Credential stuffing
Automated testing of credentials stolen from one service against many others. It works because people reuse passwords.
Full definition
Credential stuffing is the automated testing of username and password combinations stolen from one service against the login forms of many others. The attacker guesses nothing: they use real credentials leaked in previous breaches and let bots find where else they work.
The attack exists because password reuse is massive. It is enough that a corporate email password was also used on an online store that suffered a breach for the attacker to walk in through the front door, without exploiting any technical vulnerability. The combo lists circulating on the dark web feed these campaigns at a scale of millions of attempts.
Effective defenses are multi-factor authentication, detection of distributed login attempts, and leaked credential monitoring that forces a password change before the attacker tries it.
Related terms
Leaked credentials
Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.
Password spraying
An attack that tries a few common passwords against many accounts, instead of many passwords against one. That way it avoids lockouts.
Account takeover (ATO)
Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.
Multi-factor authentication (MFA)
Identity verification with two or more independent factors. It makes a stolen password insufficient, though not invulnerable.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.