Credential stuffing
Trying, in bulk, username and password pairs stolen in other sites' breaches to get into the accounts of people who reuse the same details.
- 01
Why it matters
Many people use the same password on several sites, so a breach elsewhere puts accounts on your site at risk too. The attack does not look like individual attempts; it comes from distributed addresses. Multi-factor authentication, blocking leaked passwords and detecting suspicious sign-ins are the most effective measures.
- 02
Example
On a shop, hundreds of customer accounts are successfully accessed overnight from different countries and their saved points are spent. Nothing leaked from the shop's own systems; the customers reused passwords exposed in another breach.
- 03
Common mistake
Treating the problem as purely the users' fault. If accounts on your site are being taken over, customer trust and your brand suffer; protection has to be built on the site's side.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.