Scam & Fraud Glossary

Credential stuffing

Automated attacks that try leaked passwords across many sites, exploiting password reuse.

Credential stuffing is an automated attack that takes username-and-password pairs leaked from one breached site and tries them, at scale, against many others. It works because so many people reuse the same password across accounts: one exposure elsewhere quietly becomes a master key to your email, shopping and banking logins.

Attackers use software to test huge numbers of stolen combinations, and every account that shares a reused password is at risk of silent account takeover. The defence is refreshingly concrete. Use a different password for every account, so a leak in one place cannot unlock another; a password manager makes that practical by remembering them for you. Add two-factor authentication to anything important, so a correct password on its own still fails. It is worth checking whether your addresses have appeared in a known data breach and changing any password you have reused. Unlike targeted hacking, this attack is blind and opportunistic — it simply sprays known passwords everywhere and profits from repetition — which is exactly why not repeating your own passwords defeats it. The clean-up after a compromised login is covered in our identity-theft guide.