Credential stuffing is an automated account takeover attack in which attackers use username-and-password pairs exposed in one data breach to try to access accounts on other websites, applications, APIs, or remote access services. The attack succeeds primarily when people reuse the same credentials across multiple accounts.
Unlike a traditional brute-force attack, credential stuffing does not rely on guessing passwords. Attackers test credentials that may already be valid, often using bots, distributed IP addresses, device spoofing, and carefully controlled request rates to make malicious login attempts resemble normal traffic.
Credential stuffing is also different from password spraying. Credential stuffing tests previously compromised username-and-password pairs, while password spraying tests one or a small number of common passwords against many accounts.
Key Takeaway
Credential stuffing uses stolen username-and-password pairs to take over accounts where credentials have been reused.
Organizations need layered controls across authentication, automated traffic detection, account monitoring, and incident response because no single control can reliably stop every attack.
How Credential Stuffing Works
Most credential stuffing attacks follow four stages:
-
Attackers obtain stolen credentials. Lists of usernames and passwords may come from breaches, malware, phishing, or criminal marketplaces.
-
Automated tools test the credentials. Bots submit the pairs to login pages or authentication APIs at scale.
-
Successful logins are validated. Attackers identify accessible accounts and assess their value.
-
Compromised accounts are exploited. Attackers may commit fraud, steal information, change recovery details, or resell access.
Credential stuffing can target website login forms, mobile app APIs, customer portals, loyalty programs, stored-value accounts, VPNs, and remote access gateways. Every authentication endpoint therefore needs equivalent protection.
Real-World Credential Stuffing Examples
Credential stuffing can affect organizations even when their own systems were not the source of the stolen passwords. The following examples show how reused credentials can lead to account takeover, data exposure, and fraud.
| Example | What Happened | Security Lesson |
|---|---|---|
| 23andMe | In 2023, a threat actor used credentials reused from previously compromised websites to access 0.1% of 23andMe user accounts. Through connected features, the attacker also accessed approximately 5.5 million DNA Relatives profiles and 1.5 million Family Tree profiles. | Connected and shared-data features can greatly expand the impact of a small number of compromised accounts. Authentication controls should be paired with authorization limits and monitoring of downstream data access. |
| Dunkin’ | Beginning in 2015, credential stuffing attacks compromised tens of thousands of Dunkin’ customer accounts, including accounts containing stored-value cards. A New York settlement required customer notifications, password resets, refunds, stronger safeguards, and improved incident-response procedures. | Organizations must investigate attacks promptly, protect stored-value balances, reset exposed credentials, notify affected customers, and monitor compromised accounts for unauthorized transactions. |
| Ring | The FTC reported that Ring experienced multiple credential stuffing attacks in 2017 and 2018 but did not introduce multifactor authentication until 2019. Hackers accessed stored videos, live streams, and account profiles belonging to approximately 55,000 U.S. customers. | MFA should be deployed early and implemented correctly, especially when account takeover can expose cameras, recordings, personal information, or other sensitive connected-device functions. |
The Business Impact of Credential Stuffing
Credential stuffing can create substantial financial and operational costs even when only a small percentage of attempted logins succeeds. Once an attacker gains access to an account, the attacker may:
- Make purchases using stored payment methods
- Steal gift cards, loyalty points, credits, or stored-value balances
- Access personal, financial, or confidential information
- Change contact information or account recovery settings
- Use the account to conduct phishing or other fraud
- Sell the validated account to another criminal
The affected organization may also incur chargebacks, customer-support costs, fraud investigations, password-reset expenses, authentication infrastructure load, application downtime, regulatory obligations, and customer churn.
These consequences can arise even when the organization being targeted did not suffer the original data breach. Businesses that maintain customer accounts must therefore treat stolen-credential reuse as an expected authentication risk and build controls around both login activity and post-login behavior.
Credential Stuffing vs. Brute Force and Password Spraying
Credential stuffing, brute force, and password spraying are related account attacks, but they use different inputs and exploit different weaknesses.
| Attack Type | How It Works | Primary Weakness |
|---|---|---|
| Credential Stuffing | Tests stolen username and password pairs across accounts or services | Password reuse |
| Brute Force | Tries many possible passwords against one account or a small number of accounts | Weak or guessable passwords |
| Password Spraying | Tries one or a few common passwords against many accounts | Common passwords and weak lockout policies |
A strong, complex password can still be compromised through credential stuffing if it was exposed elsewhere and reused. Password strength is more relevant to guessing attacks. Unique credentials, compromised-password screening, MFA, passkeys, and bot detection address credential stuffing risk more directly.
How to Detect Credential Stuffing Attacks
Credential stuffing detection requires correlation across accounts, devices, networks, sessions, and authentication endpoints. A single failed login may appear harmless, while thousands of related attempts can reveal a coordinated campaign.
Key warning signs include:
- Unusual increases in failed or successful login volume
- A sudden change in the ratio of failed to successful authentications
- One device, browser profile, or connection fingerprint accessing multiple accounts
- Distributed attempts across rotating IP addresses, subnets, autonomous system numbers, or regions
- Low-and-slow activity that remains below simple rate limits
- Abnormal login velocity, geography, device usage, or post-login behavior
- Immediate changes to passwords, recovery details, payment methods, or delivery addresses
- Different attack patterns across website, mobile application, and API endpoints
No single signal proves that a credential stuffing attack is occurring. Combining account, device, browser, network, timing, and behavioral data improves detection while reducing false positives. Organizations evaluating a credential stuffing detection service should also confirm that it can correlate distributed activity across every login channel.
Responding to an active credential stuffing attack
Once an attack is confirmed:
- Challenge, throttle, or block suspicious traffic using multiple risk signals.
- Identify accounts where the correct password was used or unusual activity followed a login.
- Revoke active sessions, refresh tokens, remembered devices, and exposed API tokens.
- Require password resets and prevent reuse of known compromised passwords.
- Apply MFA or step-up verification before restoring sensitive access.
- Review profile, payment, recovery, shipping, and transaction changes.
- Notify affected customers through trusted channels.
- Preserve logs and coordinate security, fraud, legal, privacy, and support teams.
- Monitor affected accounts for follow-on fraud, phishing, or renewed access.
Organizations should document and test these steps before an incident occurs.
How to Prevent Credential Stuffing Attacks
How users can protect themselves
Users should create a unique password for every account, use a reputable password manager, enable MFA or passkeys, review active sessions, reject unexpected authentication prompts, and change reused passwords after credible breach notifications.
Strengthen authentication and credential security
Organizations should screen new and changed passwords against known compromised-password data. MFA, passkeys, and risk-based step-up authentication should protect unusual logins and sensitive actions.
OWASP identifies MFA as the strongest general defense against password-related attacks.
Control automated login traffic
Apply behavioral bot detection, device and connection fingerprinting, network reputation, advanced rate limits, and adaptive challenges. Evaluate traffic by account, IP address, endpoint, device, session, and behavior rather than relying on one threshold.
Protect accounts after login
Monitor successful sessions for unusual profile changes, recovery updates, payment changes, loyalty redemptions, and transaction patterns. Allow users to review active sessions, revoke suspicious access, and receive alerts about sensitive account events.
Controls that are insufficient on their own
CAPTCHA, IP blocking, account lockouts, password complexity, and basic rate limits can reduce risk, but each may be bypassed or create unnecessary customer friction. Layered controls provide stronger protection and reduce dependence on any single detection method.
How CDNetworks Helps Prevent Credential Stuffing
CDNetworks Bot Shield helps organizations detect and mitigate automated account takeover activity across websites, applications, and APIs.
Its capabilities include advanced rate limiting across parameters such as IP address, URI, HTTP headers, and end-user ID, alongside fingerprint challenges, human behavior detection, real-time monitoring, alerts, and configurable response actions.
In addition to malicious bot protection, CDNetworks delivers layered protection and acceleration to help keep websites, applications, and APIs secure, responsive, and available. The CDNetworks portfolio includes:
DDoS Protection: Maintain service availability with cloud-based protection against volumetric, protocol-based, and application-layer DDoS attacks.
CDN: Improve content delivery performance by caching content at edge locations closer to users, reducing latency and origin load.
Web Application Firewall (WAF): Permit legitimate traffic while detecting and blocking malicious requests, common web exploits, and application-layer attacks at the edge.
API Security: Protect API endpoints by controlling access, identifying exposed or vulnerable APIs, and detecting malicious activity before it can affect backend services.
Credential Stuffing FAQs
What does credential stuffing mean?
Credential stuffing involves using stolen username-and-password pairs to access accounts on other services, typically via automated login attempts.
Is credential stuffing the same as brute force?
Brute-force attacks guess passwords, while credential stuffing tests previously exposed credentials that may already be valid on another service.
Does MFA stop credential stuffing?
MFA blocks many takeover attempts because a stolen password alone is insufficient, but organizations should still monitor recovery abuse, session theft, and suspicious post-login activity.
How can users protect themselves from credential stuffing?
Users should create unique passwords, use a password manager, enable MFA or passkeys, review active sessions, and replace reused passwords after credible breach notifications.
What is password stuffing?
Password stuffing is an informal term for credential stuffing, which tests exposed username-and-password pairs across other websites, applications, or services.
Does a strong password prevent credential stuffing?
Complexity alone cannot prevent credential stuffing because an exposed password may still work elsewhere. Unique passwords, MFA, compromised-password screening, and bot detection provide stronger protection.
Can credential stuffing target APIs and mobile apps?
Attackers can target website forms, mobile app APIs, authentication APIs, customer portals, VPNs, and any other endpoint that accepts reusable credentials.
