Slide 10 of 28
Part 2 · How It WorksSlide 10
Slide 10 · Credential Stuffing
Your users reuse passwords. Attackers know this.
No guessing required. The credentials come from someone else's breach.
How It Works

Data breaches happen constantly. When a site is breached, the leaked username/password pairs are assembled into "combo lists." These lists are shared, sold, and merged. The biggest ones contain hundreds of millions of credentials.

An attacker downloads a combo list and writes a script that fires POST requests to your login API — one per credential pair. No password guessing. They're using real passwords that worked somewhere else.

Real Incident · 2020
Spotify — 380 Million Credential Pairs Tested

In 2020, a database containing 380 million username/password pairs assembled from third-party breaches was used to test Spotify accounts. Spotify's login API had no effective rate limiting for distributed attacks. Thousands of accounts were successfully taken over. Spotify was forced to reset passwords for affected users.

The credentials weren't stolen from Spotify — they were leaked from other sites. Users who reused passwords paid the price.

Lesson: Your API inherits the risk of every breach that ever happened to your users' passwords. Rate limiting and MFA are the only defenses that work at scale.
The scale problem

A 1-in-100 success rate sounds low. Against a list of 380 million credentials, that's 3.8 million taken accounts. Even a 1-in-1,000 rate means 380,000 compromised accounts from a single attack run.

← Back Brute force without lockout →