Credential Stuffing
Definition
An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across accounts. A primary identity theft vector that does not require any vulnerability in the target system.
- Mechanism
- Automated replay of breached username-password pairs
- Exploits
- Password reuse across multiple accounts
- Requires
- No vulnerability in the target system itself
- Primary risk
- Identity theft and account takeover
Common questions
Why does credential stuffing succeed even against well-secured systems?+
The attack does not exploit any flaw in the target system, it exploits the human habit of reusing the same password across multiple services, so even a system with no vulnerabilities of its own is exposed if a user's credentials were exposed in an unrelated breach elsewhere.
How is credential stuffing distinguished from a brute-force password attack in investigation logs?+
Brute-force attempts try many password guesses against a small set of usernames, while credential stuffing tries a large set of already-paired username-password combinations, each typically attempted only once or a few times, producing a distinct pattern of many distinct accounts each hit with a single, often-correct-looking attempt.
What controls are most effective at stopping credential stuffing?+
Multi-factor authentication defeats it even when the password matches, since the attacker lacks the second factor, and rate-limiting combined with bot-detection on login endpoints reduces the volume of automated attempts a service has to absorb.
Related terms
- Anti-Forensic Technique
- Any action taken by an attacker to destroy, conceal, or alter evidence of their activity. Common examples include log clearing, timestomping, use...
- Command and Control (C2)
- The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from...
- Double Extortion
- A ransomware tactic in which the attacker exfiltrates data before encrypting it, then demands payment both for the decryption key and for...
- FAFT Virtual Asset Guidance
- Guidance from the Financial Action Task Force requiring member states to regulate virtual asset service providers (cryptocurrency exchanges) as financial institutions, applying...
- Image-Based Sexual Abuse (IBSA)
- The non-consensual creation, capture, or distribution of intimate sexual images. The term encompasses non-consensual intimate image sharing (formerly called revenge porn), upskirt...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Living-Off-the-Land (LotL)
- An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
- Privilege Escalation
- A post-access technique in which an attacker who has gained low-level access to a system exploits a vulnerability or misconfiguration to obtain...
- Synthetic Identity Fraud
- The creation of a fictitious identity by combining real and fabricated personal data elements, such as a genuine national ID number paired...
- Unauthorised Access
- The act of accessing a computer, network, or data store without permission from the owner or without lawful authority. The core element...
Explained in these topics
- Hacking and Unauthorised Access OffencesAn automated attack that uses lists of username and password pairs obtained from prior data breaches to attempt login on other services, exploiting password re...
- Ransomware, Identity Theft and Online Exploitation