GlossarySecurity awareness

Credential stuffing

Short answer

Credential stuffing is an automated attack in which criminals take usernames and passwords leaked from one service and try them on many others, counting on people reusing the same password. Each successful match gives them access to a real account.

How it works

Billions of leaked credentials circulate on criminal forums, collected from past breaches and from infostealer malware. Attackers load them into tools that try each pair against login pages for email, VPNs, SaaS applications and online shops, spreading the attempts across many IP addresses to avoid detection.

Credential stuffing vs brute force

A brute force attack guesses passwords. Credential stuffing uses real passwords that already worked somewhere else, so its success rate is much higher and each attempt looks like a normal login.

How to protect against it

MFA is the most effective measure, because a correct password is no longer enough. A password manager removes password reuse, and SSO reduces the number of separate logins. On the service side, rate limiting, bot detection and checking new passwords against lists of known leaks help. Anyone can check whether their email appears in known leaks on Have I Been Pwned.

Why it matters for companies

A single reused password on a work account can open email, file storage or a VPN, and lead to BEC fraud or ransomware. Monitoring logins and blocking suspicious sign ins closes the gap.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub