Account takeover

Credential stuffing: how leaked passwords open your other accounts

Credential stuffing takes e-mail and password pairs leaked from one site and tries them on thousands of others with bots. If you reused a password even once, it can open your accounts years later. This guide shows where the lists come from, how to tell you were hit, what to do and how to make the attack fail.

How credential stuffing works: a site leaks logins, lists are merged into combolists, bots try every pair through proxies and reused passwords open accounts
Credential stuffing in four steps. Each login attempt comes from a different address, and only reused passwords come back as hits.
Where the logins come from
Old breaches, combolists and stealer logs
Time needed
About 30 to 60 minutes to secure your main accounts
Built-in help
Password managers flag reused and leaked passwords
Works on
Any site where you sign in with an e-mail and password

Need it gone quickly?

Ad: partner link. We may earn a commission if you buy. The steps below work without it.

What credential stuffing is

Credential stuffing is an attack where someone takes e-mail and password pairs leaked from one website and tries them, automatically, on many other websites. OWASP defines it as testing username and password pairs obtained from the breach of another site [1]. It needs no malware on your device and no flaw in the site it hits. It only needs you to have used the same password twice.

Our trojans guide covers the malware that steals logins in the first place, and the info stealers guide explains how one infected PC turns into a log of passwords and cookies. This page covers what happens next: how those logins and old breach data become account takeovers, and how you make them useless.

Credential stuffing, password spraying and brute force

The three are often mixed up, but each one needs a different fix. OWASP separates credential stuffing from password spraying, which tests one weak password against a large number of different accounts [1].

How credential stuffing differs from other password attacks
AttackWhat the attacker triesWhat stops it
Credential stuffingReal pairs leaked elsewhere, one try per accountA unique password per site, two-step verification, a passkey
Password sprayingOne common password, such as Summer2026!, on many accountsA long password that is not on any common list
Brute forceEvery possible password on one accountLockouts and rate limits on the site, a long password
Session hijackingA stolen login cookie, no password at allRemoving the stealer and signing out of every session

Credential stuffing is hard to spot from the site's side because each attempt looks like an ordinary login. The username is real, the password was real somewhere, and only one or two tries are made per account. Even if only one pair in a thousand works, a list of a million pairs still opens a thousand accounts.

Why reused passwords are the whole problem

Credential stuffing works only because people reuse passwords. When a forum, shop or game you joined years ago leaks its user table, your e-mail and that password stay valid on every other site where you typed the same combination. The site you used in 2016 may be long gone, but the pair is still in circulation.

Small variations, such as adding the year or the site's name to a base password, do not help much. Treat a base password you tweak per site as one password used everywhere.

Where the lists come from

The raw material comes from three places, and you can check all three in our breach database.

1. Old breaches

Every breach that exposes passwords, whether stored in plain text or cracked from weak hashes, adds pairs to the pool. They keep working for years, because people rarely change a password they are not forced to change.

2. Combolists

A combolist, short for combination list, merges many breaches into one file of e-mail:password lines, cleaned of duplicates and ready for a checker tool. The same pairs turn up again and again under new names. The biggest ones we track:

3. Stealer logs

Stealer logs are the newer and more dangerous source. A stealer on an infected PC records the website, the username and the password exactly as saved in the browser. That means the pair is fresh, it is tied to the right site, and it works even if you never reused it. Recent stealer log sets in our database:

Bar chart of the largest credential stuffing lists by unique e-mail addresses, from Synthient and Collection #1 to recent stealer log sets
The largest lists in our breach database, counted by unique e-mail addresses. Grey bars are combolists built from old breaches, red bars are stealer logs.

Combolists catch people who reuse passwords. Stealer logs also catch people who do not, which is why the defences below come in layers.

Real cases

23andMe, 2023

In its filing with the US Securities and Exchange Commission, 23andMe said the attacker accessed about 0.1% of user accounts directly [4]. The usernames and passwords used were the same as those used on other websites that had been compromised or were otherwise available [4]. Through those accounts the attacker reached a large number of files with profile data about other users who were connected through the DNA Relatives feature [4]. The company required all users to reset their passwords on 10 October 2023, and from 6 November 2023 it made two-step verification mandatory [4].

Roku, 2024

Roku reported two credential stuffing incidents in 2024. While monitoring after the first one, it found a second that affected about 576,000 more accounts [5].

Snowflake customer accounts, 2024

Mandiant reported that a group it tracks as UNC5537 used stolen credentials to get into Snowflake customer instances, and that about 165 organisations were notified as potentially exposed [3]. The credentials came from infostealer infections including Vidar, RisePro, RedLine, Raccoon Stealer, Lumma and MetaStealer [3]. Some dated back to 2020 and had never been changed [3].

Mandiant named three causes: no multi-factor authentication, passwords still valid years later, and no network allow lists limiting where logins could come from [3].

How attackers get around a site's defences

Sites try to block automated logins, and the attackers' tools are built to slip past each check. That is why your own settings matter more than the site's.

  • Proxies. Checker tools such as Sentry MBA spread requests over many unique IP addresses through proxy networks, so no single address looks busy [1]. OWASP notes that blocking IP addresses should not be the sole defence because it is so easy to get around [1].
  • CAPTCHA solvers. OWASP warns that tools and services exist that break CAPTCHAs with a reasonably high success rate [1]. A CAPTCHA raises the cost of an attack but rarely ends it.
  • Real browsers. When a login page demands JavaScript, attackers move to automation frameworks and headless browsers that run it [1]. Site defences then fall back on device and connection fingerprints [1].
  • Session cookies. A stealer log often holds live login cookies as well as passwords. With a cookie the attacker skips the login and the two-step check. For stuffing, it means a password change alone does not end the access.

Signs your account was stuffed

Most people find out from the site, not from their own checks. Look for these:

  • A new sign-in alert by e-mail or push for a device, browser or city you do not recognise.
  • A one-time code or two-step prompt you did not ask for. That means someone already has your password for that site.
  • Your password stops working, or the recovery e-mail or phone number on the account has changed.
  • Orders, subscriptions, gift card purchases or loyalty point transfers you did not make.
  • Unknown devices on the account's active sessions page, or new profiles on a streaming account.
  • Your e-mail address shows up in a combolist or stealer log in our breach database or in a breach alert from your password manager.

Fake security alerts are a common phishing lure, so open the site by typing its address, not through the alert's link. If you are unsure about a link, scan it first.

What to do if your account was stuffed

  1. Change the password on the affected account to a new, unique one. Use the site's own app or typed address.
  2. Sign out of all other sessions. Most services have a sign out everywhere or active devices option under security settings. This ends any session the attacker opened.
  3. Check the recovery e-mail, phone number, delivery addresses, saved cards and, for e-mail accounts, forwarding rules and filters. Attackers change these to keep access.
  4. Turn on two-step verification. Our step-by-step 2FA guide covers the main services. An authenticator app or passkey beats an SMS code.
  5. Change the same password on every other site where you used it. Start with e-mail and banking.
  6. Check whether the leak came from a stealer on your own device. If the site says the password was unique, or your e-mail appears in a stealer log set, assume malware and follow how to secure your accounts after malware.
  7. Contact the service if money moved or you cannot get back in, and ask your bank to block any card that was saved on the account.

If the alert came from a named breach rather than a takeover, our guide on what to do after a data breach covers the wider steps, such as freezing credit and watching for targeted phishing.

If the logins came from a stealer on your PC

Changing passwords on a computer that still runs a stealer just hands the new ones over. Scan the device before you change anything important. Fortect, the tool we offer on this page, runs a free Windows scan that includes a Malware and PUA stage, and its paid plans add an antivirus that watches new downloads, installs and files in real time. It also repairs Windows files that malware damaged. Our Fortect review shows what each scan stage checks. After the device is clean, change your passwords from it and sign out of every session again.

How to make credential stuffing stop working on you

Table comparing unique passwords, two-step verification, passkeys, breach alerts and stealer removal against combolists, stealer passwords and stolen cookies
Each defence covers a different attack. Unique passwords end combolist reuse, a second factor or passkey stops stolen passwords, and only removing the stealer ends cookie theft.

Use a password manager for unique passwords

A password manager creates a different random password for every site and fills it for you, so a leak at one site opens nothing else. Most also warn you about reused or breached passwords. Start with your e-mail account, because it can reset every other password.

Switch to passkeys where you can

A passkey replaces the password with a cryptographic key stored on your device or synced across your devices. There is no password to leak or reuse, so a combolist has nothing to try. NIST counts this kind of authenticator as phishing resistant, because it will not hand its secret to a fake site [2]. Many large services already offer passkeys under their sign-in or security settings.

Turn on two-step verification everywhere it exists

OWASP calls multi-factor authentication by far the best defence against credential stuffing and password spraying [1]. With it on, a correct password alone does not get in. Use an authenticator app or a security key where offered, and keep SMS as a fallback only. Remember that a stolen session cookie skips this step, which is why a clean device still matters.

Get breach alerts

Turn on the leaked-password warnings in your password manager and sign up for breach notifications for your e-mail address. Search your address in our breach database to see which combolists and stealer log sets include it.

For site owners: how to stop credential stuffing

If you run a site with logins, OWASP and NIST set out what works. Layer these controls:

  • Offer and encourage multi-factor authentication, and require it for administrators [1]. Add risk-based prompts for new devices, unusual locations and automated behaviour [1].
  • Check passwords against known breached passwords when users set or change them. NIST SP 800-63B says verifiers shall compare a new password against a blocklist that includes compromised passwords [2]. OWASP points to Pwned Passwords as a free source for this [1].
  • Limit failed attempts per account. NIST requires a rate limit and caps consecutive failed attempts on one account at 100 [2]. Count per account as well as per IP, because stuffing uses one try per account from many addresses.
  • Do not force regular password changes. NIST says verifiers shall not require periodic changes, but shall force a change when there is evidence of compromise [2], such as the account appearing in a stealer log.
  • Do not impose composition rules such as one capital and one symbol [2]. Require a minimum length instead: 15 characters for a password used alone, 8 when it is part of multi-factor login [2].
  • Use device and connection fingerprinting, IP reputation and CAPTCHAs triggered by risk rather than on every login [1].
  • Notify users of unusual security events, for example a correct password followed by a failed second factor, and give them a login history and a way to end sessions [1].
  • Offer passkeys, which take the password out of the login entirely.

A spike in failed logins spread over many accounts, with many usernames that do not exist, is the fingerprint of a stuffing run. For a second opinion on a suspicious login, ask on our Windows help forum.

Frequently asked questions

What is credential stuffing?

Credential stuffing is an automated attack where leaked e-mail and password pairs from one website are tried on many other websites. It works when people reuse the same password, so a breach at one small site can open accounts at large ones.

What is a combolist?

A combolist is a file of e-mail and password pairs merged from many earlier breaches, cleaned up and formatted for automated login tools. Well-known examples are Collection #1, Exploit.In and Anti Public, each with hundreds of millions of addresses.

What are stealer logs?

Stealer logs are files produced by info stealer malware on infected computers. Each log lists the websites, usernames and passwords saved in the browser, often with session cookies. They are sold or shared in bulk and then used for credential stuffing and account takeover.

How is credential stuffing different from brute force?

Brute force guesses many passwords for one account. Credential stuffing tries one real, previously leaked password per account across many accounts, so it causes few failed logins per user and is harder to detect.

Can two-step verification stop credential stuffing?

Yes, in most cases. A correct password alone does not get past two-step verification. It does not help if the attacker steals a live session cookie from a stealer on your device, so keep the device clean as well.

How do I know if my password is in a combolist?

Search your e-mail address in a breach database such as ours, and turn on the leaked-password check in your password manager. Both tell you whether your address or password appears in known combolists and stealer log sets.

I use a unique password. Can I still be a victim?

Yes, if a stealer on your device records the password for that exact site, or if the site itself is breached. Unique passwords stop reuse attacks; two-step verification or a passkey covers the rest.

Do passkeys stop credential stuffing?

Yes. A passkey has no password that can leak or be reused, so there is nothing for a combolist to try. Accounts that still allow a password as a fallback should also have two-step verification turned on.

Sources

  1. OWASP Cheat Sheet Series: Credential Stuffing Prevention read 2026-10-09
  2. NIST SP 800-63B-4: Digital Identity Guidelines, Authentication and Authenticator Management read 2026-10-09
  3. Google Cloud Threat Intelligence (Mandiant): UNC5537 targets Snowflake customer instances for data theft and extortion (10 June 2024) read 2026-10-09
  4. 23andMe Holding Co., Form 8-K/A filed with the US Securities and Exchange Commission (December 2023) read 2026-10-09
  5. Roku: Protecting your Roku account (2024 security incident update) read 2026-10-09

Follow the story: Info stealers and stealer-log leaks

Lumma, RedLine, Vidar, AMOS and the huge leaks of passwords they stole from infected PCs. 13 events so far, updated Oct 7, 2026.

See the full timeline →

More from the trojans guide

What is a trojan and how to remove itA trojan is malware disguised as something you wanted, such as a cracked program, a fake update or an invoice. It does nothing until you run it, then steals passwords, gives a stranger remote access or downloads more malware. To remove it, cut the startup entries it added, run a full and an offline scan, then change your passwords from a clean device.Best trojan removal tools in 2026A trojan scan has to find more than the file you ran. It must catch the payloads that file fetched and the entries that restart them. This page compares six tools we reviewed, explains Defender's trojan names and false positives, and shows the scanning order that works.Info stealers: what they take, how fast, and what to doAn info stealer is malware that copies the passwords, session cookies, crypto wallets and app logins stored on your computer and uploads them, often within a minute of being started. Removing it protects the future, not the data that already left. This guide explains what stealers take, which families are active in 2026, and the order of steps that actually closes the door.Remote access trojans (RATs): how to tell if someone is in your PC and lock them outA remote access trojan gives a stranger the same control over your PC that you have at the keyboard: your screen, files, saved passwords, webcam and microphone. This guide shows what RATs and abused remote support tools can do, how to check Windows 11 and 10 for an active connection, and the order that removes the attacker and keeps them out.
5,454 members already hereReading, writing, commenting and voting. 0 verified · 179 joined this year