Security

Credential Stuffing

Automated attempts to sign in using passwords leaked from another service. Reusing a password makes one breach affect several accounts, so use a unique password for each account.

How it works

Credential stuffing tries previously obtained username and password combinations against other services. It relies on password reuse rather than guessing every character from scratch. An account on a well-maintained service can therefore be exposed by credentials stolen from a completely different website.

A practical example

If someone reuses the same email and password for a shop and a mailbox, a leak at the shop can provide a combination to try at the mailbox. Successful access there may enable further password resets. This is an illustrative chain, not proof that every leaked password still works.

What to check

Use a distinct password for each service and enable an appropriate additional authentication method. After a suspected credential leak, replace the reused password on every affected account, starting with important recovery accounts. Review active sessions, forwarding settings and recovery details. Service operators should also monitor unusual login patterns and apply appropriate abuse controls.

Limits and safe use

Changing a password on only the breached website does not protect another site still using the old combination. Extra authentication reduces risk but does not eliminate session theft or deceptive approval requests. Unexpected failed logins can have other explanations; assess provider records rather than assuming that one alert proves a successful takeover.

Technical sources

← All glossary terms