Cybersecurity Glossary
Credential Stuffing
Automated testing of passwords stolen from one service against accounts on many others.
What Credential Stuffing means
Attackers buy or download lists of email addresses and passwords exposed in past breaches, then use software to try them across hundreds of other services. Because password reuse is common, a small percentage succeeds, and that percentage of millions is a large number of accounts.
Why Credential Stuffing matters for small businesses and nonprofits
This is why a breach at a service you barely remember can end in your business mailbox being taken over. It requires no skill and no targeting, and it runs continuously against every login page on the internet, including yours.
What to do about Credential Stuffing
- Use a password manager so every account has a different password
- Turn on multi factor authentication on email first, then everything else
- Check your domains against public breach notification services regularly
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.