Blog/Account security

Credential Stuffing Explained

Credential stuffing is when criminals take leaked usernames and passwords and try them automatically on other sites. How it works, why it succeeds, and the defences for individuals and businesses.

CyberWatch AI30 September 2026 · 2 min read
Lines of computer code on a screen in blue and green

Credential stuffing is one of the most common ways accounts are taken over, and it requires no hacking skill at all. Criminals take lists of email addresses and passwords leaked from one website and use software to try them on many other websites. Every time someone has reused a password, the door opens.

How it works

  1. A breach exposes email and password pairs from one service.
  2. The list is sold or shared, and combined with other leaks.
  3. Automated tools try each pair on email providers, shops, streaming, banking and social media, often spreading attempts across many internet addresses to avoid detection.
  4. Successful logins are sold, used for fraud, or used to reset other accounts.

Why it succeeds

  • Many people reuse passwords, or use small variations.
  • Leaked lists are huge and cheap.
  • Automated attempts cost almost nothing.

See why password reuse is so dangerous.

How to protect yourself

DefenceWhy it works
Unique passwordsA leaked password only works on the site it came from.
Password managerMakes unique passwords practical. See setting one up.
Two-step verificationBlocks logins even with the right password.
PasskeysNo password to stuff. See what is a passkey.
Breach alertsTell you when to change a password. See checking breaches.

Signs it may have happened to you

  • Login alerts or verification codes you did not request. See unexpected login prompts.
  • Orders, bookings or changed details on accounts you rarely use.
  • Password reset emails you did not ask for.

For businesses

NIST guidance recommends checking new passwords against lists of known compromised passwords. Offer two-step verification and passkeys, rate-limit failed logins, and alert users about unusual sign-ins.

Received a login alert you did not expect? Paste the message into CyberWatch AI Scan for a free check, and change the password through the official site.

For more, see what to do after a data breach in our identity and account security guide.

Frequently asked questions

How is credential stuffing different from password guessing?

Guessing tries likely passwords. Credential stuffing uses real email and password pairs already leaked from other sites, relying on people reusing them.

Can two-step verification stop credential stuffing?

Yes, in most cases. Even with the correct password, the attacker cannot complete the second step without your phone or passkey.

What can businesses do?

Offer and encourage two-step verification and passkeys, check new passwords against known breached passwords, rate-limit login attempts, and watch for unusual login patterns.

Sources

  1. NIST SP 800-63B: Authentication and Lifecycle Management, US National Institute of Standards and Technology
  2. Multifactor Authentication, US Cybersecurity and Infrastructure Security Agency
  3. Have I Been Pwned, Troy Hunt
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.