Attack chain 8 steps

Credential Stuffing Campaign

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    A breach dump from an unrelated service is obtained, containing hundreds of millions of pairs.

  2. 2

    Step 2 of 8

    Known-invalid entries are filtered out so only plausible credentials remain.

  3. 3

    Step 3 of 8

    Those pairs are sprayed against the target login endpoint at low volume to evade rate limits.

  4. 4

    Step 4 of 8

    Distributed source infrastructure keeps any single IP below alert thresholds.

  5. 5

    Step 5 of 8

    Successful logins are identified by comparing response shape against genuine failures.

  6. 6

    Step 6 of 8

    Matched accounts are tested for whether the same password guards other services.

  7. 7

    Step 7 of 8

    High-value accounts with payment methods or administrative rights are prioritised.

  8. 8

    Step 8 of 8

    Access is monetised through fraud, resale or further escalation inside the organisation.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used