Glossary

What is credential stuffing?

Credential stuffing is an automated attack in which bots take username and password pairs leaked from one website and try them on the login pages of many others. It works because people reuse passwords. Each successful match becomes a hijacked account. Kavra stops the bots at the login before the password is ever checked.

Credential stuffing in plain terms

When a site is breached, its users' emails and passwords end up in lists that are traded and sold, often called combo lists. Attackers load those lists into tools built for the job, point them at a target's login page or login API, and let bots try every pair. Most attempts fail. The small share that succeeds are accounts where the owner used the same password on both sites.

Those valid logins are the product. They are sold, drained of stored value, loyalty points or gift card balances, or used for fraud in the owner's name. Credential stuffing is the most common road to account takeover.

  • Needs no guessing: every password tried is one a real person actually used.
  • Spread across thousands of proxy IP addresses so no single source looks busy.
  • Run by browser automation or HTTP clients that mimic your real login flow.

How it shows up and why it matters

On a login dashboard, credential stuffing looks like a jump in failed logins, often at night or right after a large breach is published, with the failures spread across thousands of accounts rather than a few. Password reset requests rise, and a few days later so do support tickets from customers who see orders, withdrawals or point redemptions they did not make.

The damage goes beyond the accounts that are actually taken over. Every attempt costs server time, one-time code messages can be triggered in bulk, and customers who get locked out or hit with extra checks may leave. Businesses that store value in accounts, such as wallets, betting balances, loyalty points or saved cards, are the favorite targets because a working login converts straight into money.

Credential stuffing vs brute force

Both hammer the login, but they fail and succeed in different ways.

Credential stuffingBrute force
InputReal pairs leaked from other breachesGuessed passwords or dictionary words
Attempts per accountUsually one or a fewMany, until one works
Tell-tale patternMany accounts, few tries each, high failure rateOne account, many tries
Beaten byUnique passwords, MFA, bot detection at loginLockouts, strong passwords, rate limits
Why lockouts miss itNo single account gets enough failures to lockLockouts work well here

How to stop credential stuffing

Because each attempt is a normal-looking login, the defense has to judge who is logging in, not only whether the password is right. Kavra checks every login for automation, spoofed devices and proxy networks, and compares it with the account's own history of devices and locations, then recommends allow, step up or block. The full playbook, including warning signs and a response checklist, is on the credential stuffing protection page. Botnets and residential proxies are how the traffic gets spread out.

FAQ

Frequently asked questions

Something else? Talk to our team.

Why is it called credential stuffing?

Because attackers stuff large lists of stolen credentials, username and password pairs, into login forms one after another, using automation. The name describes the mechanics: nothing is cracked or guessed, the attacker simply feeds known pairs into as many sites as possible and keeps the ones that open an account.

How can I check whether my password was leaked?

Use a breach notification service or the password checkup built into major browsers and password managers, which compare your credentials against known leaks without sending the full password. If a password shows up, change it everywhere you used it and turn on multi-factor authentication for important accounts.

What is a combo list?

A combo list is a file of username and password pairs, usually compiled from many past breaches and phishing campaigns, cleaned of duplicates and sold or shared on criminal forums. Credential stuffing tools read these lists line by line and try each pair against a target site's login.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.