Skip to content

Credential Stuffing

Definition

An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across accounts. A primary identity theft vector that does not require any vulnerability in the target system.

Mechanism
Automated replay of breached username-password pairs
Exploits
Password reuse across multiple accounts
Requires
No vulnerability in the target system itself
Primary risk
Identity theft and account takeover

Common questions

Why does credential stuffing succeed even against well-secured systems?+

The attack does not exploit any flaw in the target system, it exploits the human habit of reusing the same password across multiple services, so even a system with no vulnerabilities of its own is exposed if a user's credentials were exposed in an unrelated breach elsewhere.

How is credential stuffing distinguished from a brute-force password attack in investigation logs?+

Brute-force attempts try many password guesses against a small set of usernames, while credential stuffing tries a large set of already-paired username-password combinations, each typically attempted only once or a few times, producing a distinct pattern of many distinct accounts each hit with a single, often-correct-looking attempt.

What controls are most effective at stopping credential stuffing?+

Multi-factor authentication defeats it even when the password matches, since the attacker lacks the second factor, and rate-limiting combined with bot-detection on login endpoints reduces the volume of automated attempts a service has to absorb.

Related terms

Anti-Forensic Technique
Any action taken by an attacker to destroy, conceal, or alter evidence of their activity. Common examples include log clearing, timestomping, use...
Command and Control (C2)
The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from...
Double Extortion
A ransomware tactic in which the attacker exfiltrates data before encrypting it, then demands payment both for the decryption key and for...
FAFT Virtual Asset Guidance
Guidance from the Financial Action Task Force requiring member states to regulate virtual asset service providers (cryptocurrency exchanges) as financial institutions, applying...
Image-Based Sexual Abuse (IBSA)
The non-consensual creation, capture, or distribution of intimate sexual images. The term encompasses non-consensual intimate image sharing (formerly called revenge porn), upskirt...
Lateral Movement
Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
Living-Off-the-Land (LotL)
An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
Privilege Escalation
A post-access technique in which an attacker who has gained low-level access to a system exploits a vulnerability or misconfiguration to obtain...
Synthetic Identity Fraud
The creation of a fictitious identity by combining real and fabricated personal data elements, such as a genuine national ID number paired...
Unauthorised Access
The act of accessing a computer, network, or data store without permission from the owner or without lawful authority. The core element...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.