Skip to content

Credential stuffing

In plain terms

Your password leaked from a hacked site, and someone is now trying it automatically everywhere else. If you use the same password on several services, they all fall at once.

Definition

Credential stuffing is the reuse of username/password pairs obtained from a data breach against other services, betting that the same person used the same password elsewhere.

How it works

When a service is compromised, the credentials it held then circulate as lists. The attacker isn't trying to guess a password: they already have yours, and try it automatically against dozens of common services — email, shopping, social media. No flaw is exploited on the targeted service, and the login looks legitimate since it uses the correct password. This is why reusing a password turns one service's breach into the compromise of every other, sometimes years after the original leak.

Warning signs

  • Login notification from an unusual device or location
  • Password reset email you didn't request
  • A password that stops working even though you never changed it
  • A service telling you your address appears in a data breach
  • Unexplained activity on a secondary account that seems worthless

How to verify

Check the account's login history, which most major services offer in their security settings: it shows dates, devices, and approximate locations. Also check your email's automatic forwarding rules, often altered after an intrusion.

What to do

Use a different password for each service — a password manager makes this practical — and enable two-factor authentication at least on email and banking. A unique password per service is enough to fully neutralize this attack.

If it already happened

Change the password of the affected account, then every account that shared it. Start with your main email: it lets you reset all the others. Revoke active sessions, check forwarding rules, and enable two-factor authentication.

Frequently asked questions

My password is complex — am I protected?
No, and that's what sets this attack apart from others: it doesn't try to guess. A very long password is useless if it has leaked elsewhere and is reused. The criterion that protects you is uniqueness, not complexity.
Can a forgotten old account really be a problem?
Yes. It often carries an email address that's still active and a password reused since then. It's a frequent entry point, precisely because no one is watching it.

Official sources

This article is part of the Credentials and accounts family. Last updated: 2026-08-31.