Threat Bulletin 1170: credential stuffing against a tax authority portal platform in the Middle East

On Tuesday 19 August 2025 at 20:02 UTC, a credential stuffing targeted a tax authority portal customer in the Middle East. The attack peaked at 854.3 million requests per second and lasted 120 minutes. Traffic originated from 1217 autonomous systems in 68 countries, predominantly residential proxy networks.

Vector credential stuffing
Peak 854.3 million requests per second
Duration 120 min
Time to mitigation 0.122 s
Attack traffic reaching origin 0.044%
Legitimate traffic challenged 0.32%

Timeline

The attack was preceded by no stated motive. Request rates on the targeted routes exceeded their hourly baseline by a factor of 529 within 10 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

Checkout conversion was unchanged compared with the same hour of the previous week.

Recommendations

  • Add a dedicated rate limit for the targeted route.
  • Enable log streaming to your SIEM for faster correlation.
  • Enable authenticated origin pulls.

9 thoughts on “Threat Bulletin 1170: credential stuffing against a tax authority portal platform in the Middle East”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top