Credential stuffing is a type of cyberattack in which the attacker collects stolen account credentials, typically lists of usernames or email addresses paired with passwords, often obtained from an earlier data breach, and then uses those credentials to gain unauthorized access to accounts on other systems through large-scale automated login attempts. It differs from credential cracking in that it does not rely on brute-force guessing; instead attackers automate logins against thousands to millions of previously exposed credential pairs using web automation tools such as Selenium, cURL or PhantomJS, or dedicated attack tools such as Sentry MBA, SNIPR, STORM, Blackbullet and OpenBullet. The attack succeeds because so many users reuse the same password across multiple sites; cited research found that 81 percent of users have reused a password across two or more sites and 25 percent use the same password across most of their accounts. Security researchers estimate credential stuffing attacks succeed roughly 2 percent of the time, meaning a list of one million stolen credentials can be expected to take over more than twenty thousand accounts, and the United States Federal Trade Commission issued guidance in 2017 recommending companies adopt defenses such as unique, password-manager-generated passwords and two-factor authentication.
Facts
Elements of OffenseUsing stolen account credentials to gain unauthorized access to accounts on other systems through large-scale automated login requests 1 Notable ExampleUber breach, October and November 2016 1 Classification
Offense GradeMinor or Summary Offense 1 Connections
Has Offense Grade
Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.
Sources
1. Credential stuffing (Wikipedia)
Lead paragraph, first sentence
uses the credentials to gain unauthorized access to user accounts on other systems through large-scale automated login requests
Incidents, Uber
In October and November 2016, attackers gained access to a private GitHub repository used by Uber (Uber BV and Uber UK) developers
View the SourceReader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.