Browse Definitions :
Definition

credential stuffing

Credential stuffing is the practice of using stolen login information from one account to gain access to accounts on a number of sites through automated login. The exploit can allow hackers and those buying stolen credentials to access not just the accounts from the sites they are stolen from but any account where the victim uses the same password.

After obtaining credentials for a number of sites, a hacker may sell a list of user IDs, passwords and email addresses. It is common for these lists to be sold on underground or on the dark web. Whether lists are sold or used by the hacker themselves, it is likely the holder of the account details will want to get as much value from the accounts as possible.

Even though a single account was breached, it can lead to the simultaneous compromise of other sites used by the victim because the credentials are input for multiple sites using automated logins. The attacker often compromises multiple accounts before the user is aware that their account for any site has been breached.

Credential stuffing is a serious threat to both consumers and businesses, which both stand to lose money, either directly or indirectly. In retail in the United Kingdom, it is claimed that over 90 percent of logins come from credential stuffing attacks rather than authentic users. Eliminating these logins could make a significant impact on decreasing credential stuffing.

From an end-user perspective, it's recommended to create different and sufficiently strong passwords for each site. For the site or service provider, tools such as Shape Security's Blackfish or Fortinet's Fortiguard can help fight credential stuffing.

This was last updated in February 2018

Continue Reading About credential stuffing

Networking
  • firewall as a service (FWaaS)

    Firewall as a service (FWaaS), also known as a cloud firewall, is a service that provides cloud-based network traffic analysis ...

  • private 5G

    Private 5G is a wireless network technology that delivers 5G cellular connectivity for private network use cases.

  • NFVi (network functions virtualization infrastructure)

    NFVi (network functions virtualization infrastructure) encompasses all of the networking hardware and software needed to support ...

Security
  • phishing

    Phishing is a fraudulent practice in which an attacker masquerades as a reputable entity or person in an email or other form of ...

  • computer forensics (cyber forensics)

    Computer forensics is the application of investigation and analysis techniques to gather and preserve evidence from a particular ...

  • cybersecurity

    Cybersecurity is the practice of protecting internet-connected systems such as hardware, software and data from cyberthreats.

CIO
HRSoftware
  • OKRs (Objectives and Key Results)

    OKRs (Objectives and Key Results) encourage companies to set, communicate and monitor organizational goals and results in an ...

  • cognitive diversity

    Cognitive diversity is the inclusion of people who have different styles of problem-solving and can offer unique perspectives ...

  • reference checking software

    Reference checking software is programming that automates the process of contacting and questioning the references of job ...

Customer Experience
  • martech (marketing technology)

    Martech (marketing technology) refers to the integration of software tools, platforms, and applications designed to streamline ...

  • transactional marketing

    Transactional marketing is a business strategy that focuses on single, point-of-sale transactions.

  • customer profiling

    Customer profiling is the detailed and systematic process of constructing a clear portrait of a company's ideal customer by ...

Close