Credential stuffing in plain terms
When a site is breached, its users' emails and passwords end up in lists that are traded and sold, often called combo lists. Attackers load those lists into tools built for the job, point them at a target's login page or login API, and let bots try every pair. Most attempts fail. The small share that succeeds are accounts where the owner used the same password on both sites.
Those valid logins are the product. They are sold, drained of stored value, loyalty points or gift card balances, or used for fraud in the owner's name. Credential stuffing is the most common road to account takeover.
- Needs no guessing: every password tried is one a real person actually used.
- Spread across thousands of proxy IP addresses so no single source looks busy.
- Run by browser automation or HTTP clients that mimic your real login flow.
How it shows up and why it matters
On a login dashboard, credential stuffing looks like a jump in failed logins, often at night or right after a large breach is published, with the failures spread across thousands of accounts rather than a few. Password reset requests rise, and a few days later so do support tickets from customers who see orders, withdrawals or point redemptions they did not make.
The damage goes beyond the accounts that are actually taken over. Every attempt costs server time, one-time code messages can be triggered in bulk, and customers who get locked out or hit with extra checks may leave. Businesses that store value in accounts, such as wallets, betting balances, loyalty points or saved cards, are the favorite targets because a working login converts straight into money.
Credential stuffing vs brute force
Both hammer the login, but they fail and succeed in different ways.
| Credential stuffing | Brute force | |
|---|---|---|
| Input | Real pairs leaked from other breaches | Guessed passwords or dictionary words |
| Attempts per account | Usually one or a few | Many, until one works |
| Tell-tale pattern | Many accounts, few tries each, high failure rate | One account, many tries |
| Beaten by | Unique passwords, MFA, bot detection at login | Lockouts, strong passwords, rate limits |
| Why lockouts miss it | No single account gets enough failures to lock | Lockouts work well here |
How to stop credential stuffing
Because each attempt is a normal-looking login, the defense has to judge who is logging in, not only whether the password is right. Kavra checks every login for automation, spoofed devices and proxy networks, and compares it with the account's own history of devices and locations, then recommends allow, step up or block. The full playbook, including warning signs and a response checklist, is on the credential stuffing protection page. Botnets and residential proxies are how the traffic gets spread out.