Threat

Credential Stuffing

Credential stuffing automatically tests stolen username and password combinations across many online services.

Credential stuffing is an attack in which stolen username and password combinations are automatically tried on other services. The attack works because many people reuse their passwords across different platforms.

How it works

Millions of login credentials circulate following data breaches. Attackers buy or collect these lists. They use tools to test the data automatically against web services, VPNs or customer portals. They distribute attempts across many IP addresses to avoid detection. Even a small success rate results in many compromised accounts when using large lists.

For example, an online shop records 200,000 login attempts from thousands of addresses overnight. Most attempts fail, but a few hundred are successful. The attackers then place orders using stored payment methods. The team recognises the pattern and locks the affected accounts. They also introduce an additional check for new logins.

What to look out for

  • Multi-factor authentication is the most effective measure against credential stuffing.
  • Monitor failed login attempts across all accounts, not just on a per-account basis.
  • Check new passwords against lists of known leaked passwords.
  • Implement bot protection and rate limits for login attempts.
  • Inform affected customers quickly and require a password reset.

How it differs from other attacks

In a brute force attack, an attacker tries many passwords for a single account. In password spraying, they try a few common passwords against many accounts. Credential stuffing uses known, valid combinations from previous data breaches.

Switzerland and regulation

If customer accounts are taken over and personal data is accessed, the Federal Data Protection and Information Commissioner (FDPIC) must be notified under the revFADP (revised Federal Act on Data Protection) if a high risk for the affected persons is likely.

Typical mistakes

Login attempts are often rate-limited only on a per-account basis. A distributed attack with few attempts per account then stays below the threshold. A second mistake is offering customer portals without an MFA option.

How we implement it

We detect credential stuffing patterns in the login logs from your IdP and portals. We then lock affected accounts within the mandate.

How ANOMAL implements this