Avatier

Attack vector

Phished or stolen credentials

Phished or stolen credentials are a valid username and password that reach an attacker through a fake login page, password reuse, infostealer malware logs, a purchased credential dump or an earlier breach. The attacker then signs in as the real user, so the access looks legitimate and no exploit is needed to get through the front door.

A valid username and password reached the attacker — phished, reused, purchased, or taken from an earlier breach.

How attackers use it

Attackers send convincing login pages by email or text, buy credential lists from earlier breaches, or try reused passwords across many services. Once a pair works, they sign in like the real user, often from infrastructure that looks ordinary, and start exploring what that account can reach. Because nothing was exploited, the first sign of trouble is usually what the account does next.

What breach letters say

31 distinct incidents in California breach filings name this vector in the letter’s own words (January 1, 2023 – August 14, 2026).

The 3 most recent of 31:

  • “Xsolis became aware of unauthorized activity resulting from a targeted phishing attack on January 22, 2026.”

    Xsolis, Inc. · filed Jul 21, 2026 · letter

  • “On November 17, 2025, First Advantage became aware that an unauthorized third party obtained access through sophisticated phishing to a single First Advantage Drug & Occupational Health Screening Unit employee’s account.”

    First Advantage Corporation · filed Jun 23, 2026 · letter

  • “Within 24 hours of the event, we had removed the compromised access credentials, and improved the security protocols and processes associated with accessing the system.”

    Nickey Kehoe · filed May 26, 2026 · letter

See the Identity Attack Ledger

How to stop it

Phishing-resistant MFA, such as passkeys or FIDO2 security keys, makes a stolen password useless on its own once weaker fallback methods such as SMS codes and security questions are retired. Pair it with checks against known-breached passwords so reused credentials are caught before they are tried.

Terms under this vector

  • ClickFix

    ClickFix is a social engineering technique that tricks a user into running malicious commands on their own computer.

  • Combo list

    A combo list is a file of username and password pairs, usually email addresses and passwords, compiled from earlier data breaches, phishing and malware logs.

  • Credential stuffing

    Credential stuffing is an automated attack that takes usernames and passwords leaked from one service and tries them on many others.

  • Infostealer

    An infostealer is malware that collects saved passwords, browser cookies, session tokens, autofill data and crypto wallets from an infected computer and sends them to the attacker.

  • Password spraying

    Password spraying is a brute-force attack that tries a few common passwords against many accounts, instead of many passwords against one account.

  • Phishing kit

    A phishing kit is a ready-made package of fake login pages, scripts and hosting tools that lets someone launch a phishing campaign without building it.

  • Quishing

    Quishing is phishing that hides a malicious link inside a QR code.

  • Smishing

    Smishing is phishing delivered by text message.

  • Spear phishing

    Spear phishing is a phishing attack aimed at a specific person or small group, written with details about the target's job, contacts or interests.

  • Typosquatting

    Typosquatting is registering a web domain that looks almost like a real one, through a misspelling, swapped letter, extra word or different ending, so that people mistake it for the genuine site.

Threat actors tied to it

Last reviewed Oct 2, 2026