CYBER WELFARE

Protect your Digital Privacy

Credential stuffing and the other attacks that exploit reused passwords

When a password is stolen from one service, it almost never gets used on that service alone. It goes onto a list, and the list gets tried everywhere.

This automated process has a name — credential stuffing — and it is the reason a breach that happened years ago, on a site you had long forgotten, can show up today at the door of your email account.

This post explains that mechanism, along with the other attacks that become more effective when passwords resemble one another. It is the threat-side companion to the recommendation to use a unique password for every account.

One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

Years ago, you signed up for an online service to make a one-off purchase. You used the same password you still use today for your email.

That service suffers a breach, meaning someone gains unauthorised access to its systems. Its user database — email addresses and passwords — ends up in circulation.

From that moment on, your password is no longer private information: it is an entry on a list. And lists get tried.

Why identical or similar passwords increase the risk

All the attacks that follow share one thing: they do not need to guess, they only need to try again.

With different passwords, a stolen credential (the combination of username or email and password you use to sign in) works for one account only. With identical passwords, it works for every account where it was used. With similar passwords, it works almost as well: if the pattern can be worked out, the variations can be generated automatically.

1. Credential stuffing

In plain terms. Someone takes email and password pairs already stolen elsewhere and tries them, automatically, on many different services.

How it works. Lists of credentials circulate after breaches. Automated software tries them on dozens or hundreds of popular websites. The success rate for any single pair is low, but across millions of attempts the overall result is still large.

Why reuse makes it effective. It is quite literally the attack that password reuse makes possible: without shared passwords, it would have nothing to try again.

Possible impact. Access to email, cloud storage, social media and online shopping accounts; from there, access to everything that can be recovered through your email.

What should make you suspicious. Sign-in notifications from unusual locations, alerts that your password has been compromised, sign-in attempts on services you have not used in a long time.

How to protect yourself. Unique passwords, a password manager (an app that creates, stores and fills in your passwords for you) and multi-factor authentication, or MFA (a second check, such as a code on your phone, on top of the password). MFA can stop the attack even when the password is correct.

2. Account takeover

In plain terms. Whoever got in does not just look around: they change the details needed to keep control, and lock you out.

How it works. After signing in, they change the recovery email, the phone number and the password. Sometimes they set up automatic forwarding of your messages, so that their access continues even after you change your password.

Why reuse makes it more likely. Because the initial access is easier to obtain, and because a shared password makes it possible to repeat the same operation on several accounts within the same period.

Possible impact. Permanent loss of the account, use of your identity towards other people, exposure of personal and work files.

What should make you suspicious. Your correct password is rejected, you receive confirmations of changes you did not request, you find forwarding rules you did not create, or your contacts tell you about strange messages from you.

How to protect yourself. MFA, a periodic check of your recovery details, revoking active sessions (signing out every device that is currently connected to the account) and paying attention to emails confirming a change.

3. Password spraying

In plain terms. The reverse of credential stuffing: instead of trying many passwords on one account, a single very common password is tried on a very large number of accounts.

How it works. It starts from widespread passwords — seasons followed by the year, city names, keyboard sequences — and each one is tried only once on a large number of users. By trying very little on each account, the attempts avoid automatic lockouts.

Why reuse makes it more likely. Reused passwords tend to be the “easy to remember” ones, which are exactly the ones most present on lists of common combinations.

Possible impact. Access to work and personal accounts; within organisations, an entry point to internal systems.

What should make you suspicious. Isolated failed sign-in attempts, unexpected verification requests, temporary account lockouts.

How to protect yourself. Long, uncommon passwords — passphrases (a password made of several words strung together) are especially effective here — and MFA.

4. Systematic guessing (brute force)

In plain terms. Trying many combinations until one of them works.

How it works. Against a well-configured service it is not very effective, because the number of attempts is limited or blocked. It becomes realistic when the password is short or predictable, or when the attack is carried out on a stolen database rather than on the live service.

Why reuse matters. A short password reused everywhere, once it has been worked out, opens everything at once.

Possible impact. Compromise of accounts protected by weak passwords, especially older ones.

What should make you suspicious. Numerous failed sign-in attempts, requests for additional verification, repeated lockouts.

How to protect yourself. Length above all: a passphrase of four or five words makes this kind of attempt impractical. Then MFA.

5. Phishing

In plain terms. A message that looks genuine takes you to a page imitating a real service, where you type your password and hand it over to whoever built the page.

How it works. It arrives by email, text message or chat. It plays on urgency — “your account is about to be suspended”, “confirm your payment” — or on something you were actually expecting, such as a delivery.

Why reuse makes it more dangerous. A password obtained through phishing does not open one account: it opens every account where you used it.

Possible impact. Immediate theft of your credentials; if the fake page also asks for your MFA code, the attack can go further.

What should make you suspicious. Unjustified urgency, a sender address that does not match, web addresses slightly different from the official ones, requests for credentials by message.

How to protect yourself. Never sign in from links you received: open the service from its usual address or from the app. A password manager helps here too, because it does not fill in your details on a site other than the one it has saved. Passkeys (a way of signing in with your device and a fingerprint, face or PIN instead of a password) reduce the problem at its root.

6. Manipulating the person (social engineering)

In plain terms. The system is not attacked: a person is persuaded to grant access.

How it works. A phone call from “customer support”, a message from a colleague, a plausible request at a moment when you are in a hurry. Public information on social media profiles makes the request believable.

Why reuse matters. Passwords built on personal details — names, dates, places — are exactly the ones that can be pieced together from the information a person leaves around online.

Possible impact. Handing over credentials or codes voluntarily, authorising access, carrying out operations on someone else’s behalf.

What should make you suspicious. Urgency, a request to keep things confidential, questions about personal details, pressure not to check.

How to protect yourself. Always verify through a different channel from the one the request came through. A legitimate service does not ask you for your password or an MFA code. Do not use personal information in your passwords.

7. Work email fraud (Business Email Compromise)

In plain terms. Someone’s work email account is used to request payments or changes to bank details from colleagues, customers or suppliers.

How it works. After getting into the mailbox, the attacker watches the conversations to learn the tone, the suppliers and the deadlines. Then the request arrives: a change of bank account details, an urgent payment, an updated invoice. It is believable because it uses the real context.

Why reuse makes it more likely. If the password for your work email is the same one you use on personal services, any breach at all is enough to provide the initial access.

Possible impact. Financial losses, even significant ones, damaged trust with customers and suppliers, legal disputes.

What should make you suspicious. Urgent payment requests, changes to bank account details, a tone slightly different from usual, insistence on not checking by phone.

How to protect yourself. MFA on work mailboxes, a mandatory phone check for every change to bank account details, and a clear separation between personal and work credentials.

Summary table

AttackMain riskWhat should make you suspiciousEffective defences
Credential stuffingA stolen password tried again everywhereSign-ins from unusual locations, exposed-password alertsUnique passwords, password manager, MFA
Account takeoverLosing control of the accountCorrect password rejected, recovery details changedMFA, checking recovery details, revoking sessions
Password sprayingCommon passwords tried on a mass scaleFailed attempts, unexpected verifications, lockoutsLong passphrases, MFA
Brute forceShort passwords worked outMany failed attempts, repeated lockoutsPassword length, MFA
PhishingHanding your password to a fake siteUrgency, addresses that look similar but are not the sameSigning in only from official addresses, password manager, passkeys
Social engineeringAccess obtained by persuading a personUnusual requests, pressure, confidentialityVerifying through another channel, MFA
Business Email CompromiseFinancial fraud in your nameBank detail changes, urgent paymentsMFA, phone verification of payments, separate credentials

What they have in common

Seven different attacks, three defences that cut across almost all of them:

  1. Unique passwords — they take away the attacker’s ability to reuse what they already have.
  2. Multi-factor authentication — it works even when the password has already been obtained.
  3. Verification through a different channel — it takes apart phishing, social engineering and BEC, which all rely on haste.

These are not advanced measures. They are the first three things anyone can do, and they cover most real-world cases.

Protection checklist

  • ☐ No password is repeated or built as a variation of another
  • ☐ Long passphrases instead of short words with symbols
  • ☐ A password manager is in use
  • ☐ MFA is on for email, banking, cloud storage and work accounts
  • ☐ MFA recovery codes (the backup codes that let you back in if you lose your phone) are kept in a safe place
  • ☐ Services are always reached from their official address, never from links in messages
  • ☐ Every change to bank account details is verified by phone
  • ☐ Sign-ins, devices and connected apps are reviewed periodically

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that these attacks are not aimed at you personally, but are automated and carried out on a large scale
SkillsRecognising the mechanism of each attack from its signals
Secure BehaviourChecking before acting, especially when someone is rushing you

Reference level: FL2 — Beginner, with elements of FL3 — Autonomous in the sections on BEC and social engineering.

Conclusion

The attacks described here do not require extraordinary skills from the people carrying them out, and they are not aimed at you in particular. They work at scale, and they find fertile ground wherever the same credentials are repeated.

That is why the most effective defence is not technical but a matter of organisation: a different password for every account, and a second factor where it counts.

Something to think about. If one of your passwords appeared on a public list tomorrow, could you say how many services it still works on?

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.