Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is credential stuffing?

Credential stuffing is automated testing of username/password combinations exposed somewhere else against another service.

It relies on password reuse.

The target service does not need to have been breached at all.

The important chain has three parts

Earlier exposureCredentials obtained elsewhereLeak, breach or other source.
Automated testingCombinations tried at target serviceLarge account set and repeatable client pattern.
Successful accessSome reused credentials workLater session and account activity must be examined separately.

Each part needs its own evidence.

What might the target logs show?

Useful features include:

  • many account attempts;
  • reused username/password combinations;
  • automation/user-agent patterns;
  • changing proxy or hosting sources;
  • rapid success after failures;
  • same client/application across many accounts.

Do not reproduce unnecessary live credentials in working notes. Preserve identifiers and the evidence needed to demonstrate the pattern.

Distinguish it from spraying and brute force

Credential stuffing usually tests known username/password pairs.

Password spraying tries a small number of likely passwords across many users.

Brute force typically tests many password guesses against one or a small number of targets.

Those patterns can overlap, but the evidential model is different.

A successful login still needs follow-up

The successful account may then be used for:

  • data access;
  • fraud;
  • account changes;
  • further phishing;
  • session creation.

The source infrastructure may be a proxy, botnet or compromised device and may not identify the human operator.

The practical point is: credential stuffing is cross-service credential reuse at scale. Establish the earlier exposure, the automated testing pattern and the later account control as separate links.

Reference: CIM-048Cyber Incidents & Offender Methods