Credential Stuffing: Bulk Account Takeover Explained
by Jordan Dean on Oct 09, 2026

A data breach at another company might not seem like your security problem, but if one of your employees reused the same password at work, it can quickly become one.
What is credential stuffing?
Credential stuffing is an automated attack that takes usernames and passwords exposed in previous breaches and automatically tests them against other login pages, looking for credentials that have been reused. If an employee's password leaked from a shopping site also unlocks their work email or VPN, the attacker is in.
The result is bulk account takeover (ATO): many accounts compromised at once, across many organizations, from a single list of stolen credentials.
It is often confused with two related attacks:
|
Attack |
What the attacker has |
How it works |
Why it's hard to spot |
|
Credential stuffing |
Real username + password pairs from earlier breaches |
Tries each known pair once against a new site |
One attempt per account looks like a normal login |
|
A list of usernames |
Tries a few common passwords (e.g., Spring2026!) across many accounts |
Low attempts per account to avoid lockouts |
|
|
Brute force |
One target account |
Guesses many passwords against that account |
Usually easy to spot; triggers lockouts |
The key difference is that credential stuffing does not guess; the attacker already knows the password works somewhere. They are only testing where else it works.
How a Credential Stuffing Attack Works
A credential stuffing campaign follows the same basic playbook every time, and almost every step is automated.
- Acquire credentials. Attackers buy or download "combolists" of username and password pairs. These lists are widely traded on cybercrime marketplaces and Telegram channels, and many come from infostealer malware that harvests passwords saved in browsers.
- Pick targets. Attackers automatically test the stolen credentials across login pages, APIs, VPN portals, Microsoft 365, and SSO providers. Because each attempt costs almost nothing, they target small companies as readily as large ones.
- Configure the tooling. Off-the-shelf tools can be configured for a specific login endpoint, with attackers adjusting request headers to make automated traffic look like it came from a normal browser.
- Hide the source. Traffic is routed through large pools of proxies, often residential IP addresses, so no single IP sends enough requests to trip rate limits.
- Test once per account. Each credential pair is tried a single time. This "low and slow" pattern blends in with legitimate login traffic.
- Harvest the hits. Successful logins are logged as working accounts. Even a success rate under 1% yields hundreds of valid accounts from a list of millions.
- Exploit or resell. Attackers use the accounts for data theft, business email compromise, fraud, or ransomware staging. Or they sell verified access to other criminals.
- Enforce MFA everywhere and make it phishing-resistant where you can. This can stop many credential-stuffing attempts before they lead to an account takeover. Stronger methods like FIDO2 security keys and passkeys offer better protection than SMS codes, while number matching on push notifications can help reduce the risk of attacks.
- Screen for breached passwords. Check new and existing passwords against lists of known-compromised credentials, and require a reset when a match is found. Encouraging longer passphrases and using a company password manager can also help prevent password reuse.
- Rate-limit and add friction at login. Throttle by IP, device, and account. Add bot detection or CAPTCHA, while knowing that determined attackers can bypass some of these.
- Respond fast. When an account is compromised, revoke sessions and tokens, reset credentials, review mailbox rules, and investigate what was accessed. Defense contractors should also check DFARS reporting timelines.
- Train your people. Teach employees why password reuse is dangerous and how to report unexpected MFA prompts.
The Scale and Effectiveness of Credential Stuffing
Credential stuffing can succeed for two reasons: people reuse passwords, and multifactor authentication (MFA) is not enabled everywhere it’s available.
Credential stuffing is also a constant background load. Over two years, it made up a median 19% of daily authentication attempts on SSO providers, rising to 25% for enterprises and about 12% for small businesses. On the worst single day, Verizon observed that it reached 44% of all login attempts.
The damage can far outrun the initial foothold. In the 2023 23andMe breach, credential stuffing unlocked roughly 0.1% of accounts, about 14,000. Through those accounts, attackers scraped profile data on 6.9 million people. The company later agreed to a $30 million U.S. class action settlement and was fined £2.31 million by the UK Information Commissioner's Office.
What's at Stake for Defense Contractors and SMBs
For a small business in the Defense Industrial Base (DIB), one stuffed account can turn into a contract problem, not just an IT problem.
The most direct risk is access to Controlled Unclassified Information (CUI). A taken-over Microsoft 365 or VPN account can expose engineering drawings, contract data, and other CUI. Attackers also use valid accounts as a launch point: sending convincing phishing from a trusted domain, moving laterally, or staging ransomware. Nation-state actors target DIB suppliers specifically to reach primes and sensitive programs.
A successful credential stuffing attack can also create compliance and reporting obligations. Under DFARS 252.204-7012, contractors must report cyber incidents affecting covered defense information to the DoD within 72 hours. The incident may also raise questions about whether required controls, such as MFA and audit logging, were properly implemented and working as intended.
The costs are real: in RADICL's 2025 DIB Cybersecurity Maturity Report, 37% of SMB respondents said cyber incidents had cost their company more than $100,000.
Warning Signs of a Credential Stuffing Attack
No single login looks suspicious, so detection depends on spotting patterns across many logins. The clearest signal is a sudden jump in failed logins spread across many different accounts, rather than many failures on one. Attempts against usernames that don't exist in your directory are another tell, since they show someone is working from an outside list.
Look at where the traffic comes from, too. High login volume from residential proxy ranges, hosting providers, or unusual countries deserves a closer look.
Finally, watch what happens around and after a login. A spike in MFA push requests, or users reporting prompts they didn't trigger, often means attackers already have valid passwords. After a successful takeover, look for new inbox rules, mail forwarding, password resets, or device changes.
How to Defend Against Credential Stuffing
The OWASP Credential Stuffing Prevention Cheat Sheet has deeper technical guidance for teams that run their own login systems.
Stop Account Takeover Before It Starts
Credential stuffing is not a sophisticated attack. It is a cheap, automated numbers game that exploits password reuse at massive scale. That's exactly why it works so well against organizations without strong MFA or continuous monitoring.
For many small and mid-sized government contractors, maintaining 24/7 visibility into every login isn't realistic with internal resources alone. RADICL helps fill that gap with continuous monitoring and deep security expertise.
Our virtual Security Operations Center (vSOC) combines AI-driven detection with expert analysts to spot credential stuffing and account takeover in real time, then shut it down before attackers reach your data.
RADICL also helps you build and maintain the controls NIST SP 800-171 and CMMC require, so stronger security and compliance readiness move forward together.
Talk to a RADICL expert today to see how we protect your organizations from account takeover and other advanced threats.
- DIB Innovators (136)
- Podcast (136)
- Industry Analysis (111)
- Threat Hunting and Intelligence (36)
- Regulatory Compliance (27)
- CMMC (16)
- Attack Surface and Vulnerability Management (15)
- Signal & Noise (14)
- Zero Gravity Summit (11)
- General (10)
- Security Operations & vSOC (7)
- Testimonials (6)
- Company (5)
- Founder (4)
- Incident Response (3)
- Managed Security Operations (3)
- Operational Resilience (2)
- Threat Management (2)
- NIST CSF (1)
- The RAID Party (1)
- Webinar (1)
No Comments Yet
Let us know what you think