Credential stuffing
Attackers try your leaked password on hundreds of sites until one lets them in.
What it is
Credential stuffing is an automated attack that takes username-and-password pairs stolen in one data breach and tries them on many other services. Because so many people reuse the same password, a single leak can quietly unlock email, shopping, and banking accounts across the web.
How it happens
After a company is breached, lists of logins are traded online. Attackers feed these into software that tries them against countless sites automatically. When a reused password works, they take over the account, change its recovery details, and use it to reach anything connected to it.
Warning signs
- Login alerts or “new device” notifications you didn't trigger.
- Being locked out of an account whose password suddenly no longer works.
- Password-reset emails you never requested.
- A breach-notification service warning that your details were exposed.
Who it targets
Anyone who reuses passwords is at risk, which is most people. Accounts with stored payment details, loyalty points, or resale value are especially attractive. The more breaches your email appears in, the more often your credentials get tried.
How to protect yourself
- Use a unique password for every account — a password manager makes this effortless.
- Turn on two-factor authentication so a stolen password alone isn't enough.
- Check haveibeenpwned.com to see which breaches include you, and change those passwords.
- Protect your email first; it can reset almost every other account.
- Replace any password you have used in more than one place.
If it happens to you
- Change the password on the affected account and everywhere else you used it.
- Turn on two-factor authentication and review the account's connected apps and recovery options.
- Check for changes the attacker may have made — forwarding rules, new addresses, or payees.
- If money or identity is involved, contact your bank and report it to your fraud service.