APAC CIOOutlook

Advertise

with us

  • Technologies
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • Digital Transformation
      • Internet of Things
      • Low Code No Code
      • MarTech
      • Mobile Application
      • Security
      • Software Testing
      • Wireless
  • Industries
      • E-Commerce
      • Education
      • Logistics
      • Retail
      • Supply Chain
      • Travel and Hospitality
  • Platforms
      • Microsoft
      • Salesforce
      • SAP
  • Solutions
      • Business Intelligence
      • Cognitive
      • Contact Center
      • CRM
      • Cyber Security
      • Data Center
      • Gamification
      • Procurement
      • Smart City
      • Workflow
  • Home
  • CXO Insights
  • CIO Views
  • Vendors
  • News
  • Conferences
  • Whitepapers
  • Newsletter
  • CXO Awards
Apac
  • Artificial Intelligence

    Big Data

    Blockchain

    Cloud

    Digital Transformation

    Internet of Things

    Low Code No Code

    MarTech

    Mobile Application

    Security

    Software Testing

    Wireless

  • E-Commerce

    Education

    Logistics

    Retail

    Supply Chain

    Travel and Hospitality

  • Microsoft

    Salesforce

    SAP

  • Business Intelligence

    Cognitive

    Contact Center

    CRM

    Cyber Security

    Data Center

    Gamification

    Procurement

    Smart City

    Workflow

Menu
    • AI
    • Cyber Security
    • Hotel Management
    • Workflow
    • E-Commerce
    • Business Intelligence
    • MORE
    #

    Apac CIOOutlook Weekly Brief

    ×

    Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

    Subscribe

    loading

    THANK YOU FOR SUBSCRIBING

    • Home
    • Artificial Intelligence
    Editor's Pick (1 - 4 of 8)
    left
    The Right Technology And Reliable Partners; The Business Next Frontier

    Luke O'Brien, CIO, ISS Facility Services Australia & New Zealand

    Conquering Technological Transformation

    David Kennedy, Group CIO, Transaction Services Group

    How to Get to AI-first

    Ani Paul, CIO, ING Australia

    Legal Knowledge Management and the Rise of Artificial Intelligence

    Christopher Zegers, CIO, Lowenstein Sandler LLP

    Building an AI-Based Machine Learning for Global Economics

    Alexander Fleiss, CIO & CEO, Rebellion Research Partners LP

    Responsible Data Leadership in an AI-Driven World

    Gemma Dias, Head of Data Governance, Tyro Payments

    Building Agile, Secure and Human-Centered IT at Globe

    Raul Macatangay, Chief Information Officer, Globe Telecom

    AI Adoption in Hospitality: Striking the Balance Between Innovation, Excellence and Trust

    Phiphat Khanonwet, Head of IT, Onyx Hospitality Group

    right

    Fraudulent registration attempts the top identity attack type in APAC

    Ben Goodman, SVP and General Manager APJ, Okta

    Tweet
    content-image

    Ben Goodman, SVP and General Manager APJ, Okta

    The customer login box lures bad actors like bees to honey, and the attraction is highly potent in the Asia-Pacific.

    The login box seeks, through authentication enabled by Customer Identity and Access Management (CIAM) services, to confirm a customer’s digital identity. However, for actors who can bypass this identity security measure–and an entire ecosystem of technologies, services and resources exist to enable illicit intrusions–the rewards are potentially considerable.

    Bad actors targeting customer identity (CIAM) systems

    Okta’s third annual 2023 State of Secure Identity report reveals CIAM systems are under attack from bad actors using sign-up fraud, credential stuffing and multi-factor authentication (MFA) bypass for illicit purposes.

    The report uses H1 2023 anonymised data from the Okta Customer Identity Cloud powered by Auth0, which provides CIAM functionality to thousands of organisations worldwide. The prevalence and impact of identity threats come across clearly in the report.

    When measuring attack types by global region for the first calendar half of 2023, organisations headquartered in the Asia-Pacific were second overall to those headquartered in the Americas.

    Fraudulent registration attempts the top attack type in APAC

    However, fraudulent registration attempts in the Asia Pacific are, at 27.9% of total registration attempts on the Okta Customer Identity Cloud–about three times higher than in the Americas (9.4%) and Europe, the Middle East and Africa (EMEA - 8.1%). In Japan, this figure rises to 43.6%, whereas for Southeast Asia, it is just 16.2%.

    By contrast, credential stuffing attempts are, at 13.3% against organisations headquartered in the Asia-Pacific, well below the equivalent figures in the Americas (28%) and EMEA (20.2%).

    The higher fraudulent registration attempt figure is likely to be a symptom of a less mature approach to identity security in the Asia Pacific, compared to other regions. This corresponds to the enablement of fewer security products and features among Okta’s APAC customers, compared to customers in other parts of the world.

    Successful fraudulent registrations at business-to-consumer companies allow bad actors to exploit any incentives provided for consumers to create new customer accounts, degrade the experience of legitimate customers and divert business resources away from more valuable tasks.

    Worldwide in H1 2023, nearly one quarter (24.3%) of login attempts on the Okta Customer Identity Cloud constitutes credential stuffing. Unsurprisingly, given the value of accounts in retail and ecommerce, companies in that industry were prime targets accounting for more than half (51.3%) of all credential stuffing events.

    About one-seventh (13.9%) of attempted account registrations on the Okta Customer Identity Cloud met our criteria of a sign-up attack, with four industries standing out. These were financial services, with 28.8% of attempted account registrations classed as sign-up attacks, media (28.4%), manufacturing (25.1%) and software/SaaS/technology (24%).

    The report noted that 12.7% of MFA bypass attempts were malicious, with media (12.8%), financial services (10.9%), manufacturing (7.8%) and software/SaaS/tech (6.4%) experiencing the highest proportions of MFA bypass attacks.

    AI increases danger of threat landscape

    Beyond these, the report acknowledges that artificial intelligence (AI) has made the threat landscape more perilous by enabling spear phishing at scale to target thousands of employees at a range of organisations. Other dangers include making low-quality, high intensity attacks such as credential stuffing and fraudulent registrations harder to detect and more effective, enabling new types of attacks, and overcoming some existing security measures such as CAPTCHAs and voice biometric systems.

    Fortunately AI also provides opportunities to strengthen defences through further securing applications by design, improving automated threat detection and mitigating risk.

    So how can businesses in the Asia Pacific minimise the risk presented by identity attacks? For a start, CIAM must rely on subtle security techniques to achieve a strong and resilient posture, while preserving convenient user experiences.

    Because enterprise needs become more demanding while the threat landscape becomes more sophisticated, these techniques need to be tuned continuously to balance user experience, security and privacy, based on each organisation’s risk profile and appetite.

    The answer? a best-of-breed CIAM solution with an agile, secure-by-design, defence-in-depth architecture is a highly effective approach to achieving Identity security.

    To learn more about the State of Secure Identity, download our report here.

    tag

    AI

    Financial

    SaaS

    Identity and Access Management

    Fraud

    Weekly Brief

    loading
    Top 20 Prominent Artificial Intelligence Solutions Providers in APAC - 2024
    ON THE DECK

    I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

    Read Also

    Loading...
    Copyright © 2025 APAC CIOOutlook. All rights reserved. Registration on or use of this site constitutes acceptance of our Terms of Use and Privacy and Anti Spam Policy 

    Home |  CXO Insights |   Whitepapers |   Subscribe |   Conferences |   Sitemaps |   About us |   Advertise with us |   Editorial Policy |   Feedback Policy |  

    follow on linkedinfollow on twitter follow on rss
    This content is copyright protected

    However, if you would like to share the information in this article, you may use the link below:

    https://artificial-intelligence.apacciooutlook.com/views/fraudulent-registration-attempts-the-top-identity-attack-type-in-apac-nwid-10091.html