Skip to main content

What is a stuffing attack?

A credential attack or stuffing attack or brute force attack is becoming a common way for attackers to attempt

Written by Product team

A credential attack or stuffing attack or brute force attack is becoming a common way for attackers to attempt

What is a stuffing attack?

A stuffing attack (also called credential stuffing) is a type of cyberattack where attackers use automated tools to try stolen username/password combinations across multiple websites and services. This differs from a brute force attack, which tries to guess passwords through systematic attempts; stuffing attacks use known compromised credentials.

How a stuffing attack works

Attackers get large databases of compromised emails and passwords from previous data breaches.

They use automated bots to systematically test these username/password pairs on various login pages. Attackers can test thousands of credentials per minute.

Studies show 65% of people reuse passwords across multiple accounts, so some attempts succeed.

Successfully compromised accounts are then used for fraud, data theft, or sold to other criminals.

Did this answer your question?