{"id":28300,"date":"2019-08-07T20:17:58","date_gmt":"2019-08-07T20:17:58","guid":{"rendered":"http:\/\/7a897cdc-37e6-4de2-8e41-1b3ab255166e"},"modified":"2019-08-07T20:17:58","modified_gmt":"2019-08-07T20:17:58","slug":"state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/","title":{"rendered":"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2019\/08\/07\/a0e44698-fa10-4c63-b653-d150398be877\/e86a95c3adfdf8a80ae68e46b4a1485f\/statefarm.jpg\" class alt=\"State Farm\"><\/span><\/p>\n<p>US banking and insurance giant State Farm said it suffered a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Credential_stuffing\" target=\"_blank\" rel=\"noopener noreferrer\">credential stuffing attack<\/a> during which &#8220;a bad actor&#8221; was able to confirm valid usernames and passwords for State Farm online accounts.<\/p>\n<p>State Farm said it reset account passwords to all impacted accounts to prevent future abuse from the bad actor. The company is now <a href=\"https:\/\/www.scribd.com\/document\/421098383\/Customer-Letter-State-Farm\" target=\"_blank\" rel=\"noopener noreferrer\">notifying affected customers<\/a>.<\/p>\n<p>A State Farm spokesperson told <em>ZDNet<\/em> the company discovered the credential stuffing attack on July 6, 2019. However, the company did not respond to a direct question asking about the number of impacted accounts.<\/p>\n<p>Nevertheless, State Farm said that it did not identify any fraudulent activity in the accounts that had their passwords confirmed.<\/p>\n<p>The company&#8217;s online accounts allow users to manage insurance claims, pay bills, or wire funds, among many other things [<a href=\"https:\/\/www.statefarm.com\/customer-care\/manage-your-accounts\" target=\"_blank\" rel=\"noopener noreferrer\">1<\/a>, <a href=\"https:\/\/www.statefarm.com\/finances\/banking\/manage-your-accounts\/account-help\" target=\"_blank\" rel=\"noopener noreferrer\">2<\/a>].<\/p>\n<p>&#8220;We have implemented additional controls and continue to evaluate our information security efforts to mitigate future attacks,&#8221; a State Farm spokesperson told <em>ZDNet<\/em>.<\/p>\n<p>&#8220;We encourage customers to regularly change their passwords to a new and unique password, use multi-factor authentication whenever possible, and review all personal accounts for signs of unusual activity,&#8221; the company added.<\/p>\n<h3>Banks are under a barrage of credential stuffing attacks<\/h3>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p><a href=\"https:\/\/www.zdnet.com\/article\/an-inside-look-at-how-credential-stuffing-operations-work\/\" target=\"_blank\" rel=\"noopener noreferrer\">Credential stuffing attacks<\/a> are when hackers take username and password combinations that have been made public through security breaches at other companies, and use them to gain access to accounts on other services, hoping that users had reused passwords across accounts.<\/p>\n<p>These types of attacks have been growing in frequency at an alarming rate since last year. In a report published last month, Akamai said it detected <a href=\"https:\/\/www.akamai.com\/us\/en\/multimedia\/documents\/state-of-the-internet\/soti-security-financial-services-attack-economy-report-2019.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">over 3.5 billion credential stuffing requests<\/a> aimed at financial institutions in the past 18 months.<\/p>\n<p>Companies like ad blocker <a href=\"https:\/\/www.zdnet.com\/article\/adguard-resets-all-user-passwords-after-credential-stuffing-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">AdGuard<\/a>, banking giant <a href=\"https:\/\/www.zdnet.com\/article\/hsbc-discloses-security-incident\/\" target=\"_blank\" rel=\"noopener noreferrer\">HSBC<\/a>, social media site <a href=\"https:\/\/www.reddit.com\/r\/help\/comments\/aea649\/recently_locked_out_of_your_account_help_is_on\/\" target=\"_blank\" rel=\"noopener noreferrer\">Reddit<\/a>, video sharing portal <a href=\"https:\/\/www.zdnet.com\/article\/dailymotion-discloses-credential-stuffing-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">DailyMotion<\/a>, delivery service <a href=\"https:\/\/www.teiss.co.uk\/threats\/deliveroo-accounts-credential-stuffing\/\" target=\"_blank\" rel=\"noopener noreferrer\">Deliveroo<\/a>, enterprise tool <a href=\"https:\/\/m.signalvnoise.com\/yesterdays-mass-login-attack-on-basecamp-is-another-reminder-to-protect-yourself\/\" target=\"_blank\" rel=\"noopener noreferrer\">Basecamp<\/a>, restaurant chain <a href=\"https:\/\/www.zdnet.com\/article\/dunkin-donuts-accounts-compromised-in-second-credential-stuffing-attack-in-three-months\/\" target=\"_blank\" rel=\"noopener noreferrer\">Dunkin&#8217; Donuts<\/a>, tax filing service <a href=\"https:\/\/ago.vermont.gov\/wp-content\/uploads\/2019\/02\/2019-02-22-Intuit-Notice-of-Data-Breach-to-Consumers.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">TurboTax<\/a>, and UK telco <a href=\"https:\/\/www.zdnet.com\/article\/credentials-stuffing-attack-prompts-password-resets-for-sky-customers\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sky<\/a> have all publicly acknowledged being on the receiving end of credential stuffing attacks in the past year alone.<\/p>\n<p>Hackers typically use credential stuffing attacks to confirm passwords for online accounts, which they later resell online, on hacking forums or on the dark web.<\/p>\n<p>&#8220;Large companies see cyber security attacks on a regular basis,&#8221; a State Farm told <em>ZDNet<\/em>. &#8220;We take the security of all customer information seriously, and we regularly monitor our networks and test the strength of our security to remain vigilant against increasingly sophisticated cyber security threats. Incidents like this remind us we all must continue to exercise diligence to protect our personal information.&#8221;<\/p>\n<h3>More data breach coverage:<\/h3>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>State Farm suffered a credential stuffing attack in July and is now notifying impacted customers.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":28301,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-28300","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-08-07T20:17:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack\",\"datePublished\":\"2019-08-07T20:17:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/\"},\"wordCount\":434,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/\",\"name\":\"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg\",\"datePublished\":\"2019-08-07T20:17:58+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg\",\"width\":1000,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/","og_locale":"en_US","og_type":"article","og_title":"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-08-07T20:17:58+00:00","og_image":[{"width":1000,"height":450,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack","datePublished":"2019-08-07T20:17:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/"},"wordCount":434,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/","url":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/","name":"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg","datePublished":"2019-08-07T20:17:58+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/08\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack.jpg","width":1000,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/state-farm-says-hackers-confirmed-valid-usernames-and-passwords-in-credentials-stuffing-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"State Farm says hackers confirmed valid usernames and passwords in credentials stuffing attack"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/28300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=28300"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/28300\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/28301"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=28300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=28300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=28300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}