# Credential stuffing protection that stops login bots, not customers

Source: https://kavralab.com/solutions/credential-stuffing/

**Credential stuffing** is an automated attack where bots take email and password pairs leaked from other sites and try them on your login page at scale, betting that people reuse passwords. Kavra spots the automation, the proxy networks and the one-device-many-accounts pattern on every attempt, so bots are refused before any login succeeds.

- **Who it hits:** Any site with a login and stored value
- **What it costs:** Takeovers, infra load, lockouts, support
- **Tools used:** Combo lists, checker bots, proxy pools
- **Where to stop it:** Every login and password reset attempt

## What is credential stuffing?

Credential stuffing is the bulk testing of stolen login details. Attackers do not guess passwords. They start from lists of real email and password pairs, known as combo lists, collected from old data breaches and infostealer malware, and replay them against a new target. Because many people reuse the same password on several sites, a small share of attempts succeed.

It is worth separating the attack from its outcome. Credential stuffing is the automated testing stage: high volume, mostly failures, run by bots. [Account takeover](https://kavralab.com/solutions/account-takeover/) is what happens after a hit, when someone logs in and uses the account. Stopping stuffing early means fewer valid logins end up for sale, and fewer takeovers downstream.

## Credential stuffing vs related login attacks

These attacks are often grouped together, but they leave different traces and need different responses.

| Attack | What the attacker has | Pattern at your login |
|---|---|---|
| Credential stuffing | Real email and password pairs leaked from other sites | Many accounts, one or two tries each, from many IPs |
| Brute force | A target username and a password generator | Many passwords against one account until it locks |
| Password spraying | A list of usernames and a few very common passwords | The same weak password tried across many accounts, slowly |
| Phishing | Credentials captured from the victim directly | A single correct login, often from a new device |
| [Account takeover](https://kavralab.com/glossary/account-takeover/) | A working login from any of the above | Correct password, unfamiliar device, quick changes to the account |

## How a credential stuffing attack works

Stuffing is cheap to run because every part of it is sold as a service.

1. **Get a combo list**: Attackers buy or download lists of email and password pairs. Fresh lists from recent infostealer logs are worth more than old breach dumps, because the passwords are more likely to still work.
2. **Configure a checker**: An account checker tool is set up for your login flow: which URL to call, which fields to fill, what a success page looks like. Ready-made configs for popular sites are traded in forums.
3. **Spread the traffic**: Attempts are routed through thousands of [residential proxies](https://kavralab.com/detect/residential-proxies/) or a [botnet](https://kavralab.com/glossary/botnet/), so each IP address makes only a few tries and stays under rate limits.
4. **Imitate a browser**: Requests come from [headless browsers](https://kavralab.com/detect/headless-browsers/) with stealth plugins, or from HTTP clients that copy a real browser's headers, to pass basic bot checks.
5. **Sort and sell the hits**: Working logins are checked for balances, saved cards and points, then used directly or sold in bulk to other criminals who carry out the takeover.

## Who it hits and what it costs

Any business with a login is a target, but attackers focus on accounts that turn into money fast: banking and wallets, retail with stored cards, gift card and loyalty programs, streaming and gaming subscriptions, travel miles and betting balances. The attack also hits login-adjacent endpoints such as password reset, mobile app APIs and partner logins, which are often less protected than the website form.

- Takeovers of real customer accounts, with the fraud losses and refunds that follow.
- Infrastructure load: login and database traffic spikes, sometimes large enough to slow the service for everyone.
- Locked-out customers when lockout rules fire on their accounts during an attack.
- Polluted analytics, as failed logins inflate traffic and conversion numbers drop.
- Security reviews, disclosure questions and reputational damage if a campaign succeeds at scale.

## Signs of a credential stuffing attack

Individual attempts can look normal. The pattern across attempts gives stuffing away.

- **Login failure rate jumps**: The ratio of failed to successful logins rises sharply, often with many attempts on emails that have no account at all.
- **One actor, many usernames**: The same underlying device or session setup tries hundreds of different accounts, even as its IP address changes.
- **Wide spread of home IPs**: Attempts arrive from many residential and mobile addresses, each used a handful of times, all belonging to proxy pools.
- **Signs of automation**: Headless browsers, automation frameworks, or clients that send browser-like headers but cannot run the page like a real browser.
- **No human interaction**: Forms submitted with no typing, no mouse movement and identical timing, or direct calls to the login API with no page view.
- **Odd hours and steady rhythm**: Traffic that holds a flat, machine-like rate through the night in your customers' timezone.

## Why common defenses miss it

Stuffing tools are built to stay just under the thresholds of standard login controls.

| Defense | What it assumes | How stuffing gets around it |
|---|---|---|
| Rate limits per IP | One attacker, one address | Each proxy IP makes only a few attempts |
| Account lockout | Attackers hammer one account | Each account gets one or two tries, and lockouts hurt real users |
| CAPTCHA | Bots cannot solve it | Solving services return answers in seconds, while customers face the puzzle |
| IP reputation lists | Bad traffic comes from bad IPs | Residential proxies use clean home addresses |
| Basic bot rules | Bots send odd headers | Modern tools copy real browser headers exactly |
| Password complexity rules | Weak passwords are the risk | Stuffed passwords are real, and often strong, just reused |

## How to prevent credential stuffing

Effective protection looks at who is making each attempt, not only how many attempts an address makes. The aim is to refuse automated attempts silently, so the attacker learns nothing, while real customers log in as usual.

- Assess every login attempt, including mobile app and API logins and password reset requests.
- Detect automation directly: headless browsers, scripted clients and missing human interaction.
- Track the actor behind attempts across IP changes, and count how many usernames one device tries.
- Recognize residential and mobile proxy traffic by what it is, not by its reputation score.
- Return the same response for wrong password and unknown user, so checkers cannot sort valid emails.
- Check new passwords against known breached lists and encourage passkeys or app-based two-factor.
- Watch the login failure ratio as a live alert, not a monthly report.

## A customer who forgot a password vs a stuffing bot

**Customer with a typo**

- Tries one account, a few times
- Types, pauses, corrects, clicks reset
- Known device on a normal home or mobile network
- Real browser that behaves consistently

**Stuffing bot**

- Tries hundreds of accounts, once each
- Instant submits with pasted values
- New proxy IP for nearly every attempt
- Automation or a client pretending to be a browser

> **Key takeaway:** Credential stuffing wins on volume and spread. Beat it by recognizing the automated actor behind the attempts, however many IPs it uses, and refusing it before a password is ever checked. The same checks protect other endpoints from [API abuse](https://kavralab.com/solutions/api-abuse/).

## How Kavra stops credential stuffing

Kavra assesses every login attempt with 3,000+ data points and returns a clear verdict before your backend checks the password.

- **Automation detected**: Headless browsers, automation frameworks, stealth plugins and HTTP clients imitating browsers are exposed by contradictions between layers.
- **Own edge network**: Kavra sees the real connection, not only what the client claims, so a script dressed as a browser does not pass as one.
- **Proxy intelligence**: Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.
- **One actor, many usernames**: Devices are recognized across IP changes and fingerprint rotation, so one checker trying hundreds of accounts is seen as one actor.
- **Web, app and API logins**: The script covers your site, native iOS and Android SDKs cover apps, and a server-side API covers backend and partner login endpoints.
- **Tokens that cannot be replayed**: Each assessment is a signed, single-use, short-lived token bound to the login, so a checker cannot reuse a good token across attempts.

## FAQ

### What is the difference between credential stuffing and brute force?

Brute force guesses passwords, often trying many combinations against one account. Credential stuffing uses real email and password pairs leaked elsewhere and tries each pair once or twice across many accounts. Stuffing has a far higher hit rate per attempt, and because it spreads thinly, lockout and per-account limits rarely catch it.

### Where do combo lists come from?

From data breaches at other companies and, increasingly, from infostealer malware that copies saved passwords and cookies from infected computers. The lists are cleaned, merged and sold or shared in criminal forums and chat channels. Your own site does not need to be breached for its customers' passwords to appear in them.

### Does CAPTCHA stop credential stuffing?

Not reliably. Solving services answer CAPTCHAs cheaply and quickly, and some bots solve them with image models. Meanwhile, real customers pay the friction on every login. Kavra runs its checks in the background instead, so customers never have to solve a challenge.

### How do I know if my site is under a credential stuffing attack?

Watch for a sudden rise in failed logins, many attempts on emails that do not exist in your user base, a wide spread of residential IP addresses each making few attempts, and traffic at steady machine-like rates. A spike in password reset requests or customer lockout complaints is another common early sign.

### Can multi-factor authentication stop credential stuffing?

It stops most stuffed logins from turning into takeovers, because the attacker lacks the second factor. It does not stop the attack itself: bots still hit your login, learn which passwords are valid and cost you infrastructure and SMS fees. Blocking the automation first, then using two-factor for risky logins, covers both problems.

### Should I lock accounts after failed logins?

Use lockouts carefully. Stuffing tries each account only once or twice, so lockouts rarely stop it, while they do lock out real customers and give attackers a way to deny service. Temporary, risk-based delays and blocking the automated actor behind the attempts work better than hard lockouts.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
