Credential stuffing: the attack that exploits password reuse

Nobody needs to single you out. It is enough that a shop you once bought from suffers a breach and that you used the same password there as on your email. From that point a program does the work, against millions of people at once.
There is a mental image almost everyone has of a computer attack: someone decides to get into your account and starts trying passwords. That image is wrong, and it is why people misjudge their own risk. They think “who would bother attacking me?” and the answer is nobody. Nobody has to.
The most common attack against personal accounts is called credential stuffing, and it works the other way round: it does not choose targets, it works through them.
How it works, step by step
1. Someone steals a database. An online shop, a forum, a fitness app — any service with users. The breach can go unnoticed for months.
2. That list circulates. It is sold, shared, or eventually published for free. It contains email addresses and passwords. If the service stored passwords badly — unencrypted, or with outdated hashing — they are directly readable.
3. A program tries them elsewhere. Here is the trick. The attacker does not try to get into the service that was breached: they try those same email-and-password pairs on Gmail, Amazon, Netflix, PayPal, Instagram, banks. All automated, from thousands of different addresses so as not to draw attention.
4. A small percentage works. And that is enough. If 1% of two million credentials still works on another service, that is twenty thousand accounts opened without guessing anything.
The economics are what make it unstoppable: the cost per attempt is effectively zero and the raw material is real rather than invented.
Why it is more dangerous than brute force
A brute-force attack tries invented combinations. It is noisy — thousands of failed attempts against one account — and services detect and block it easily.
Credential stuffing is quiet. It tries once per account, with a password that is very likely correct. There is no burst of failures to trigger any alarm. From the attacked service’s point of view, it looks a great deal like ordinary people signing in.
That is why the classic defence — lock the account after five failed attempts — does not stop it.
What they do with the account once inside
It depends where they get in, and it is rarely what you imagine.
- Email. The jackpot. From there they request password resets on everything else. They also set up silent forwarding rules to keep reading your correspondence after you change the password.
- Accounts with balances or points. Gift cards, loyalty points, app credit. These turn into cash quickly and victims often take months to look.
- Subscriptions. Streaming accounts get resold cheaply. It is an enormous, boring market, and being boring is exactly why it goes unnoticed.
- Social media. To scam your contacts while pretending to be you. A message asking for money from your real account works far better than from a fake one.
- Work accounts. Here the goal is usually bigger: access to internal systems or invoice fraud.
The signs it has been tried on you
- Password reset emails you did not request.
- Sign-in alerts from unfamiliar locations or devices.
- Two-factor codes arriving when you are not signing in. This means somebody already has your correct password and only lacks the second factor. It is a serious alarm: change the key immediately.
- Being logged out of a session for no reason.
- A warning from your browser or manager that one of your passwords appeared in a breach.
The two defences that work
Everything else is secondary to these two.
1. A different password on every site
This is the complete defence against this particular attack. If your password for that shop was only ever used at that shop, the leaked list opens absolutely nothing else. The attack runs out of raw material.
You do not have to memorise them: that is what password managers are for. And for new ones, the generator creates a random key in a second.
2. Two-factor authentication
This is the safety net for when the first one fails. Even with the correct password, without the second factor there is no entry. Turning it on for email alone cuts off the most dangerous escalation path.
What you can do today, in ten minutes
- Check in the breach checker whether any of your usual keys is already circulating.
- If it appears: change it on every site where you used it, not just one.
- Turn on two-factor authentication for your email.
- Check your email forwarding rules, in case someone is already inside.
In short
- Nobody chooses you: a program works through leaked lists and tries them across dozens of services.
- It works because people reuse passwords, not because it guesses them.
- It is quiet: one attempt per account, with a probably-valid key.
- Unique passwords disarm it. Two-factor stops it even when that fails.
- A verification code arriving when you are not signing in means they already have your password.
Frequently asked
The questions that keep coming up
What is credential stuffing?
It is an automated attack that takes lists of usernames and passwords leaked from one service and tries them on many others, exploiting the fact that many people reuse the same password across sites.
How is it different from brute force?
Brute force tries invented combinations until one works. Credential stuffing invents nothing: it uses real passwords that have already leaked, which is why it succeeds with far fewer attempts and is much harder to detect.
How do I know if someone has tried to get into my account?
Check the sign-in history and failed-attempt alerts offered by services like Google or Microsoft. A password reset email you did not request is also a clear signal.
What stops this attack?
Two things, in this order: using a different password on every service, and turning on two-factor authentication. The first makes the leaked list useless; the second means that even if it is not, the password alone is not enough.


