What is credential stuffing?¶
Credential stuffing is automated testing of username/password combinations exposed somewhere else against another service.
It relies on password reuse.
The target service does not need to have been breached at all.
The important chain has three parts¶
Each part needs its own evidence.
What might the target logs show?¶
Useful features include:
- many account attempts;
- reused username/password combinations;
- automation/user-agent patterns;
- changing proxy or hosting sources;
- rapid success after failures;
- same client/application across many accounts.
Do not reproduce unnecessary live credentials in working notes. Preserve identifiers and the evidence needed to demonstrate the pattern.
Distinguish it from spraying and brute force¶
Credential stuffing usually tests known username/password pairs.
Password spraying tries a small number of likely passwords across many users.
Brute force typically tests many password guesses against one or a small number of targets.
Those patterns can overlap, but the evidential model is different.
A successful login still needs follow-up¶
The successful account may then be used for:
- data access;
- fraud;
- account changes;
- further phishing;
- session creation.
The source infrastructure may be a proxy, botnet or compromised device and may not identify the human operator.
The practical point is: credential stuffing is cross-service credential reuse at scale. Establish the earlier exposure, the automated testing pattern and the later account control as separate links.