Mass attacks with stolen passwords... how to protect yourself

If you use the same password on multiple accounts, you think you're choosing convenience, but in reality you're choosing risk. "When one site is compromised, cybercriminals don't stop there," explains Christian Ali Bravo from the team at cybersecurity firm ESET. "They take the stolen credentials and automatically try them on thousands of other sites. That's the credential stuffing».Password

This attack is particularly dangerous because it doesn’t require attackers to “crack” each password individually. Instead, cybercriminals steal lists of usernames and passwords from a compromised site and automatically try them on many others – email, social media, banks and e-shops. If the password works even once, they have gained access to a real account.

See more articles from iGuRu.gr when you search for news on Google.

For the average citizen, this translates into a simple but serious reality: their account can be hacked without them making any mistakes at the time. They just need to use the same password on another site that was compromised, even if the site they are currently using is completely secure.

In practice, credential stuffing is the digital equivalent of someone finding a key that opens your home, office, and safe at the same time. And obtaining that "key" is not at all difficult, emphasizes Ali Bravo from ESET.

Cybercriminals can acquire it from previous data breaches or even purchase it in the cybercrime ecosystem. They also often use infostealer malware, which extracts credentials directly from compromised devices and browsers.

So what makes credential stuffing so dangerous and effective?

This threat is generating significant profits for cybercriminals. To illustrate the scale of the problem, NordPass recently published a survey that found that 62% of Americans admit to reusing the same password “often” or “always.”

The extent to which credential stuffing attacks can be carried out is typified by the following examples:

  • PayPal (2022): The company reported that nearly 35.000 customer accounts were compromised through credential stuffingThe fintech company itself was not breached; the attackers leveraged login credentials from previous data breaches, gaining access to user accounts that had used the same passwords across multiple services.
  • Snowflake (2024): The wave of attacks on Snowflake customers highlighted a different dimension of the problem. The data storage and processing platform itself was not compromised, but the incident affected approximately 165 customer companies. The attackers used credentials previously stolen via the infostealer malware to gain access to multiple Snowflake corporate accounts, with some victims later receiving ransom demands.

How to protect yourself

Here are some practical steps you can take to stay safe. The first step is particularly simple:

  • Do not use NEVER the same password across multiple websites or services. A password manager makes this step very easy, as it can generate and store strong, unique passwords for each account.
  • Enable two-factor authentication (2FA) whenever it is available. Even if attackers know the password, they will not be able to log in without the second factor.
  • Stay alert. and use services like haveibeenpwned.com to check if your email or credentials have been exposed in previous leaks or breaches. If this has happened, change your passwords immediately, especially for accounts that store sensitive data.

How to protect your company

Today, credential compromise is a key driver of account takeovers, fraud, and large-scale data theft across many industries, including retail, finance, SaaS (Software as a Service), and healthcare. Yet many companies still rely solely on passwords for authentication. Even when two-factor authentication (2FA) is available, it is often not implemented by default.

Organizations should adopt additional protection measures, such as limiting login attempts, using whitelists or IP whitelists, monitoring unusual login activity, and implementing bot or CAPTCHA detection systems to prevent automated abuse.

It’s worth noting that more and more organizations are moving toward passwordless authentication, such as passkeys, which render credential stuffing essentially ineffective. However, adoption of these methods remains uneven, and established practices are difficult to change. As a result, it’s not surprising that credential stuffing continues to offer high performance to attackers with minimal effort.

At the same time, millions of leaked credentials remain active for a long time after a breach, especially when users never change their passwords. Under these circumstances, credential stuffing remains a low-cost, highly scalable, and consistently effective method for cybercriminals.

Credential stuffing is a simple, low-cost, and scalable attack technique. It works because it uses our own habits against us and undermines outdated security measures. Until passwords are completely eliminated, the risk of account compromise can be neutralized through careful password management practices.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).