Credential stuffing
In plain terms
Your password leaked from a hacked site, and someone is now trying it automatically everywhere else. If you use the same password on several services, they all fall at once.
Definition
Credential stuffing is the reuse of username/password pairs obtained from a data breach against other services, betting that the same person used the same password elsewhere.
How it works
When a service is compromised, the credentials it held then circulate as lists. The attacker isn't trying to guess a password: they already have yours, and try it automatically against dozens of common services — email, shopping, social media. No flaw is exploited on the targeted service, and the login looks legitimate since it uses the correct password. This is why reusing a password turns one service's breach into the compromise of every other, sometimes years after the original leak.
Warning signs
- Login notification from an unusual device or location
- Password reset email you didn't request
- A password that stops working even though you never changed it
- A service telling you your address appears in a data breach
- Unexplained activity on a secondary account that seems worthless
How to verify
Check the account's login history, which most major services offer in their security settings: it shows dates, devices, and approximate locations. Also check your email's automatic forwarding rules, often altered after an intrusion.
What to do
Use a different password for each service — a password manager makes this practical — and enable two-factor authentication at least on email and banking. A unique password per service is enough to fully neutralize this attack.
If it already happened
Change the password of the affected account, then every account that shared it. Start with your main email: it lets you reset all the others. Revoke active sessions, check forwarding rules, and enable two-factor authentication.
Frequently asked questions
- My password is complex — am I protected?
- No, and that's what sets this attack apart from others: it doesn't try to guess. A very long password is useless if it has leaked elsewhere and is reused. The criterion that protects you is uniqueness, not complexity.
- Can a forgotten old account really be a problem?
- Yes. It often carries an email address that's still active and a password reused since then. It's a frequent entry point, precisely because no one is watching it.
Related attacks
Official sources
This article is part of the Credentials and accounts family. Last updated: 2026-08-31.