What Is Credential Stuffing and Why Reusing Passwords Is Dangerous
Patrick Bushe
September 18, 2024 · 5 min read
Credential stuffing is an attack where criminals take usernames and passwords leaked from one website and try them on many others. It works because so many people reuse the same password. It's one of the most common ways accounts are taken over.
How it works
- A website is breached and its users' emails and passwords leak.
- Those lists are sold or shared, sometimes combined into huge collections with billions of entries.
- Attackers use automated tools to try each email and password on banks, shops, email providers and streaming services.
- Only a small share of attempts work, but with millions of pairs that's still a lot of accounts.
- Accounts that work are used for fraud, sold, or used to find more personal information.
A real example
In 2023, attackers used credential stuffing to break into about 14,000 accounts at the genetic testing company 23andMe. Through a feature that shared information between relatives, they then reached data about millions more customers. The people whose accounts were opened had reused passwords from other breached sites.
Why reusing passwords is so risky
A strong password is still weak if you use it everywhere. Your security becomes only as good as the least secure site you've ever signed up for, including old forums and shops you've forgotten.
Signs you've been hit
- Emails about sign-ins or password changes you didn't make.
- Orders, messages or posts you don't recognize.
- Being suddenly signed out, or your password no longer working.
How to protect yourself
- Use a password manager to create a different strong password for every site. See how password managers work.
- Turn on two-step verification, or use passkeys, so a stolen password isn't enough. See setting up two-step verification.
- Check for leaks: Have I Been Pwned shows which breaches your email appears in. Chrome's Password Checkup flags saved passwords found in leaks. See checking for breaches.
- Change reused passwords first on your email account, then banking, then everything else. Your email matters most, because it can reset all the others.
Protect passwords as you use them
Password managers often copy passwords to the clipboard. Clipboard Guard stops websites from reading your clipboard, so a page can't quietly grab what you've copied.
For site owners
Rate-limit sign-in attempts, check new passwords against known leaked lists, offer two-step verification and passkeys, and watch for unusual sign-in patterns. See auditing saved passwords in Chrome.