POST /loginBlockedAutomated login, 212 usernames tried
- Browser automation detected
- Same actor, 212 usernames
- Residential proxy, rotating IP
Solution
Credential stuffing is an automated attack where bots take email and password pairs leaked from other sites and try them on your login page at scale, betting that people reuse passwords. Kavra spots the automation, the proxy networks and the one-device-many-accounts pattern on every attempt, so bots are refused before any login succeeds.
POST /loginBlockedAutomated login, 212 usernames tried
Credential stuffing is the bulk testing of stolen login details. Attackers do not guess passwords. They start from lists of real email and password pairs, known as combo lists, collected from old data breaches and infostealer malware, and replay them against a new target. Because many people reuse the same password on several sites, a small share of attempts succeed.
It is worth separating the attack from its outcome. Credential stuffing is the automated testing stage: high volume, mostly failures, run by bots. Account takeover is what happens after a hit, when someone logs in and uses the account. Stopping stuffing early means fewer valid logins end up for sale, and fewer takeovers downstream.
These attacks are often grouped together, but they leave different traces and need different responses.
| Attack | What the attacker has | Pattern at your login |
|---|---|---|
| Credential stuffing | Real email and password pairs leaked from other sites | Many accounts, one or two tries each, from many IPs |
| Brute force | A target username and a password generator | Many passwords against one account until it locks |
| Password spraying | A list of usernames and a few very common passwords | The same weak password tried across many accounts, slowly |
| Phishing | Credentials captured from the victim directly | A single correct login, often from a new device |
| Account takeover | A working login from any of the above | Correct password, unfamiliar device, quick changes to the account |
Stuffing is cheap to run because every part of it is sold as a service.
Attackers buy or download lists of email and password pairs. Fresh lists from recent infostealer logs are worth more than old breach dumps, because the passwords are more likely to still work.
An account checker tool is set up for your login flow: which URL to call, which fields to fill, what a success page looks like. Ready-made configs for popular sites are traded in forums.
Attempts are routed through thousands of residential proxies or a botnet, so each IP address makes only a few tries and stays under rate limits.
Requests come from headless browsers with stealth plugins, or from HTTP clients that copy a real browser's headers, to pass basic bot checks.
Working logins are checked for balances, saved cards and points, then used directly or sold in bulk to other criminals who carry out the takeover.
Any business with a login is a target, but attackers focus on accounts that turn into money fast: banking and wallets, retail with stored cards, gift card and loyalty programs, streaming and gaming subscriptions, travel miles and betting balances. The attack also hits login-adjacent endpoints such as password reset, mobile app APIs and partner logins, which are often less protected than the website form.
Individual attempts can look normal. The pattern across attempts gives stuffing away.
The ratio of failed to successful logins rises sharply, often with many attempts on emails that have no account at all.
The same underlying device or session setup tries hundreds of different accounts, even as its IP address changes.
Attempts arrive from many residential and mobile addresses, each used a handful of times, all belonging to proxy pools.
Headless browsers, automation frameworks, or clients that send browser-like headers but cannot run the page like a real browser.
Forms submitted with no typing, no mouse movement and identical timing, or direct calls to the login API with no page view.
Traffic that holds a flat, machine-like rate through the night in your customers' timezone.
Stuffing tools are built to stay just under the thresholds of standard login controls.
| Defense | What it assumes | How stuffing gets around it |
|---|---|---|
| Rate limits per IP | One attacker, one address | Each proxy IP makes only a few attempts |
| Account lockout | Attackers hammer one account | Each account gets one or two tries, and lockouts hurt real users |
| CAPTCHA | Bots cannot solve it | Solving services return answers in seconds, while customers face the puzzle |
| IP reputation lists | Bad traffic comes from bad IPs | Residential proxies use clean home addresses |
| Basic bot rules | Bots send odd headers | Modern tools copy real browser headers exactly |
| Password complexity rules | Weak passwords are the risk | Stuffed passwords are real, and often strong, just reused |
Effective protection looks at who is making each attempt, not only how many attempts an address makes. The aim is to refuse automated attempts silently, so the attacker learns nothing, while real customers log in as usual.
How Kavra helps
Kavra assesses every login attempt with 3,000+ data points and returns a clear verdict before your backend checks the password.
Headless browsers, automation frameworks, stealth plugins and HTTP clients imitating browsers are exposed by contradictions between layers.
Kavra sees the real connection, not only what the client claims, so a script dressed as a browser does not pass as one.
Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.
Devices are recognized across IP changes and fingerprint rotation, so one checker trying hundreds of accounts is seen as one actor.
The script covers your site, native iOS and Android SDKs cover apps, and a server-side API covers backend and partner login endpoints.
Each assessment is a signed, single-use, short-lived token bound to the login, so a checker cannot reuse a good token across attempts.
FAQ
Something else? Talk to our team.
Brute force guesses passwords, often trying many combinations against one account. Credential stuffing uses real email and password pairs leaked elsewhere and tries each pair once or twice across many accounts. Stuffing has a far higher hit rate per attempt, and because it spreads thinly, lockout and per-account limits rarely catch it.
From data breaches at other companies and, increasingly, from infostealer malware that copies saved passwords and cookies from infected computers. The lists are cleaned, merged and sold or shared in criminal forums and chat channels. Your own site does not need to be breached for its customers' passwords to appear in them.
Not reliably. Solving services answer CAPTCHAs cheaply and quickly, and some bots solve them with image models. Meanwhile, real customers pay the friction on every login. Kavra runs its checks in the background instead, so customers never have to solve a challenge.
Watch for a sudden rise in failed logins, many attempts on emails that do not exist in your user base, a wide spread of residential IP addresses each making few attempts, and traffic at steady machine-like rates. A spike in password reset requests or customer lockout complaints is another common early sign.
It stops most stuffed logins from turning into takeovers, because the attacker lacks the second factor. It does not stop the attack itself: bots still hit your login, learn which passwords are valid and cost you infrastructure and SMS fees. Blocking the automation first, then using two-factor for risky logins, covers both problems.
Use lockouts carefully. Stuffing tries each account only once or twice, so lockouts rarely stop it, while they do lock out real customers and give attackers a way to deny service. Temporary, risk-based delays and blocking the automated actor behind the attempts work better than hard lockouts.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.