Accounts & identity
Credential stuffing
Credential stuffing
An identity and access attack involving credential stuffing that can compromise an online account or authenticated session.
Fiche de sensibilisationPrête à diffuser à vos équipes ou clients
MIGHT YOU BE AFFECTED?
Turn knowledge into action.
How does this work?
Credential stuffing relies on a technical weakness, stolen access or human manipulation. The exact mechanism depends on the target and the attacker’s objective.
REAL-WORLD EXAMPLE
« A victim or organisation encounters signs consistent with credential stuffing and must verify the event before taking further action. »
Typical sequence
- 1Initial access or contact
- 2Exploitation, manipulation or persistence
- 3Impact on accounts, systems or data
Warning signs
- Unexpected activity or security alerts
- Unfamiliar access, software or network behaviour
- Pressure, disruption or unexplained changes
How to protect yourself
- Keep systems and applications up to date
- Use strong access controls and phishing-resistant MFA
- Monitor unusual activity and preserve reliable backups
If you think you are affected
Stop the affected activity, isolate exposed devices or accounts, preserve evidence, revoke suspicious access and contact the appropriate security professional.
Last updated: 6 September 2026