What it is
Credential stuffing is an automated attack: the attacker takes email and password pairs leaked in other sites’ breaches and tries them across many services, hoping you reused the same password.
How it works
- 1Lists of leaked credentials circulate online after data breaches.
- 2Automated programs try millions of combinations on banks, shops, social networks and work services.
- 3The accounts that open are used or resold.
- 4With AI, the programs imitate human behaviour better and bypass some checks more easily.
How to spot it
- Sign-in alerts from a new device or country you do not recognise
- Password reset emails you did not request
- Purchases, orders or changes you did not make
- Your email appears in a known data breach
How to defend
- Use a different password for every service, with a password manager
- Enable passkeys or multi-factor authentication, preferably with an app rather than SMS
- Check whether your email is in a known breach on Have I Been Pwned
- In companies: limit login attempts, detect bots and block already-leaked passwords
- Never reuse the password of your main email
If you think you have been hit
- Change the password at once on the affected service and everywhere you reused it
- Enable multi-factor authentication and sign out of all sessions
- Check recovery addresses and automatic email forwarding set up by the attacker
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026