Attack vector
Phished or stolen credentials
Phished or stolen credentials are a valid username and password that reach an attacker through a fake login page, password reuse, infostealer malware logs, a purchased credential dump or an earlier breach. The attacker then signs in as the real user, so the access looks legitimate and no exploit is needed to get through the front door.
A valid username and password reached the attacker — phished, reused, purchased, or taken from an earlier breach.
How attackers use it
Attackers send convincing login pages by email or text, buy credential lists from earlier breaches, or try reused passwords across many services. Once a pair works, they sign in like the real user, often from infrastructure that looks ordinary, and start exploring what that account can reach. Because nothing was exploited, the first sign of trouble is usually what the account does next.
What breach letters say
31 distinct incidents in California breach filings name this vector in the letter’s own words (January 1, 2023 – August 14, 2026).
The 3 most recent of 31:
“Xsolis became aware of unauthorized activity resulting from a targeted phishing attack on January 22, 2026.”
Xsolis, Inc. · filed Jul 21, 2026 · letter
“On November 17, 2025, First Advantage became aware that an unauthorized third party obtained access through sophisticated phishing to a single First Advantage Drug & Occupational Health Screening Unit employee’s account.”
First Advantage Corporation · filed Jun 23, 2026 · letter
“Within 24 hours of the event, we had removed the compromised access credentials, and improved the security protocols and processes associated with accessing the system.”
Nickey Kehoe · filed May 26, 2026 · letter
How to stop it
Phishing-resistant MFA, such as passkeys or FIDO2 security keys, makes a stolen password useless on its own once weaker fallback methods such as SMS codes and security questions are retired. Pair it with checks against known-breached passwords so reused credentials are caught before they are tried.
Terms under this vector
- ClickFix
ClickFix is a social engineering technique that tricks a user into running malicious commands on their own computer.
- Combo list
A combo list is a file of username and password pairs, usually email addresses and passwords, compiled from earlier data breaches, phishing and malware logs.
- Credential stuffing
Credential stuffing is an automated attack that takes usernames and passwords leaked from one service and tries them on many others.
- Infostealer
An infostealer is malware that collects saved passwords, browser cookies, session tokens, autofill data and crypto wallets from an infected computer and sends them to the attacker.
- Password spraying
Password spraying is a brute-force attack that tries a few common passwords against many accounts, instead of many passwords against one account.
- Phishing kit
A phishing kit is a ready-made package of fake login pages, scripts and hosting tools that lets someone launch a phishing campaign without building it.
- Quishing
Quishing is phishing that hides a malicious link inside a QR code.
- Smishing
Smishing is phishing delivered by text message.
- Spear phishing
Spear phishing is a phishing attack aimed at a specific person or small group, written with details about the target's job, contacts or interests.
- Typosquatting
Typosquatting is registering a web domain that looks almost like a real one, through a misspelling, swapped letter, extra word or different ending, so that people mistake it for the genuine site.
Threat actors tied to it
- Akira
Profile with government sources
- ALPHV Blackcat
Profile with government sources
- APT29
Profile with government sources
- Black Basta
Profile with government sources
- LockBit
Profile with government sources
- Scattered Spider
Profile with government sources
Last reviewed Oct 2, 2026