Skip to Content

Credential stuffing: exploiting password reuse

Credential stuffing consists of testing username/password combinations from previous data breaches at scale across many services, betting that some users reuse the same credentials elsewhere.

Definition

Unlike brute force which guesses an unknown password, credential stuffing exploits already known credentials stolen during a breach at another service. The attack works precisely because a significant number of users reuse their passwords from one site to another.

This type of attack is easily automated at very large scale using dedicated tools, and is difficult to distinguish from legitimate traffic unless specific protection — rate limiting, MFA, behavioral detection — is in place.

Key points

Exploits reuse

The attack relies on the fact that a credential compromised elsewhere is often reused on other services.

Fueled by data breaches

Each major breach feeds databases of reusable credentials for future attacks.

MFA as a decisive protection

Even a valid credential becomes insufficient if a second authentication factor is required.

How BCIT can support you

MFA and monitoring for abnormal login attempts, covered on our page multi-factor authentication, are the direct response to this risk. We also recommend regularly checking your professional email addresses against known breach databases to anticipate this type of campaign.

Frequently asked questions ❓

How can I know if my credentials have been leaked elsewhere?

Specialized services can check whether an email address appears in databases of known breaches.

Why is MFA the most effective protection here?

Because the attack relies on an already valid credential: without a second factor, nothing prevents it from succeeding once the credential is found.

Not ready to talk yet? Discover our cybersecurity assessment →

Are your accounts exposed to reused credentials?

Let’s assess how well your access is protected against this type of automated attack.