Bots were being used to scrape and download content from the site. Because the online learning platform was primarily designed for streaming content, it was unable to handle the flood of concurrent content downloads and performance slowed significantly.
In addition, many users complained that their accounts were compromised. Users’ login and password combinations were being validated by brute force credential stuffing attacks on the login page, leading to account takeovers (ATOs). As the team investigated, they also noticed a high number of bot-created fake accounts that were used to plagiarize content and post it on other platforms.