistent with operators preparing for volume rather than opportunistic probing.
Who this affects
Retail banking, payment institutions and e-money issuers with customer-facing login portals.
Review authentication failure baselines; the validation phase deliberately stays under conventional rate-limit thresholds.
Confirm that credential-stuffing protections consider device and behavioural signals, not source IP alone — residential proxy pools defeat IP reputation.
Ensure step-up authentication triggers on anomalous device characteristics, not only on anomalous geography.
Indicators and detection logic
The full technical package — infrastructure indicators, hashes, sender patterns and ready-to-deploy detection rules — goes to platform customers ahead of publication. If you are in an affected sector and not a customer, ask us and we will send this one anyway.