Users of the Verizon Carrier Visible Victimized by Credentials Stuffing Attack

Some mobile phone owners who were using Verizon Visible - an attractively priced offering from the mobile operator and its wireless carrier - woke up to find that they've just ordered a new expensive iPhone, shipping to an address other than their own, and were locked out of their accounts, and had their emails and logins swapped out.

As Verizon and Visible were quick to explain, the attack was not a data breach and no systems and networks operated by Verizon and its wireless carrier were hacked into. Rather, the incident was most likely the result of a moderately successful credentials stuffing attack.

Credentials stuffing refers to the process of bad actors obtaining large databases of leaked passwords or password and username combinations and then trying to match this data with accounts on other services and platforms. Of course, this vector of attack only works if the user uses the same password or username and password combination across several different platforms. Sadly, this is still a very common practice and it is why large-volume credentials stuffing can work well.

On October 13, Visible stated that bad actors managed to access accounts using credentials obtained from "outside sources". Naturally, the company urged users who had their accounts breached and were also using those same credentials across other services, especially financial and banking ones, to change those credentials immediately.

The bad actors who illegally accessed Visible user accounts usually abused them to order a brand new, expensive iPhone using the victim's associated payment method. Obviously, anyone who woke up to find they had racked up a huge bill and weren't even going to receive the iPhone got quite a shock.

This incident underlines the importance of using different, varied login credentials across every account you have - something that we have been trying to drive home for a long time as well. The breached accounts also underline the great value some form of multi-factor authentication can add to any platform. Something relatively simple and basic as MFA was not offered through Visible's platform and some customers are now wondering why that was the case.

October 15, 2021
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.