What Is Credential Stuffing and How to Protect Yourself

Credential stuffing is an automated attack. Criminals take email and password pairs leaked in earlier breaches and try them on other websites, hoping you reused the same password. It is one of the most common causes of account takeover and it is entirely preventable.
How it works
- An attacker obtains a list of credentials from an old breach.
- Software tries those pairs on banks, shops, streaming services and social networks at high speed.
- Any login that works is taken over or sold.
Why it succeeds
Many people reuse passwords. If a small forum you joined years ago is breached, the same password may open your email or bank account.
How to protect yourself
- Use a unique password for every account. A password manager makes this practical.
- Turn on two-factor authentication. Even a correct password is useless without the second factor.
- Use passkeys where offered, since they cannot be reused.
- Check for breaches and change affected passwords.
- Watch for login alerts and unrecognised devices.
For site owners
Rate-limit login attempts, offer two-factor authentication or passkeys, and check new passwords against known breached lists.


