Resource icon

What is credential stuffing?

Credential stuffing means testing stolen username-and-password pairs from one service against other services. It is different from guessing random passwords: the attacker already has a pair that worked somewhere else.

Quick example​

A shopping site leaks your email and password. You used the same password for your email account. An automated attempt tries that pair at your email provider and succeeds.

What to do​

Use a unique password for every account, ideally stored in a password manager, and enable MFA on important accounts. If a site reports a breach, change that site's password and any other account where you reused it. A login attempt on another service does not prove that service was breached. OWASP distinguishes credential stuffing from password spraying and brute force.

Practical distinction​

A breach notice from one store should prompt you to check every place where you reused that password. If each service has a unique password, a leaked pair is much less useful elsewhere.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack