What the experts say
"Password reuse is one of the fastest paths to identity theft. One breached account can unlock many more—especially email, which acts as a gateway to everything else."
If your information is exposed or stolen in a data breach, it can end up on the dark web where it can be sold for as little as 10 cents.
LifeLock monitors hundreds of millions of data points a second.
††† Up to $1 million coverage for Lawyers and Experts included with all plans. Reimbursement and expense compensation vary according to plan. Insurance benefits are issued by third parties. See LifeLock.Norton.com/legal for policy info.
1 Credit features require successful setup, identity verification and sufficient credit history by the appropriate credit bureau. Credit monitoring features may take several days to activate after enrollment.
7 Scam protection coverage as part of identity theft benefits is currently available to all customers residing in the United States, including U.S. territories and the District of Columbia, with the exception of residents of New York. Gen Digital is not a licensed insurance producer. Benefits under the Master Policy are issued and covered by HSB Specialty Insurance Company. You can find further details and exclusions in the Summary of Benefits.
8 After setup, automatic data broker removal service scans and requests removal every 90 days.
Identifying your concerns gives us the ability to recommend the right plan for your needs.
Knowing this number helps us recommend coverage that fits your needs.
Providing your email address makes you eligible for notifications of potential identity threats.
Has your personal data been recently exposed?
Check if information like your Social Security number, email, and passwords is exposed on the dark web.
You have reached the maximum number of scans allowed. Please come back after 24 hours.
Scanning the dark web...
Scanning public databases...
Scanning millions of records...
Narrowing down the search...
Please enter a few more details to ensure we show you the right information.
We found your personal information on the dark web and on data broker sites.
No one can prevent all cybercrime or prevent all identity theft.
††† Up to $1 million coverage for Lawyers and Experts included with all plans. Reimbursement and expense compensation vary according to plan. Insurance benefits are issued by third parties. See lifelock.norton.com/legal for policy info.
1 Bureau Monitoring and Monthly Credit Report and Score / 3 Bureau Monitoring and Monthly Credit Report and Score.
2 Credit Lock cannot prevent all account takeovers, unauthorized account openings, or credit file inquiries. Deactivates if you downgrade or cancel your subscription.
7 Scam protection coverage as part of identity theft benefits is currently available to all customers residing in the United States, including U.S. territories and the District of Columbia, with the exception of residents of New York. Gen Digital is not a licensed insurance producer. Benefits under the Master Policy are issued and covered by HSB Specialty Insurance Company. You can find further details and exclusions in the summary of benefits.
8 After setup, automatic data broker removal service scans and requests removal every 90 days.
We found your personal information on data broker sites.
No one can prevent all cybercrime or prevent all identity theft.
††† Up to $1 million coverage for Lawyers and Experts included with all plans. Reimbursement and expense compensation vary according to plan. Insurance benefits are issued by third parties. See lifelock.norton.com/legal for policy info.
1 Bureau Monitoring and Monthly Credit Report and Score / 3 Bureau Monitoring and Monthly Credit Report and Score.
2 Credit Lock cannot prevent all account takeovers, unauthorized account openings, or credit file inquiries. Deactivates if you downgrade or cancel your subscription.
7 Scam protection coverage as part of identity theft benefits is currently available to all customers residing in the United States, including U.S. territories and the District of Columbia, with the exception of residents of New York. Gen Digital is not a licensed insurance producer. Benefits under the Master Policy are issued and covered by HSB Specialty Insurance Company. You can find further details and exclusions in the summary of benefits.
8 After setup, automatic data broker removal service scans and requests removal every 90 days.
We didn’t find your personal information across millions of records or on public data sources.
No one can prevent all cybercrime or prevent all identity theft.
††† Up to $1 million coverage for Lawyers and Experts included with all plans. Reimbursement and expense compensation vary according to plan. Insurance benefits are issued by third parties. See lifelock.norton.com/legal for policy info.
1 Credit features require successful setup, identity verification, and sufficient credit history by the appropriate credit bureau. Credit monitoring features may take several days to activate after enrollment.
2 Identity Lock cannot prevent all account takeovers, unauthorized account openings, or credit file inquiries. Deactivates if you downgrade or cancel your subscription.
8 After setup, automatic data broker removal service scans and requests removal every 90 days.
Credential stuffing affects millions of consumers each year, leading to data breaches and compromised accounts. In 2023, personal genomics company 23andMe reported that 14,000 user accounts were breached after another company's data leak exposed reused passwords. The attack revealed sensitive information such as display names, genetic ancestry, and locations of nearly 7 million people.
Thankfully, there are steps you can take to protect yourself from credential stuffing attacks. Keep reading to discover how credential stuffing works, and, more importantly, how to safeguard your personal information with practical, proactive measures.
Credential stuffing (also called password stuffing) is a cyberattack in which hackers use stolen username and password combinations to brute force their way into user accounts.
Usually, attackers obtain leaked credentials after data leaks. Because online users often reuse passwords for multiple accounts (an account privacy no-no), attackers can then run automated tools to test large lists of compromised usernames and passwords until they find another account using matching credentials.
Once they gain account access, they can steal personal information, make fraudulent purchases, or sell account details on the dark web.
Credential stuffing is technically a type of brute force attack. But, the biggest difference is that credential stuffing uses known username-password pairs gleaned from data breaches to target accounts, while brute force attacks blindly guess passwords through random combinations until they’re successful.
Credential stuffing works by using bots (automated software programs designed to perform repetitive tasks) to test stolen credentials, helping cybercriminals gain unauthorized access to accounts so they can exploit the account user's personal information.
Here's a step-by-step look at the credential stuffing process:
The first step in credential stuffing is for the attacker to obtain stolen account credentials. These credentials can come from several sources:
Once the attacker gains access to a list of stolen usernames, passwords, or both, they deploy bots to automatically test these credentials across various websites. To prevent being blocked for excessive failed login attempts or other suspicious activity, these bots can conceal their IP addresses, evading detection.
When the bots find a match, the attacker gains unauthorized access to the target’s account and proceeds with the account takeover. Networks of infected devices controlled by attackers (botnets) can launch thousands of login attempts in seconds, making it easy to exploit unsecured or weakly secured accounts.
Attackers target many types of accounts, including:
If the attacker gains access to one of your accounts, they can exploit it for malicious purposes, like stealing personal details, making fraudulent purchases, or selling account details on the dark web. They may also lock you out or use the account to launch further attacks.
Credential stuffing is a highly effective tactic for hackers because it exploits the common habit of reusing login credentials across multiple platforms. When a username and password from one breach are exposed, cybercriminals can easily use them to gain unauthorized access to other accounts. And research consistently shows that this tactic is successful.
A recent survey commissioned by Forbes Advisor shows that 46% of Americans reported their password was stolen within the last year. Of those respondents, 30% believe it was due to recycling passwords across platforms.
What the experts say
"Password reuse is one of the fastest paths to identity theft. One breached account can unlock many more—especially email, which acts as a gateway to everything else."
Other attributes that contribute to credential stuffing's success include:
Since it's relatively easy for cybercriminals to access personal data online, credential stuffing attacks are a persistent threat. Here are a few recent, real-world examples that impacted large companies and their customers:
Credential stuffing attacks can be difficult to detect because they mimic legitimate login behavior, using real credentials just like you would when accessing your own account. However, there are a few warning signs that may indicate you're being targeted by such an attack.
Common signs of credential stuffing include:
If you suspect you’ve been targeted by a credential stuffing attack, start by reviewing your account details to confirm that only your own email address and information are associated with the account. Then, change your password, ensuring it’s strong and unique to that specific site, and enable 2FA for an added layer of security.
Here are some more tips for protecting your personal information if you think you’re a victim of credential stuffing:
The best way to reduce your vulnerability to credential stuffing attacks is to prevent your credentials from falling into the wrong hands to begin with. To safeguard your personal information and reduce your exposure, follow these key strategies:
Credential stuffing attacks are more common — and destructive — than most people realize. Knowing how they work is the first step in defending yourself.
For stronger protection, get LifeLock Total. It offers powerful tools to help monitor for signs of identity theft, including the suspicious use of your personal information. You’ll also receive alerts about large-scale data breaches that may involve your credentials, giving you the chance to act quickly and reduce the risk of account takeovers.
1 Identity Lock cannot prevent all account takeovers, unauthorized account openings, or stop all credit file inquiries. The credit lock on your TransUnion credit file and the Payday Loan Lock will be unlocked if your subscription is downgraded or canceled.
Editors’ note: Our articles provide educational information about identity theft, scams, financial fraud, and other topics that can put your identity or personal accounts at risk. LifeLock offerings may not cover or protect against every type of crime, fraud, scam, or threat we write about. For more details about how we write, review, and update our articles, see our Editorial Policy.