High severity Attack Technique

Credential Stuffing

Username and password pairs leaked from one breach are replayed against other services.

Overview

This works because people reuse passwords: billions of leaked pairs are tested at scale against login endpoints.\nNo cracking is involved, so password strength barely matters as long as the same secret guards several sites.\nThe definitive controls are breached-password screening, MFA, and refusing login on any pair seen in a known dump.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Distributed low-and-slow login failures
  • Logins matching published breach corpora
  • Traffic concentrated on a small set of popular accounts

Controls that stop it

  • Enforce Multi-Factor Authentication

    Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.

  • Rate Limit and Monitor Authentication

    Throttle failed logins per account and per source, apply exponential back-off, and alert on volumes that look like automation. Rate limit expensive endpoints such as search, password reset and OTP verification so they cannot be used for enumeration or denial of service. Logging without alerting is not monitoring.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used