Automated attack that bulk-tests credential pairs from prior data breaches to take over new accounts.
Credential stuffing exploits password reuse: most users apply the same credentials across multiple services. The attacker purchases or downloads from underground forums lists of login/password pairs from past breaches, then automates log-in attempts against high-value targets such as banks, e-commerce platforms or online insurers. The success rate is low, often below one percent, but one million attempts still yields thousands of compromised accounts. Standard defenses are CAPTCHAs, rate limiting and multi-factor authentication. For insurers, credential stuffing is a frequent cause of fraud on customer portals and of exposure to data breach notification requirements, making it a standard criterion in cyber underwriting questionnaires. It differs from brute force, which generates random passwords, and from phishing, which targets a specific individual: it relies solely on already-compromised data.
A life insurer discovers in an audit that thousands of logins to its customer portal originate from South American bots. Credential stuffing granted access to 340 accounts, some of which suffered changes to banking details. GDPR notification is triggered and the cyber policy renewal premium rises by 15%.
bourrage d'identifiants, credential stuffing, attaque par liste de mots de passe volés