Credential stuffing

The password you have reused for years can open more doors than you think.

Request a consultation

What it is

Credential stuffing is an automated attack: the attacker takes email and password pairs leaked in other sites’ breaches and tries them across many services, hoping you reused the same password.

How it works

  1. 1Lists of leaked credentials circulate online after data breaches.
  2. 2Automated programs try millions of combinations on banks, shops, social networks and work services.
  3. 3The accounts that open are used or resold.
  4. 4With AI, the programs imitate human behaviour better and bypass some checks more easily.

How to spot it

  • Sign-in alerts from a new device or country you do not recognise
  • Password reset emails you did not request
  • Purchases, orders or changes you did not make
  • Your email appears in a known data breach

How to defend

  • Use a different password for every service, with a password manager
  • Enable passkeys or multi-factor authentication, preferably with an app rather than SMS
  • Check whether your email is in a known breach on Have I Been Pwned
  • In companies: limit login attempts, detect bots and block already-leaked passwords
  • Never reuse the password of your main email

If you think you have been hit

  • Change the password at once on the affected service and everywhere you reused it
  • Enable multi-factor authentication and sign out of all sessions
  • Check recovery addresses and automatic email forwarding set up by the attacker

And there are many, many more

The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.

Contact me

Other attacks

Watch the Shorts on YouTube

Matteo Russo · Updated October 2026

Let's talk
no strings attached

Want to know how exposed you are, train your team, or just ask a question? Write to me: I reply personally.

  1. You writeA couple of lines about your case: person, company, doubt or request.
  2. We talkA short intro call to understand what you really need.
  3. Practical defenseAssessment, consulting or training, with clear, prioritized actions.

Request a consultation

For security, the email address is not written on the page: press the button to reveal it and copy it in one click.

For companies and individuals. No scaremongering, just practical defense.