RIPE NCC Internet Registry Discloses SSO Credential Stuffing Attack

RIPE NCC Internet Registry Discloses SSO Credential Stuffing Attack

RIPE NCC is warning members that they suffered a credential stuffing attack attempting to gain access to single sign-on (SSO) accounts.

RIPE NCC is a not-for-profit regional Internet registry for Europe, the Middle East, and parts of Central Asia. It is responsible for allocating blocks of IP addresses to Internet providers, hosting providers, and organizations in the EMEA region.

Membership includes over 20,000 organizations from over 75 countries who act as Local Internet Registries (LIRs) to assign IP address space to other organizations in their own country.

RIPE NCC hit by a credential stuffing attack

RIPE disclosed today that they suffered a credential stuff attack over the weekend targeting their single sign-on (SSO) service. This SSO service is used to login to all RIPE sites, including My LIR, Resources, RIPE Database, RIPE Labs, RIPEstat, RIPE Atlas, and the RIPE Meeting websites.

“Last weekend, RIPE NCC Access, our single sign-on (SSO) service was affected by what appears to be a deliberate ‘credential-stuffing’ attack, which caused some downtime.

Also Read: How a Smart Contract Audit Works and Why it is Important

“We mitigated the attack, and we are now taking steps to ensure that our services are better protected against such threats in the future,” RIPE NCC disclosed today in an announcement on their website.

RIPE states that their investigation does not indicate that any of their accounts have been compromised, but they will immediately contact the account holders if any are found.

The RIPE NCC SSO service offers two-factor authentication, which members can enable on their profile page. RIPE urges all users to enable two-factor authentication on their Access accounts to prevent compromise in future credential-stuffing attacks.

RIPE asks any users who detect suspicious activity on their account to contact them immediately.

It is also recommended to use a different password at every site you frequent to prevent leaked credentials from being used in credential stuffing attacks at other websites.

Also Read: Data Centre Regulations Singapore: Does It Help To Progress?

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

2 weeks ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago