Credential stuffing is an automated attack that uses large collections of stolen usernames and passwords to attempt unauthorized access across many online services.
Overview
Credential stuffing is an automated attack that uses large collections of stolen usernames and passwords to attempt unauthorized access across many online services. Its effectiveness stems from widespread password reuse and poor credential hygiene, making it a persistent risk to consumer, enterprise, and healthcare platforms; defenses emphasize MFA, monitoring, and limiting login attempts.
Related Threat Clusters
-
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
54 articles · Updated July 2, 2026 -
Russian Hackers Target Networks via RDP, VPNs, and Supply Chains
Russian state-aligned threat groups are increasingly exploiting Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), and supply chain vulnerabilities to gain initial access to networks across various sectors,…
3 articles · Updated May 22, 2026 -
Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts
In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…
9 articles · Updated April 1, 2026 -
FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously…
105 articles · Updated June 17, 2026 -
Massive Data Leak from SplitVPN Exposes Millions Despite 'No-Logs' Claims
A significant data breach involving SplitVPN has exposed approximately 58 million connection logs and millions of user records, contradicting the VPN's 'no logs' policy. The leaked database, distributed on the Altenen…
5 articles · Updated July 30, 2026 -
Exploitation of Ukrainian IP Cameras Using Custom Tooling by Russian Operator
A Russian-speaking operator has been identified using a custom Docker project named camview to exploit and stream IP cameras in Ukraine. The tool, built with FastAPI, wraps the open-source Ingram scanner and employs a…
2 articles · Updated August 10, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Vulnerability Exploitation Surpasses Credential Theft as Leading Cyber Breach Vector
The 2026 Verizon Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has overtaken stolen credentials as the primary entry point for data breaches, accounting for 31% of incidents. This…
33 articles · Updated May 20, 2026 -
Akira Ransomware Attack Exploits Disabled VPN Account
A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…
2 articles · Updated May 29, 2026 -
Surge in Cyber Threats Targeting France: Data Leaks and Ransomware Rise
Over the past 24 months, France has experienced a significant increase in cyber threats, including 17,800 instances of data leaks, credential dumps, ransomware advisories, and hacktivist activities. Monthly dark-web…
2 articles · Updated July 24, 2026
Recent Intelligence Reports
- Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak — Securityaffairs.Co · September 7, 2026
- Top tips for staying secure online | Turn on 2-step verification (2SV) | National Cyber Security Centre — www.ncsc.gov.uk · September 7, 2026
- WordPress Security Plugins: How to Choose the Right One — Blog.Sucuri · September 5, 2026
- Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks — Theregister · September 1, 2026
- AI Model Evaluator METR Hit by Credential Theft, Probing — Darkreading · September 1, 2026
- Attackers Steal METR API Key and Burn $600,000 in AI Credits — Infosecurity-Magazine · September 1, 2026
- 2026 08 31 Security Update — metr.org · September 1, 2026
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 — Thehackernews · September 1, 2026