What Is Credential Stuffing? Meaning, Attack and Defenses
Credential stuffing uses stolen passwords from other breaches to break into your accounts. Here is how it works, how it differs from brute force, and how to stop it.

Credential stuffing is an automated attack in which criminals take username-and-password pairs stolen from one website's data breach and "stuff" them into the login forms of completely unrelated websites, betting that at least some victims reused the same password. It is not guessing and it is not hacking in the traditional sense — the attacker already has working logins, just for the wrong site, and a botnet quietly tries each pair at scale until a percentage of them work somewhere else.
Quick facts
- What it is: automated login attempts using real, previously-breached username/password pairs, replayed against other sites.
- Why it works: widespread password reuse across accounts — one breach can unlock logins everywhere else the same password was used.
- Not the same as: brute force (random guessing against one account) or password spraying (one common password tried across many accounts).
- Best individual defense: a unique, randomly generated password per site, managed by a password manager, plus MFA or passkeys.
- Check yourself: Have I Been Pwned (haveibeenpwned.com) lets you search whether your email has appeared in known breach dumps.
What is credential stuffing?
Credential stuffing is a type of automated threat that the Open Web Application Security Project (OWASP) catalogs as OAT-008 in its Automated Threat Handbook. OWASP defines it plainly as "mass log in attempts used to verify the validity of stolen username/password pairs." The pairs themselves are not invented by the attacker — they are lifted wholesale from a previous, unrelated data breach, a criminal marketplace sale, or a public breach dump, then fired at the login page of a different service entirely.
The mechanics are simple and that simplicity is exactly why the attack is so common. An attacker doesn't need to compromise your bank, your retailer, or your streaming account directly. They only need one data breach, anywhere, that exposed your email and password — then they test that same pair against hundreds of other sites, hoping you reused it. Security researchers sometimes call this "password replay," "list cleaning," or simply account takeover by credential reuse.
How a credential stuffing attack actually works
A typical credential stuffing campaign follows a predictable pipeline:
- Acquire a credential list. The attacker obtains a large file of email/password (or username/password) pairs, usually sourced from a prior, unrelated breach.
- Load it into stuffing software. Purpose-built tools (often sold or shared on underground forums) automate the process of submitting each pair to a target site's login form.
- Distribute the traffic. To avoid triggering basic rate limits or an IP block, the attack is spread across thousands of proxy IP addresses or a botnet of infected devices, so each individual source looks like a normal, isolated login attempt.
- Harvest the hits. Even a very low success rate — industry research on stuffing campaigns commonly cites hit rates in the low single digits — can yield thousands of working accounts out of a list of millions of credential pairs.
- Monetize the access. Compromised accounts are drained, resold, or used as a foothold: loyalty points, stored payment methods, gift card balances, email accounts used to reset other passwords, or just a verified login sold on to the next buyer.
OWASP's own technical notes tie the automation side of this to a lack of "anti-automation" controls (cataloged as WASC-21, Insufficient Anti-Automation) — meaning a login form that cannot distinguish a script firing thousands of attempts per minute from a real person typing is exactly the kind of target this attack is built for.
Where attackers get the credential lists
None of the usernames or passwords in a stuffing list are "cracked" in the traditional sense — they're copied. The main sources are:
- Breach dumps. When a company is breached and its user database (or a password-adjacent dataset) leaks, that data circulates — first sold privately, then eventually posted more widely. Have I Been Pwned exists specifically to track and index these dumps so people can check whether their own email address has shown up in one.
- Combo lists. Attackers merge and deduplicate records from dozens or hundreds of separate breaches into huge "combination" (combo) lists of email:password pairs, sometimes hundreds of millions of rows long, stripped of any indication which original breach each row came from.
- Criminal marketplaces. Fresh, unverified, or higher-quality lists are bought and sold directly between threat actors, as OWASP's OAT-008 entry notes alongside the more common route of public dumps.
- Infostealer malware logs. A growing share of circulating credentials doesn't come from a breached company database at all — it comes from credential-stealing malware quietly logging what a victim typed into their own browser, then uploading that log for sale.
This is also where Pandromeda's recent run of breach coverage connects to the bigger picture. Stories like the Georgia Power data breach, the DriveWealth data breach, and the ASOS data breach each involved the exposure of customer account data. To be clear, none of those incidents has been confirmed as a credential-stuffing attack itself — but breaches like these are exactly where stuffing lists come from downstream, once exposed credentials are compiled, combined with data from other breaches, and recirculated. A password typed into one breached service years ago can still end up being tried against your email, your bank, or your retail accounts today, which is precisely why reuse is the single factor that turns an old, unrelated breach into a new account takeover.
Credential stuffing vs. brute force vs. password spraying
These three terms get used interchangeably in headlines, but they describe different attack logic, and the distinction matters because the defenses differ too. The clearest primary-source comparison comes from the US Cybersecurity and Infrastructure Security Agency, which in its advisory on brute-force attacks explicitly separates "traditional" brute forcing from password spraying — and the same logic is what separates both from credential stuffing.
Credential Stuffing vs Brute Force vs Password Spraying
| Attack | What's tried | Target scope | Why it evades defenses | Best defense |
|---|---|---|---|---|
| Credential stuffing | Real, previously-breached username/password pairs | Many accounts across many unrelated sites | Each login attempt uses a correct-looking, real-world credential pair, not a guess | Unique password per site + MFA/passkeys |
| Brute force (classic) | Every possible password combination, guessed | One specific target account | N/A — usually triggers lockouts quickly, which is why it's less common at scale today | Account lockouts, rate limiting, long passwords |
| Password spraying | A small list of common passwords (e.g. "Summer2026!") | Many accounts, one password at a time, before moving to the next password | Low attempts per account avoids per-account lockout thresholds | Ban weak/common passwords, MFA, login anomaly detection |
In plain terms: classic brute force guesses blindly against one account and usually gets locked out fast. Password spraying flips that around — it tries one common password against thousands of accounts before trying a second password, deliberately staying under the radar of per-account lockout limits (CISA's own advisory describes this as a "low-and-slow" technique). Credential stuffing is different from both because there's no guessing at all: the attacker already has a correct, working password — just for a different website — and is simply testing whether you reused it. That's also why credential stuffing tends to have a much higher success rate per attempt than either brute force or spraying, even though all three rely on automation to work at scale.
Warning signs you may have been targeted
Credential stuffing usually happens invisibly, against sites you use, without you doing anything wrong in the moment. Signs worth taking seriously include:
- Unexpected login or "new device" alerts from a service for a login you didn't make, especially from an unfamiliar location.
- Password reset emails you didn't request — sometimes a sign an attacker tried your email as a username and the site responded.
- Account lockout notices you didn't trigger, which can mean automated attempts hit a rate limit before succeeding.
- Unfamiliar orders, messages, or loyalty-point redemptions appearing in an account you still control but haven't used recently.
- A breach notification naming a site you used — especially one where you know you reused that same password elsewhere.
- A positive result on Have I Been Pwned for your email address, which doesn't confirm an account was taken over, but does confirm your credentials are circulating and could be tried elsewhere.
How to protect yourself from credential stuffing
Because credential stuffing exploits reuse rather than weak passwords specifically, the defenses are different from classic "pick a stronger password" advice:
- Use a unique password for every site. This is the single control that neutralizes credential stuffing outright: if a password is never reused, a stolen pair from Site A is simply useless against Site B. A password manager makes this realistic by generating and storing a long, random password per account so you never have to remember or reuse one.
- Turn on multi-factor authentication (MFA), or switch to passkeys where offered. Even a correct, stolen password stops working as a login on its own once a second factor — an authenticator app code, a hardware key, or a passkey tied to your device — is required. NIST's digital identity guidelines (SP 800-63B) treat this kind of layered authentication as core guidance for any account handling sensitive data.
- Check Have I Been Pwned periodically and set up its free notification service so you're alerted automatically the next time your email surfaces in a new breach, rather than finding out from the attacker.
- Never reuse your email password anywhere else. Your inbox is usually the master key to every other account via "forgot password" links — treat it as the single most important password you own.
- Watch for compromised-password warnings from your browser or password manager — Chrome, Safari, and most major password managers now cross-check your saved logins against known breach data and will flag reused or exposed passwords automatically.
- Be skeptical of unexpected login or lockout notifications — don't click links in them; log in directly through the site or app instead, and change the password there if anything looks off.
What websites and services do to stop it
Individual password hygiene matters, but credential stuffing is ultimately a problem of scale that login systems also have to defend against. OWASP's Credential Stuffing Prevention Cheat Sheet lays out the main technical countermeasures site operators use, including multi-factor authentication, CAPTCHA or similar anti-automation challenges on login forms, rate limiting and device/IP reputation checks, and — the control most directly tied to this specific attack — screening newly chosen passwords against lists of known-compromised values at signup and reset, which is also the exact recommendation NIST makes in SP 800-63B. None of these are visible to you as a user, but they're why some sites quietly force a password reset after a large breach is publicly reported elsewhere, even if that site itself wasn't the one breached.
Is credential stuffing illegal?
Yes. Gaining unauthorized access to an account — even using a "correct" password that was simply stolen from elsewhere — is unauthorized computer access under laws like the US Computer Fraud and Abuse Act and equivalent legislation in most other countries, regardless of whether the attacker had to "break" anything to get in. The credentials being real, rather than guessed, doesn't change that the access itself was never authorized.
What to do right now
If you want to check your own exposure today, this is the fastest path:
- Search your email address on Have I Been Pwned and turn on its free breach notifications.
- Open your password manager's security/breach-check dashboard (or your browser's built-in one) and fix every password flagged as reused or compromised, starting with email, banking, and any account with stored payment details.
- Turn on MFA or passkeys on those same high-value accounts first, then work outward.
- Stop reusing passwords going forward — let a password manager generate a new, unique one every time you sign up for something.
None of this requires guessing which breach your password came from. The whole point of credential stuffing is that it doesn't matter which breach leaked it — what matters is whether you reused it anywhere else.
Frequently asked questions
What does credential stuffing mean?
Credential stuffing is an automated cyberattack where criminals take username-and-password pairs stolen from one website's data breach and test them against the login forms of many other, unrelated websites. It works because people reuse the same password across multiple accounts.
How is credential stuffing different from a brute-force attack?
Classic brute force guesses passwords for one specific account through trial and error, and usually triggers a lockout quickly. Credential stuffing uses no guessing at all -- it replays real, already-correct username/password pairs stolen from a previous breach against a different site, so it doesn't rely on cracking anything.
How is credential stuffing different from password spraying?
Password spraying tries one common, guessed password (like a seasonal password) against many different accounts before moving to a second guessed password, staying under per-account lockout limits. Credential stuffing instead uses real, previously-breached credential pairs rather than guesses, which typically gives it a much higher success rate.
How do I know if I've been a victim of credential stuffing?
Warning signs include login or new-device alerts you didn't trigger, unexpected password-reset emails, account lockout notices you didn't cause, unfamiliar orders or loyalty-point activity, and your email address turning up on a breach-monitoring service like Have I Been Pwned.
Can a password manager really stop credential stuffing?
Yes, for your own accounts. Credential stuffing only works when a stolen password from one site is also valid on another. A password manager that generates and stores a unique, random password for every account removes that overlap entirely, so a breach elsewhere can't be reused against you.
Is credential stuffing illegal?
Yes. Logging into an account without authorization is unauthorized computer access under laws such as the US Computer Fraud and Abuse Act and similar laws elsewhere, regardless of whether the password used was guessed, stolen, or technically 'correct'.
Sources
- OWASP Automated Threat Handbook: OAT-008 Credential Stuffingowasp.org
- OWASP Cheat Sheet Series: Credential Stuffing Preventioncheatsheetseries.owasp.org
- CISA/FBI Advisory TA18-086A: Brute Force Attacks Conducted by Cyber Actorscisa.gov
- NIST SP 800-63B: Digital Identity Guidelines - Authentication and Lifecycle Managementpages.nist.gov
- Have I Been Pwned: Check if your email has been exposed in a data breachhaveibeenpwned.com
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


