Back to the glossary
    Credentials & identityCybersecurity glossary

    Credential stuffing

    Automated testing of credentials stolen from one service against many others. It works because people reuse passwords.

    Full definition

    Credential stuffing is the automated testing of username and password combinations stolen from one service against the login forms of many others. The attacker guesses nothing: they use real credentials leaked in previous breaches and let bots find where else they work.

    The attack exists because password reuse is massive. It is enough that a corporate email password was also used on an online store that suffered a breach for the attacker to walk in through the front door, without exploiting any technical vulnerability. The combo lists circulating on the dark web feed these campaigns at a scale of millions of attempts.

    Effective defenses are multi-factor authentication, detection of distributed login attempts, and leaked credential monitoring that forces a password change before the attacker tries it.

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.