← All terms

Credential Stuffing

Credential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.

Credential stuffing is an automated account-takeover attack in which criminals take large lists of usernames and passwords stolen in previous data breaches and "stuff" them into the login forms of unrelated services. The attack works for one simple reason: people reuse passwords. If an employee's personal streaming-service password leaked in 2023 and it is the same password they use for their corporate email, the attacker does not need to hack your company at all — they just need to try the door.

How it works

Attackers buy or download combo lists — files containing millions of email-and-password pairs aggregated from historical breaches — and feed them into automated tools that distribute login attempts across botnets and residential proxies. This makes the traffic look like ordinary logins from ordinary home connections rather than a brute-force flood from one server. Success rates are low in percentage terms, typically a fraction of one percent, but against a list of ten million credentials even 0.1% means ten thousand compromised accounts. Once inside, attackers drain loyalty points, harvest personal data, commit payment fraud, or — in the corporate context — use the foothold to launch internal phishing and business email compromise from a trusted mailbox.

Credential stuffing differs from brute forcing: it does not guess passwords, it replays known-valid ones. That is why password complexity rules alone do nothing against it — a strong password reused in two places is exactly as vulnerable as a weak one.

How to defend against it

Multi-factor authentication is the single most effective control, since a stolen password alone no longer opens the account — though be aware attackers respond with MFA fatigue prompts and phishing kits that relay codes in real time. Deploy breached-password screening so users cannot choose credentials that already appear in public dumps, encourage password managers to make unique passwords practical, and monitor for the telltale signs of stuffing campaigns: spikes in failed logins, logins from unusual ASNs, and impossible-travel patterns. Finally, address the human habit at the root of the problem — password reuse — through continuous security awareness training that explains why one leaked personal account can endanger the whole company.

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo