In October 2023, 23andMe disclosed that attackers accessed roughly 14,000 customer accounts using credentials stolen from unrelated breaches. Through its DNA Relatives feature, that access exposed data connected to nearly 6.9 million accounts.
The incident highlights the core risk of credential stuffing: attackers do not always need sophisticated exploits. Reused passwords, automated login attempts, and a single vulnerable entry point can turn a limited account compromise into a much larger data exposure.
What Is Credential Stuffing?
Credential stuffing is an automated attack in which stolen username and password pairs are tested against a login system to find accounts where the same credentials were reused. The credentials are not guessed or cracked. They come from earlier, unrelated breaches, criminal marketplaces, or public breach dumps, and attackers simply check where else they still work. This is what separates credential stuffing from brute-force password guessing, and why the attack can succeed even against systems with strong password complexity rules.
Why Is Credential Stuffing So Effective Against Enterprises?
Credential stuffing works because password reuse is common and the supply of breached credentials is enormous. Verizon’s 2025 Data Breach Investigations Report found that credential abuse was the leading initial access vector, present in 22% of confirmed breaches analyzed. In a separate analysis of single sign-on provider logs, Verizon found that credential stuffing made up a median of 19% of daily authentication attempts, climbing to 25% at larger enterprises and spiking as high as 44% on the worst recorded day. The same analysis found only about half of a typical user’s passwords were unique across services. For an enterprise, this means a meaningful share of daily login traffic is not customers or employees, but automated tools testing whether last year’s breach still opens this year’s account.
How Does A Credential Stuffing Attack Work?
A credential stuffing attack begins with a list of breached username and password pairs, often numbering in the millions, obtained from prior breaches or purchased on criminal marketplaces. The attacker loads this list into automation tools and distributes login attempts across a large pool of proxy IP addresses so no single address sends enough requests to trigger basic rate limiting. Each request mimics a real browser, with realistic headers and user agents, letting the traffic blend into normal login activity. When a pair succeeds, the attacker has a validated account and can move on to draining stored value, harvesting personal data, or using the account as a foothold into connected systems, as happened through the DNA Relatives feature in the 23andMe case.
How Is Credential Stuffing Different From Brute Force And Password Spraying?
Credential stuffing tests real, previously valid username and password combinations rather than guessing new ones, which is what separates it from brute-force credential cracking. Password spraying is a related but distinct technique where an attacker tries a small number of common passwords against many different accounts to avoid lockout thresholds. Credential stuffing relies on the accuracy of stolen data rather than guesswork, so it often succeeds on the first attempt per account. Security teams sometimes lump these attacks together, but the detection signals differ: password spraying shows one or two passwords across many usernames, while credential stuffing shows many unique password and username pairs tested in bulk. Ampcus Cyber’s recent analysis of password spraying attacks bypassing misconfigured MFA breaks down how these adjacent techniques are evolving.
What Are The Warning Signs Of A Credential Stuffing Attack?
The clearest warning sign of credential stuffing is a spike in login attempts coming from a wide spread of IP addresses and geographies within a short window. Other indicators include an unusually high ratio of failed to successful logins across many accounts at once, login requests with missing or inconsistent device fingerprints, and near-identical request timing that suggests scripted rather than human behavior. A sudden rise in password reset requests or account lockouts across unrelated users can also signal an active campaign, since some accounts trigger lockout thresholds before the attacker moves on.
How Can Organizations Detect Credential Stuffing In Real Time?
Organizations detect credential stuffing by combining behavioral analytics with device and network-level signals rather than relying on failed login counts alone. Bot management tools that analyze mouse movement, typing cadence, and browser fingerprinting can separate scripted traffic from genuine users even when the credentials entered are technically correct. Monitoring login velocity per IP range and per credential pair, flagging impossible travel patterns, and correlating authentication logs with known breach corpuses all add detection depth. Feeding these signals into a security operations function that can act within minutes, not hours, is what a continuously monitored, autonomous SOC is built to
How Can Enterprises Prevent Credential Stuffing Attacks?
Enterprises prevent credential stuffing by making stolen passwords insufficient on their own to gain access. Multi-factor authentication is the most widely recommended control, though it is not absolute. It significantly raises the cost of an attack, but push-bombing and other MFA-fatigue techniques have shown attackers can work around it, which is why MFA implementation quality matters as much as MFA presence. Screening passwords against known breach corpuses, as NIST SP 800-63B-4 recommends, catches credentials before an attacker gets the chance to test them. Rate limiting, CAPTCHA challenges, and IP reputation filtering reduce the volume an automated tool can push through. Longer term, moving toward phishing-resistant methods such as passkeys and FIDO2 removes the reusable password from the equation, an approach compared in detail here. Monitoring the dark web for the organization’s own leaked credentials adds an early warning layer, since dark web monitoring can flag exposure before it turns into a campaign.
Which Compliance Frameworks Address Credential Stuffing Risk?
Several frameworks give enterprises reference points for managing credential stuffing risk, though none prescribes identical controls. OWASP’s Automated Threats to Web Applications project defines and catalogs credential stuffing as OAT-008, giving security teams shared vocabulary and detection guidance rather than a compliance checklist. NIST SP 800-63B-4, the current revision of NIST’s digital identity guidelines, requires verifiers to screen passwords against known compromised credential lists and to support phishing-resistant authenticators. PCI DSS requires multi-factor authentication for remote access and for any access into the cardholder data environment, limiting the value of a stolen password in payment environments, an area covered under Ampcus Cyber’s PCI DSS compliance services. No single framework covers detection, authentication, and compliance end to end, which is why most identity programs draw on more than one.
Protect your login systems before attackers test them for you.
| Talk to Ampcus Cyber about strengthening authentication, detection, and compliance controls against credential-based attacks. |
People Also Ask
Can multi-factor authentication fully stop credential stuffing?
Is credential stuffing the same as a data breach
Who should own credential stuffing defense inside an organization?
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.










