Ultimate Guide For Credential Stuffing Prevention

  • By David Lukic
  • Published: May 26, 2021
  • Last Updated: Mar 18, 2022

Dozens of major data breaches in the U.S. have leaked countless usernames and passwords to the dark web and into the hands of hackers. Yours may be among them, and if you reused your passwords elsewhere, your accounts could be at risk of credential stuffing.

What is Credential Stuffing?

Credential Stuffing

Credential stuffing is when cybercriminals use your stolen credentials from one account and use them on another, trying to steal data or for an account takeover. Usernames and passwords are leaked or stolen in data breaches frequently, and they end up in massive databases on the dark web for sale. Anyone who purchases them may have your account details. Once they do, they will try to use them on other accounts such as bank accounts, Netflix, credit card company accounts, and other places.

Statistics show that credential stuffing is one of the major causes of subsequent data breaches. The problem is that roughly 65% of people reuse usernames/emails and passwords on multiple accounts, making it easy for criminals to get in. Threat experts say there are billions of stolen credentials online, among them some of yours are probably included. 

Credential stuffing is often confused with brute force attacks, but they are different. Brute force attacks are another type of cyberattack where hackers use automation to guess random passwords rather than use those stolen in a data breach. 

How Does a Credential Stuffing Attack Work?

Credential Harvesting

Typically, a hacker will get ahold of a batch of user credentials and create or purchase a program or use a network of linked devices (botnet) that automatically trolls the intent and tries those credentials on other logins. 

These large-scale attacks can overwhelm a system and cause a Distributed Denial of Service (DDoS) attack in the process. Often hackers use a botnet so that each login appears to come from a different IP address, so they do not get locked out from too many attempts from the same location. Online login forms often limit floods of activity to shut out hackers. 

The Value of Credential Harvesting

Some of the most valuable credentials found on the dark web are for Netflix, Disney+, and Spotify. Bank accounts, credit cards, web applications, and other financial logins are also especially profitable for cybercriminals. 

Email accounts, social security numbers, driver’s license numbers, passports, and other personally identifiable information (PII) is also like gold to hackers because they can use it for identity theft or fraud

In recent years hackers have combined large numbers of data breach sets into massive databases called “Collections” to date, there are Collections #1-5 totaling billions of username/password combinations. Since these compilations, credential stuffing attacks have spiked. These collections range in price from $9,350 (Bitcoin) to $20,000 on the dark web.

The good news is many of these login credentials were stolen in old data breaches, and the owners have since changed their passwords, so they no longer work. 

Attackers have to use millions of account credentials to achieve even a 1-2% success rate. Some attackers simply want to break in only to steal more information to sell on the dark web. Others take over the account and change the login so that the rightful owner can no longer access it. In other cases, they may steal money or credit card numbers stored within the account and charge purchases on them. The worst is when they can access your bank account and drain the funds before you find out about it.

Credential Stuffing PreventionCredential Stuffing Attack

The best way you can protect yourself against credential harvesting is to always use unique passwords on all of your accounts and change them often. Some other tips to stay safe and prevent this type of attack are:

  • Use really long, strong passwords on all your accounts.

  • Avoid password reuse at all costs. 

  • Invest in a good password vault or a password manager to keep all your password pairs locked up safe.

  • Turn on two-factor authentication whenever possible on all your online accounts.

  • Never click links in emails or download attachments. Hackers get you to provide credentials using phishing attacks. Links and downloads often install malware on your device. 

  • Use biometric or multi-factor authentication (like fingerprinting) for logging in. Many mobile apps allow this. 

  • Protect your personal data whenever possible.

  • Use IDStrong’s random strong password generator

What Are Companies Doing to Avoid Credentials Stuffing?What is Credential Stuffing

Companies like Netflix, Google, Nest, and Dunkin’ Donuts have experienced huge credential stuffing attacks. Since then, many of these large companies are beefing up their cybersecurity measures. Some like Google may force a password reset after a specific length of time or lock you out after a certain number of failed login requests. Some organizations actually check data breaches in a very proactive approach to see if their user’s accounts were found and then force a password reset.

Threat experts suggest that companies get in the habit of tracking IP addresses when an account is breached to create a blacklist of spoiled IPs, which will hamper the attackers’ efforts. Basecamp withstood an attack of 30,000 failed login attempts in one hour. They immediately began blocking IPs and added a CAPTCHA to their login form to prevent automated logins from non-legitimate users. That one attack resulted in only 124 user accounts being compromised.

Another very effective way to prevent credential harvesting from the corporate side of things is to institute two-factor authentication into your system. It will require that anyone trying to log in provide additional information such as a text message or emailed code. Even if a hacker has authentic credentials, they won’t likely be able to continue without that code. It may prevent a good number of user accounts from being breached. Another option is to invest in biometric logins or multi factor authentication (MFA) and ditch passwords altogether. 

Even though the loss for the customer may be significant, the impact on a retailer is even worse. Your reputation may be tarnished, and you may lose business as backlash for not protecting user accounts as well as possible. 

Another side effect may be a blow to your information security department and downtime of your systems. Putting preventative measures into place is less costly in the long run. As these attacks become more prevalent, there is also the question of compliance. Some government agencies (such as the GDPR) sanction companies that do not do enough to protect their customers’ and employees’ data.

About the Author
IDStrong Logo

Related Articles

How To Make Your IG Account Private

There are occasions when it makes more sense to have a private Instagram (IG) account. You might w ... Read More

Windows 10 Privacy Settings You Should Change Now

Privacy is a buzzword we hear a lot these days in the wake of data breaches, Wikileaks, and other ... Read More

How to Delete Your Facebook Account

It might seem absurd to some people who live on Facebook, deleting your Facebook account. But, man ... Read More

How to Change Network From Public to Private On Windows

Privacy has become a major concern for many of us after reading about all the data breaches, hacki ... Read More

Twitter Security and Privacy Settings Made Simple

With data breaches and ransomware intrusions in the news daily, privacy is the word on everyone&rs ... Read More

Latest Articles

Financial Business and Consumer Solutions Data Breach

Financial Business and Consumer Solutions Data Breach

Financial Business and Consumer Solutions (FBCS) was founded in 1982 as Federal Bond Collection Services and currently has over 100 employees.

Wattpad Data Breach

Wattpad Data Breach

Reportedly, in the top 160 most visited websites in the world, Wattpad prides itself as the world's most loved storytelling platform.

Teleperformance Breach

Teleperformance Breach

Teleperformance began its operations in 1910 in Paris, France, as a customer service management company. The company founded its United States division in 1993, which is situated in Salt Lake City, Utah.

Featured Articles

How to Buy a House with Bad Credit

How to Buy a House with Bad Credit

Buying your own home is the American Dream, but it might seem out of reach to those with bad credit. However, the good news is, if your credit is less than perfect, you do still have options and in most cases, can still buy a home.

How Secure Is Your Password? Tips to Improve Your Password Security

How Secure Is Your Password? Tips to Improve Your Password Security

Any good IT article on computers and network security will address the importance of strong, secure passwords. However, the challenge of good passwords is that most people have a hard time remembering them, so they use simple or obvious ones that pose a security risk.

Top 10 Senior Scams and How to Prevent Them

Top 10 Senior Scams and How to Prevent Them

Senior scams are becoming a major epidemic for two reasons. First, seniors often have a lot of money in the bank from a life of working hard and saving.

Free Identity Exposure Scan
Instantly and Securely Check if Your Personal Information is Exposed on the Dark Web or Sold by Data Brokers
Please enter first name
Please enter last name
Please select a state
Free Identity Threat Scan
Instantly Check if Your Personal Information is Exposed
All fields below are required
Please enter first name
Please enter last name
Please enter a city
Please select a state
Please enter an age
Please enter an email address