---
title: What is a credential stuffing attack?
description: Credential stuffing attacks use stolen usernames and passwords to attempt to take over a user’s account by gaining access to accounts during a data breach.
---

[Managed IT and Security Provider - LaScala](https://blog.lascala.com)

# [What is a credential stuffing attack?](https://blog.lascala.com/credential-stuffing-attack)

 Written by [Angel Belford](https://blog.lascala.com/author/angel-belford) | May 8, 2024 4:57:08 PM

Did you know that there was over $500 million dollars of consumer loss for data breaches in 2023? (According to the 2023 IC3 annual report.)  

One way cybercriminals can gain access to accounts during a data breach is by using credential stuffing attacks. Credential stuffing or stealing attacks use stolen usernames and passwords to attempt to take over a user’s account. This process is repeated over and over while cybercriminals try to find a successful match in order to takeover an account.    

##### Process of a credential stuffing attack 

##### Red flags 

- Watch for any type of suspicious login activity 
- Notice any unusual account lockouts 
- Receive multiple authentication attempts to approve a device when you are not trying to access the account 

##### How to minimize risk 

- Never reuse the same password 
- Use multi-factor authentication 
- Use a password manager 

##### Potential business implications 

- Financial loss 
- Organization's reputation damage 

##### Credential Stuffing Attacks in the News 

[Chick-fil-A](https://www.bleepingcomputer.com/news/security/chick-fil-a-confirms-accounts-hacked-in-months-long-automated-attack/)  
[PetSmart](https://www.bleepingcomputer.com/news/security/petsmart-warns-of-credential-stuffing-attacks-trying-to-hack-accounts/)

 

##### Reporting Crimes 

Report all crimes to your local police department and to the following agencies:

- [Michigan Cyber Command Center (MC3)](https://www.michigan.gov/msp/divisions/intel-ops/cyber/mc3)
- [Internet Crime Complaint Center (IC3)](https://www.ic3.gov/)

##### How LaScala Can Help 

Contact us today at [sales@lascala.com](mailto:sales@lascala.com) and get started on proactive threat hunting, security awareness training, and more security protection.  

Sources 

1 - Internet Crime Complaint Center (IC3): [https://www.ic3.gov/](https://www.ic3.gov/)  
2 - Fortinet: [https://www.fortinet.com/resources/cyberglossary/credential-stuffing](https://www.fortinet.com/resources/cyberglossary/credential-stuffing)  
3 - Proofpoint: [https://www.proofpoint.com/us/threat-reference/credential-stuffing](https://www.proofpoint.com/us/threat-reference/credential-stuffing) 

 

Disclaimer  

Please respect all trademarks mentioned in this document as their respective owners. 

[View full post](https://blog.lascala.com/credential-stuffing-attack)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Angel Belford"
  },
  "dateModified" : "2024-05-08T16:57:08.481Z",
  "datePublished" : "2024-05-08T16:57:08Z",
  "headline" : "What is a credential stuffing attack?",
  "image" : {
    "@type" : "ImageObject",
    "height" : 600,
    "url" : "https://20371606.fs1.hubspotusercontent-na1.net/hubfs/20371606/Binary1200x600grey-ransomware-blog-post-hoodie.png",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://blog.lascala.com/credential-stuffing-attack",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Blog"
  }
}
```