Crime and Justice Atlas

How Justice Is Served
Sign In
Text size
100%
Theme
Offense

Credential Stuffing

Cyber and Technology-Enabled Offenses

Credential stuffing is a type of cyberattack in which the attacker collects stolen account credentials, typically lists of usernames or email addresses paired with passwords, often obtained from an earlier data breach, and then uses those credentials to gain unauthorized access to accounts on other systems through large-scale automated login attempts. It differs from credential cracking in that it does not rely on brute-force guessing; instead attackers automate logins against thousands to millions of previously exposed credential pairs using web automation tools such as Selenium, cURL or PhantomJS, or dedicated attack tools such as Sentry MBA, SNIPR, STORM, Blackbullet and OpenBullet. The attack succeeds because so many users reuse the same password across multiple sites; cited research found that 81 percent of users have reused a password across two or more sites and 25 percent use the same password across most of their accounts. Security researchers estimate credential stuffing attacks succeed roughly 2 percent of the time, meaning a list of one million stolen credentials can be expected to take over more than twenty thousand accounts, and the United States Federal Trade Commission issued guidance in 2017 recommending companies adopt defenses such as unique, password-manager-generated passwords and two-factor authentication.

Facts
Elements of Offense
Using stolen account credentials to gain unauthorized access to accounts on other systems through large-scale automated login requests 1
Notable Example
Uber breach, October and November 2016 1
Classification
Offense Grade
Minor or Summary Offense 1
Connections

Has Offense Grade

Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.

Sources
1. Credential stuffing (Wikipedia)
  • Lead paragraph, first sentence
    uses the credentials to gain unauthorized access to user accounts on other systems through large-scale automated login requests
  • Incidents, Uber
    In October and November 2016, attackers gained access to a private GitHub repository used by Uber (Uber BV and Uber UK) developers
View the Source
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.