What is Credential stuffing?

Credential stuffing is an attack in which email and password pairs stolen in other sites' breaches are tried automatically against thousands of services. It works because people reuse the same password in several places.

A leak of an employee's personal account can become a break-in to their work account if the password is the same. Unique passwords and 2FA all but stop this attack.

How to spot it

  • A login alert from a device you don't recognise

What to do

  • A unique password for work
  • Check whether your address appears in a known breach

Related courses

Terms on this topic

← Cybersecurity glossary

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.