Most of us today have a multitude of online accounts to manage. Creating and remembering secure passwords for each isn’t easy, so many of us end up reusing passwords across multiple accounts. Cybercriminals know this well, exploiting bad password habits through attacks like credential stuffing.
This guide covers credential stuffing attacks and how they work. It also explains how individuals can protect themselves and how organizations can harden their services against this threat.
What Does Credential Stuffing Mean?
Credential stuffing is a type of cyberattack where attackers try to use known user credentials to log into different websites or services. Often, it starts with attackers obtaining a huge number of user records from a data breach or other hack. They then use those credentials to log into other, potentially unrelated websites.
While data breaches are the most common source, cybercriminals may also get logins by exploiting application programming interfaces (APIs), compromising website endpoints, or accessing public archives. They then try to access user accounts, typically starting with popular platforms.
How Does a Credential Stuffing Attack Work?
While details may vary, all credential stuffing attacks follow the same pattern:
- A website or business suffers a large data breach, exposing information that includes user or personnel records, such as usernames, passwords, and contact details.
- An attacker feeds the information into an automated tool that tries to log into various websites, often running logins in parallel and using fake IPs.
- When a login succeeds, the tool alerts the attacker, who may now have access to the account and a set of validated credentials.
- The attacker then uses their account access to steal data, make fraudulent transactions, or impersonate the victim.
- The attacker may also keep the credentials for future attacks or share them on password dump sites.
Why Is Credentials Stuffing So Effective?
Attackers use credential stuffing because it’s relatively low effort, low risk, and highly scalable. Massive data breaches like the Collection #1-5 leak, where cybercriminals obtained over 25 billion total emails and passwords from several sources, can expose hundreds of millions of credentials at once.¹
Once this data goes public, anyone can use it to carry out a credential stuffing attack. Cybercriminals often sell the data on dark web sites or post it on leak sites. Beyond usernames and passwords, the records may also contain information attackers can use, such as the person’s identity and the other websites they use.
Once a bad actor has this information, automated tools let them try large numbers of login combinations across many sites in a short time. Some of these tools come prebuilt and ready to use. As such, they don’t necessarily need a high success rate per login.
Credential stuffing also thrives because password reuse is so widespread. According to LastPass, most individuals mostly reuse the same password for most, if not all, their accounts.² At the same time, up to 41% of all logins Cloudflare processed involved stolen credentials.³
Services can strengthen authentication with techniques like two-factor authentication (2FA). While these techniques make credential stuffing much harder, advanced attacks can bypass some of them using methods like social engineering or cookie theft. Other defenses, like banning IPs or limiting login attempts, may disrupt normal users as well.
Finally, as more of our lives move online, companies collect more personal data, and remote work becomes more common, credential-stuffing attacks are likely to become increasingly prevalent.
What Are the Consequences of Credential Stuffing?
A successful credential stuffing attack can have severe consequences for individuals and organizations:
- User impersonation: Attackers can take over victims’ accounts and act on their behalf or contact their connections, enabling social engineering attacks and various kinds of fraud.
- Data theft: Attackers can use their account access to uncover information about the victim, such as their contact details, address, past behavior, medical history, or financial status. Beyond the privacy violation, this information can expose victims to further crimes.
- Identity or financial fraud: If the attacker obtains enough information, they can take out loans in the victim’s name, sign up for new credit cards, apply for government ID, and more.
- Payment fraud: An attacker may be able to make unauthorized purchases, fund transfers, or subscription changes on the victim’s account. This can lead to financial losses or disrupt access to services the victim thought they paid for.
- Credential exposure: Working credentials are valuable to other cybercriminals. Attackers who find valid logins could sell or post them on leak sites along with the site(s) they work on.
- Advanced persistent threats (APTs): If attackers gain access to a corporate portal or network, they can use it to establish a long-term presence. For example, they may impersonate an employee, create new user roles, or spread to other services, enabling corporate espionage and potential intellectual property theft.
- Data breaches: A data breach is often the primary goal for attackers who target corporate networks. They can use this access to steal customer records or personal files, fueling a new wave of credential stuffing attacks.
Credential Stuffing vs Brute Force vs. Password Spraying Attacks

Credential stuffing falls under brute force attacks, but there are important differences between the two.
Brute-forcing an account means trying as many passwords as possible until the attacker finds the correct one. In contrast to credential stuffing, a brute force attacker lacks a pre-existing list of passwords to try. While it’s possible to carry out a manual brute force attack, attackers usually rely on some kind of automated password generator.
Password spraying is another brute force technique where the attacker only tries a short list of overused passwords. For example, they may try passwords like “12345,” “qwerty,” “password,” or the victim’s name, birth date, etc. If they fail to break into the account, they move on to the next one.
Credential stuffing is arguably the most effective method. Unlike the other two, attackers have credentials that they know worked at one point. They need to find other accounts where the same credentials work. It also uses large datasets and is relatively easy to automate and scale, similar to basic brute force attacks.
How to Prevent Credential Stuffing Attacks

Both individuals and businesses can reduce their exposure to credential stuffing by taking these precautions.
Individuals
The most effective habit is using a different password for every account. Granted, this isn’t always feasible due to the sheer number of accounts most of us have today.
For example, some people may prefer to reuse a few complex, hard-to-guess passwords rather than fall back on simpler, but unique, passwords for every account. While complex passwords provide better protection against brute-force and password-spraying attacks, a unique password for each account matters more for preventing credential stuffing.
Here are some strategies that can help:
- Password manager: A tool that stores passwords using strong encryption. You can protect it with a master password and link it to your accounts for automated logins.
- Multi-factor authentication (MFA): MFA adds another layer of protection to your logins by sending an authorization request to a device or contact method you own. In most cases, an attacker would need both your password and the additional authentication method to gain access.
- Device passkeys: These let you approve logins on a device using a previously configured unlock method, like a PIN code, pattern, or biometric. Unlike passwords, they aren’t vulnerable to credential stuffing and are also resistant to phishing.
Organizations
Preventing credential stuffing attacks can be challenging. First, the services targeted in these attacks are often not the ones responsible for the original data breach or leak. Second, organizations can’t force users to create unique passwords because they have no knowledge of users’ other accounts or credentials.
To protect both themselves and their users, organizations must rely on a combination of technological safeguards and secure user practices. Here are some of the ways businesses can minimize the risk of credential stuffing attacks:
- Enforce cybersecurity hygiene: Require strong, unique passwords (or passphrases), block commonly used or compromised passwords, and require password changes when there’s a suspected breach or compromise.
- Use CAPTCHAs: Add “are you human” checks to limit bot activity. Modern techniques like reCAPTCHA v3 can detect bots without manual user input.
- Deploy proactive threat hunting: Run tools that scan devices, services, and networks for malicious logins, suspicious OAuth events, or unusual internal activity to catch intrusions before they spread.
- Use device fingerprinting: This detects repeat logins from the same source by analyzing its signature (device, browser, operating system, etc.).
- Rate-limit non-essential traffic: Block IPs, connections, or login requests when activity exceeds a specified permissible threshold.
- Block headless browsers: Legitimate users rarely access services through a headless browser like PhantomJS.
- Disallow emails as user IDs: Users often reuse the same email as a username across accounts, potentially making credential stuffing attacks more likely to succeed.
- Hash passwords: This scrambles stored passwords so that attackers must decipher them before using them. Effective protection depends on the hashing algorithm, but hashing may buy enough time to send out alerts for users to change their passwords.
- Use continuous authentication: Analyze user behavior after login and maintain access as long as it stays above a set trust score.
- Adopt passwordless authentication: Switch to passkey, biometrics, or physical security keys, as these methods are less susceptible to credential stuffing.
Real-Life Credential Stuffing Examples
Credential stuffing has played a part in numerous high-profile cyber incidents, affecting many prominent brands and millions of individuals around the world. Here are some cases from the last few years:
- New York Attorney General investigation (2022): A broad investigation by the OAG uncovered more than 1.1 million compromised accounts across 17 well-known companies, including retailers, restaurant chains, and food-delivery services.4
- PayPal (2022): Attackers used credentials obtained elsewhere to access 34,942 PayPal accounts over several days in December. The attack may have exposed victims’ personal information, including names, addresses, dates of birth, and Social Security numbers.5
- Norton LifeLock (2022): Norton detected a credential stuffing campaign targeting approximately 925,000 active and inactive accounts, including Norton Password Manager users. In response, the company sent out data breach notices to roughly 6,500 customers.6
- 23andMe (2023): Attackers used stolen credentials to compromise 18,222 accounts at the genetic testing company. They then exploited 23andMe’s DNA Relatives feature to access information associated with almost 7 million additional customers.⁷
- Roku (2024): In separate incidents, Roku suffered two credential-stuffing attacks affecting around 15,000 and 576,000 accounts, respectively. In up to 400 cases, attackers abused their access to make unauthorized purchases using stored payment methods.8
Protect Your Accounts from Credential Stuffing
Credential stuffing lets attackers exploit leaked data by targeting vast numbers of accounts on popular sites. Preventing it takes a mix of good password habits and strong authentication methods. While it can’t directly prevent credential stuffing, a VPN helps limit the data cybercriminals can collect on you, minimizing their opportunities to use it against you.
CyberGhost VPN helps improve your online privacy and security by encrypting your connections, particularly on unsecured public Wi-Fi networks. Using a VPN can be an effective part of your overall cybersecurity setup, especially when you plan on logging into sensitive accounts.
FAQ
What is a credential stuffing attack?
Credential stuffing is a type of cyberattack in which attackers try to access user accounts using known credentials. Attackers can obtain these credentials from breaches or leaks on unrelated sites. They may use automated tools or bots to carry out large numbers of fraudulent login attempts across many services.
How is credential stuffing different from brute-force attacks?
The two differ in terms of how much information the attacker knows and what they have to guess. Credential stuffing is a subset of brute force attacks where attackers attempt to log into accounts using known passwords obtained elsewhere. In conventional brute force attacks, attackers try to “guess” the password by generating and testing different combinations.
How do attackers get credentials for credential stuffing?
Attackers often obtain credentials from large data leaks, data breaches, or public archives, then automate attacks against a large number of accounts. These data sets may also contain other contextual information that attackers can leverage, such as emails, usernames, and contact details.
How can I protect my accounts from credential stuffing?
For individuals, the best advice is to minimize password reuse and secure logins with two-factor authentication (2FA) or passkeys. A password manager can also help you manage unique passwords across your accounts. Organizations can take many steps to prevent credential stuffing, such as implementing 2FA, monitoring login activity, deploying bot management solutions, blocking scam IPs, and limiting login attempts.
Does multi-factor authentication stop credential stuffing?
Multi-factor authentication (MFA) makes credential stuffing much less likely but can’t prevent it entirely. Attackers may bypass MFA by combining credential stuffing with phishing, session hijacking, adversary-in-the-middle, or other techniques. They may also complete 2FA if they can access the victim’s email account or carry out a SIM swap attack.
References
- What happened in the Collection #1-5 Breach? — databreach.com
- How Many Passwords Does the Average Person Have? — LastPass
- Password reuse is rampant: nearly half of observed user logins are compromised — Cloudflare
- Business guide for credential-stuffing attacks — New York State Attorney General
- Thousands Of PayPal Accounts Breached—Is Yours One Of Them? — Forbes
- Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner — Office of the Privacy Commissioner of Canada
- Protecting your Roku account — Roku
Leave a comment