Skip to content

What is credential stuffing?

Credential stuffing is the automated use of usernames and passwords leaked from one service to log in to another. It works because people reuse passwords, and it looks like many ordinary failed logins spread across many accounts.

How it works

An attacker obtains a list of email and password pairs from an old breach of a different website. A script replays each pair against your login API:

POST /api/auth/login  {"email": "[email protected]",  "password": "Summer2019!"}  → 401
POST /api/auth/login  {"email": "[email protected]",  "password": "Raj#1985"}     → 401
POST /api/auth/login  {"email": "[email protected]", "password": "lena2020"}     → 200

Most attempts fail. The few that succeed belong to people who reused a password, and the attacker now holds a valid session in their name. The requests rotate through many IP addresses, so each address sends only a handful.

It differs from its neighbours by what it guesses. Password spraying tries a few common passwords against many accounts. Brute force tries many passwords against one account. Credential stuffing tries one known pair per account.

It belongs under API2, broken authentication, in the OWASP API Security Top 10 (2023).

Why classic controls miss it

  • Every request is a valid login with a real username. There is no malicious payload for a firewall to match.
  • Per-address rate limits barely fire, because the attempts are spread across many addresses.
  • Account lockouts rarely trigger, because each account sees only one attempt.
  • A successful login looks exactly like the real user signing in.

How to detect and prevent it

  1. Offer multi-factor authentication, and require it before sensitive actions.
  2. Check new and changed passwords against lists of known breached passwords.
  3. Watch the login endpoint as a whole: a rising failure ratio across many accounts, many usernames from one source, and logins from anonymising networks.
  4. Add friction progressively, with a challenge or a delay when those signals rise, rather than locking real users out.
  5. After a suspicious success, end the account’s other sessions and tell the user.

How Cyron handles it

Cyron API Security detects credential stuffing, password spraying and brute force against your login endpoints, and reports them under API2 of the OWASP API Security Top 10 (2023). Behavioural intelligence follows the pattern across sessions, and anonymiser traffic on login endpoints is flagged. Threat intelligence marks an address as malicious only when sources agree, and iris, the eBPF kernel agent, blocks a confirmed source at the kernel. See how Cyron API Security works.