Browse Definitions :
Definition

credential stuffing

Credential stuffing is the practice of using stolen login information from one account to gain access to accounts on a number of sites through automated login. The exploit can allow hackers and those buying stolen credentials to access not just the accounts from the sites they are stolen from but any account where the victim uses the same password.

After obtaining credentials for a number of sites, a hacker may sell a list of user IDs, passwords and email addresses. It is common for these lists to be sold on underground or on the dark web. Whether lists are sold or used by the hacker themselves, it is likely the holder of the account details will want to get as much value from the accounts as possible.

Even though a single account was breached, it can lead to the simultaneous compromise of other sites used by the victim because the credentials are input for multiple sites using automated logins. The attacker often compromises multiple accounts before the user is aware that their account for any site has been breached.

Credential stuffing is a serious threat to both consumers and businesses, which both stand to lose money, either directly or indirectly. In retail in the United Kingdom, it is claimed that over 90 percent of logins come from credential stuffing attacks rather than authentic users. Eliminating these logins could make a significant impact on decreasing credential stuffing.

From an end-user perspective, it's recommended to create different and sufficiently strong passwords for each site. For the site or service provider, tools such as Shape Security's Blackfish or Fortinet's Fortiguard can help fight credential stuffing.

This was last updated in February 2018

Continue Reading About credential stuffing

Networking
  • remote infrastructure management

    Remote infrastructure management, or RIM, is a comprehensive approach to handling and overseeing an organization's IT ...

  • port address translation (PAT)

    Port address translation (PAT) is a type of network address translation (NAT) that maps a network's private internal IPv4 ...

  • network fabric

    'Network fabric' is a general term used to describe underlying data network infrastructure as a whole.

Security
  • DNS over HTTPS (DoH)

    DNS over HTTPS (DoH) is a relatively new protocol that encrypts domain name system traffic by passing DNS queries through a ...

  • governance, risk and compliance (GRC)

    Governance, risk and compliance (GRC) refers to an organization's strategy for handling the interdependencies among the following...

  • total risk

    Total risk is an assessment that identifies all the risk factors associated with pursuing a specific course of action.

CIO
  • microtargeting

    Microtargeting (also called micro-niche targeting) is a marketing strategy that uses consumer data and demographics to identify ...

  • business process

    A business process is an activity or set of activities that accomplish a specific organizational goal. Business processes should ...

  • business process improvement (BPI)

    Business process improvement (BPI) is a practice in which enterprise leaders analyze their business processes to identify areas ...

HRSoftware
  • employee onboarding and offboarding

    Employee onboarding involves all the steps needed to get a new employee successfully deployed and productive, while offboarding ...

  • skill-based learning

    Skill-based learning develops students through hands-on practice and real-world application.

  • gamification

    Gamification is a strategy that integrates entertaining and immersive gaming elements into nongame contexts to enhance engagement...

Customer Experience
  • Microsoft Dynamics 365

    Dynamics 365 is a cloud-based portfolio of business applications from Microsoft that are designed to help organizations improve ...

  • Salesforce Commerce Cloud

    Salesforce Commerce Cloud is a cloud-based suite of products that enable e-commerce businesses to set up e-commerce sites, drive ...

  • Salesforce DX

    Salesforce DX, or SFDX, is a set of software development tools that lets developers build, test and ship many kinds of ...

Close