Solution

Credential stuffing protection that stops login bots, not customers

Credential stuffing is an automated attack where bots take email and password pairs leaked from other sites and try them on your login page at scale, betting that people reuse passwords. Kavra spots the automation, the proxy networks and the one-device-many-accounts pattern on every attempt, so bots are refused before any login succeeds.

POST /loginBlocked

Automated login, 212 usernames tried

  • Browser automation detected
  • Same actor, 212 usernames
  • Residential proxy, rotating IP
Risk97
Your actionRefuse the attempt
Who it hits
Any site with a login and stored value
What it costs
Takeovers, infra load, lockouts, support
Tools used
Combo lists, checker bots, proxy pools
Where to stop it
Every login and password reset attempt

What is credential stuffing?

Credential stuffing is the bulk testing of stolen login details. Attackers do not guess passwords. They start from lists of real email and password pairs, known as combo lists, collected from old data breaches and infostealer malware, and replay them against a new target. Because many people reuse the same password on several sites, a small share of attempts succeed.

It is worth separating the attack from its outcome. Credential stuffing is the automated testing stage: high volume, mostly failures, run by bots. Account takeover is what happens after a hit, when someone logs in and uses the account. Stopping stuffing early means fewer valid logins end up for sale, and fewer takeovers downstream.

These attacks are often grouped together, but they leave different traces and need different responses.

AttackWhat the attacker hasPattern at your login
Credential stuffingReal email and password pairs leaked from other sitesMany accounts, one or two tries each, from many IPs
Brute forceA target username and a password generatorMany passwords against one account until it locks
Password sprayingA list of usernames and a few very common passwordsThe same weak password tried across many accounts, slowly
PhishingCredentials captured from the victim directlyA single correct login, often from a new device
Account takeoverA working login from any of the aboveCorrect password, unfamiliar device, quick changes to the account

How a credential stuffing attack works

Stuffing is cheap to run because every part of it is sold as a service.

  1. 01

    Get a combo list

    Attackers buy or download lists of email and password pairs. Fresh lists from recent infostealer logs are worth more than old breach dumps, because the passwords are more likely to still work.

  2. 02

    Configure a checker

    An account checker tool is set up for your login flow: which URL to call, which fields to fill, what a success page looks like. Ready-made configs for popular sites are traded in forums.

  3. 03

    Spread the traffic

    Attempts are routed through thousands of residential proxies or a botnet, so each IP address makes only a few tries and stays under rate limits.

  4. 04

    Imitate a browser

    Requests come from headless browsers with stealth plugins, or from HTTP clients that copy a real browser's headers, to pass basic bot checks.

  5. 05

    Sort and sell the hits

    Working logins are checked for balances, saved cards and points, then used directly or sold in bulk to other criminals who carry out the takeover.

Who it hits and what it costs

Any business with a login is a target, but attackers focus on accounts that turn into money fast: banking and wallets, retail with stored cards, gift card and loyalty programs, streaming and gaming subscriptions, travel miles and betting balances. The attack also hits login-adjacent endpoints such as password reset, mobile app APIs and partner logins, which are often less protected than the website form.

  • Takeovers of real customer accounts, with the fraud losses and refunds that follow.
  • Infrastructure load: login and database traffic spikes, sometimes large enough to slow the service for everyone.
  • Locked-out customers when lockout rules fire on their accounts during an attack.
  • Polluted analytics, as failed logins inflate traffic and conversion numbers drop.
  • Security reviews, disclosure questions and reputational damage if a campaign succeeds at scale.

Signs of a credential stuffing attack

Individual attempts can look normal. The pattern across attempts gives stuffing away.

  • Login failure rate jumps

    The ratio of failed to successful logins rises sharply, often with many attempts on emails that have no account at all.

  • One actor, many usernames

    The same underlying device or session setup tries hundreds of different accounts, even as its IP address changes.

  • Wide spread of home IPs

    Attempts arrive from many residential and mobile addresses, each used a handful of times, all belonging to proxy pools.

  • Signs of automation

    Headless browsers, automation frameworks, or clients that send browser-like headers but cannot run the page like a real browser.

  • No human interaction

    Forms submitted with no typing, no mouse movement and identical timing, or direct calls to the login API with no page view.

  • Odd hours and steady rhythm

    Traffic that holds a flat, machine-like rate through the night in your customers' timezone.

Why common defenses miss it

Stuffing tools are built to stay just under the thresholds of standard login controls.

DefenseWhat it assumesHow stuffing gets around it
Rate limits per IPOne attacker, one addressEach proxy IP makes only a few attempts
Account lockoutAttackers hammer one accountEach account gets one or two tries, and lockouts hurt real users
CAPTCHABots cannot solve itSolving services return answers in seconds, while customers face the puzzle
IP reputation listsBad traffic comes from bad IPsResidential proxies use clean home addresses
Basic bot rulesBots send odd headersModern tools copy real browser headers exactly
Password complexity rulesWeak passwords are the riskStuffed passwords are real, and often strong, just reused

How to prevent credential stuffing

Effective protection looks at who is making each attempt, not only how many attempts an address makes. The aim is to refuse automated attempts silently, so the attacker learns nothing, while real customers log in as usual.

  • Assess every login attempt, including mobile app and API logins and password reset requests.
  • Detect automation directly: headless browsers, scripted clients and missing human interaction.
  • Track the actor behind attempts across IP changes, and count how many usernames one device tries.
  • Recognize residential and mobile proxy traffic by what it is, not by its reputation score.
  • Return the same response for wrong password and unknown user, so checkers cannot sort valid emails.
  • Check new passwords against known breached lists and encourage passkeys or app-based two-factor.
  • Watch the login failure ratio as a live alert, not a monthly report.

A customer who forgot a password vs a stuffing bot

Customer with a typo

  • Tries one account, a few times
  • Types, pauses, corrects, clicks reset
  • Known device on a normal home or mobile network
  • Real browser that behaves consistently

Stuffing bot

  • Tries hundreds of accounts, once each
  • Instant submits with pasted values
  • New proxy IP for nearly every attempt
  • Automation or a client pretending to be a browser

Sources

  1. OWASP Automated Threats to Web Applications: OAT-008 Credential Stuffing
  2. OWASP Automated Threats to Web Applications: OAT-007 Credential Cracking
  3. OWASP Cheat Sheet Series: Credential Stuffing Prevention
  4. NIST SP 800-63B-4: Digital Identity Guidelines, Authentication and Authenticator Management
  5. OWASP API Security Top 10: API2:2023 Broken Authentication

How Kavra helps

How Kavra stops credential stuffing

Kavra assesses every login attempt with 3,000+ data points and returns a clear verdict before your backend checks the password.

  • Automation detected

    Headless browsers, automation frameworks, stealth plugins and HTTP clients imitating browsers are exposed by contradictions between layers.

  • Own edge network

    Kavra sees the real connection, not only what the client claims, so a script dressed as a browser does not pass as one.

  • Proxy intelligence

    Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.

  • One actor, many usernames

    Devices are recognized across IP changes and fingerprint rotation, so one checker trying hundreds of accounts is seen as one actor.

  • Web, app and API logins

    The script covers your site, native iOS and Android SDKs cover apps, and a server-side API covers backend and partner login endpoints.

  • Tokens that cannot be replayed

    Each assessment is a signed, single-use, short-lived token bound to the login, so a checker cannot reuse a good token across attempts.

FAQ

Frequently asked questions

Something else? Talk to our team.

What is the difference between credential stuffing and brute force?

Brute force guesses passwords, often trying many combinations against one account. Credential stuffing uses real email and password pairs leaked elsewhere and tries each pair once or twice across many accounts. Stuffing has a far higher hit rate per attempt, and because it spreads thinly, lockout and per-account limits rarely catch it.

Where do combo lists come from?

From data breaches at other companies and, increasingly, from infostealer malware that copies saved passwords and cookies from infected computers. The lists are cleaned, merged and sold or shared in criminal forums and chat channels. Your own site does not need to be breached for its customers' passwords to appear in them.

Does CAPTCHA stop credential stuffing?

Not reliably. Solving services answer CAPTCHAs cheaply and quickly, and some bots solve them with image models. Meanwhile, real customers pay the friction on every login. Kavra runs its checks in the background instead, so customers never have to solve a challenge.

How do I know if my site is under a credential stuffing attack?

Watch for a sudden rise in failed logins, many attempts on emails that do not exist in your user base, a wide spread of residential IP addresses each making few attempts, and traffic at steady machine-like rates. A spike in password reset requests or customer lockout complaints is another common early sign.

Can multi-factor authentication stop credential stuffing?

It stops most stuffed logins from turning into takeovers, because the attacker lacks the second factor. It does not stop the attack itself: bots still hit your login, learn which passwords are valid and cost you infrastructure and SMS fees. Blocking the automation first, then using two-factor for risky logins, covers both problems.

Should I lock accounts after failed logins?

Use lockouts carefully. Stuffing tries each account only once or twice, so lockouts rarely stop it, while they do lock out real customers and give attackers a way to deny service. Temporary, risk-based delays and blocking the automated actor behind the attempts work better than hard lockouts.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.