THREAT-WATCH logo

THREAT‑WATCH

Glossary

Credential Stuffing

An attack that automatically tries username/password pairs stolen from one breach against many other websites, betting on password reuse.

Credential stuffing works because people commonly reuse the same password across multiple accounts. Attackers take credential lists from past breaches (often available on criminal marketplaces) and run them at scale against banking, email, and business logins, hoping some percentage still work elsewhere. Unique passwords per account (ideally via a password manager) fully neutralize this attack.