Credential Stuffing is a attack_type tracked across 50 threat clusters and 147 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity July 25, 2026.
Credential stuffing is an automated attack that uses large collections of stolen usernames and passwords to attempt unauthorized access across many online services. Its effectiveness stems from widespread password reuse and poor credential hygiene, making it a persistent risk to consumer, enterprise, and healthcare platforms; defenses emphasize MFA, monitoring, and limiting login attempts.
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
Russian state-aligned threat groups are increasingly exploiting Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), and supply chain vulnerabilities to gain initial access to networks across various sectors,…
In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously…
The 2026 Verizon Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has overtaken stolen credentials as the primary entry point for data breaches, accounting for 31% of incidents. This…
A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…
Over the past 24 months, France has experienced a significant increase in cyber threats, including 17,800 instances of data leaks, credential dumps, ransomware advisories, and hacktivist activities. Monthly dark-web…
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
Dutch police, in collaboration with the National Cyber Security Centre (NCSC), have dismantled a massive botnet comprising over 17 million infected devices. The operation involved seizing more than 200 servers located…
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…