Avatier

Phished or stolen credentials

Credential stuffing

Credential stuffing is an automated attack that takes usernames and passwords leaked from one service and tries them on many others. It works because people reuse passwords. Each successful match gives the attacker a real account without guessing, phishing or exploiting any software flaw, and the login looks like the genuine user.

How it works

Attackers load large lists of leaked email and password pairs into tools that try each pair against a target's login page, often spread across many IP addresses to avoid rate limits. Most attempts fail, but a small success rate across millions of pairs still yields many working accounts, which are then used directly or sold.

A real example

In a notification letter filed with the California Attorney General, 23andMe said it believed a threat actor ran a credential stuffing attack from May 2023 through September 2023 to access some customer accounts.

Source: 23andMe notification letter to California residents — 23andMe, Inc. (filed with the California Attorney General), 2024-01-21

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Require MFA on every account and check new and existing passwords against known-breached password lists, so a reused password alone cannot open an account.

Related terms

Sources

  1. 23andMe notification letter to California residents — 23andMe, Inc. (filed with the California Attorney General), 2024-01-21

Last reviewed Oct 2, 2026