Credential stuffing is a cyber-attack method wherein attackers utilize automated tools to systematically input large volumes of username and password pairs, typically obtained from previous data breaches, to try and gain unauthorized access to user accounts across various online services. This method relies on the unfortunate reality that many users reuse passwords across multiple platforms, thereby exploiting the compromise of credentials from one source to compromise accounts on other platforms.
In 2018, credential stuffing attacks on popular platforms like Reddit and Spotify were reported. Attackers used usernames and passwords obtained from previous data breaches on other sites to gain unauthorized access to user accounts on these platforms.
Loading comments 0%