Credential Stuffing
An attack that replays username and password pairs leaked from other breaches against a target, exploiting password reuse. Defended with MFA, passkeys, and bot detection.
Credential stuffing works because password reuse is near-universal and the attacker's cost per attempt is close to zero. Rate limiting alone loses: modern kits distribute across residential proxies at low volume per IP. What actually breaks the economics is removing the reusable secret, which is why passkey rollouts show sharp drops in stuffing success, and detecting the pattern at the population level rather than per account.
See also: account takeover, password spraying, phishing-resistant MFA, Snowflake 2024 credential attacks
Related on Start with Identity
- GlossaryInfostealer
Malware that harvests credentials, cookies, and session tokens from infected devices, then sells them. A major driver of recent account-takeover and session-the
- GlossaryLateral Movement
How an attacker moves from an initial foothold to other systems and accounts, often abusing identity and trust relationships. A primary target of identity threa
- GlossarySession Hijacking
Stealing a valid session, commonly via a captured session cookie or token, to impersonate a user and bypass MFA. Mitigated by token binding, short lifetimes, an
- BlogChick-fil-A's second credential stuffing breach in three years hit 13,322 loyalty accounts
Automated login attempts using credentials obtained from a third-party source, not a Chick-fil-A breach, compromised 13,322 Chick-fil-A One loyalty accounts ove
- TechniqueCredential stuffing
Attackers replay username and password pairs leaked from one breach against every other login page they can reach, betting on the well-documented habit of passw
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a