- Home
- Financial Education
Cybersecurity alert: credential stuffing
04/06/2021 Terry Inskip 5 min read
Why reusing login credentials on a variety of webpages is a very bad idea.
What is credential stuffing?
Even if it was only because the title piqued your interest, we’re happy you’re here because we want to warn about the latest in personal cybersecurity attacks; it comes from you reusing login credentials. It’s such an important topic that we believe it’s worth its own article.We all did it, especially on our early days of creating online accounts. We all made that password (or even more than one!) that combines:
- The name of a pet, a friend or a relative;
- Two or three super easy digits –something like a year, or even easier yet, 001, 100 or even the all-time favorite 123; plus
- One of those symbols that online systems always want us to use, like ¡”#%&()/?
A variety of webpages
We all have one or more of these passwords that we have been using for years now on various webpages. When we forget the login credentials on a page we seldom visit, we always try these passwords first, before we have to click that “forgot password” button. Because it’s easy and it works often, right?The root of the problem
Credential stuffing comes precisely from that bad habit of hours, one that over 80% of web users have* had at some point. Reusing login credentials on a variety of webpages is a mistake that cybercriminals are cashing in on right now.Unravelling a person’s identity
Let’s imagine Anthony, who has password “Max123?” because Max is his dog’s name. Anthony has used that password for the following:- In 2016 he created a profile on his favorite online newspaper so he could get a few free articles a month.
- In 2017, because everyone at work was doing it, he created a LinkedIn account; he forgot about that because he had a great job.
- He signed up on a forum for model airplane builders in 2018.
- In 2020, he created an account at his alma mater to request transcripts and a copy of his diploma.
Pandora’s Box
A hacker breaks in to the model airplane aficionado’s forum and steals everyone’s credentials. He uses specialized software to test their credentials on a bunch of other webpages; this is what is commonly referred to as credential stuffing. As it’s an automated tracking system, the hacker can afford to check thousands upon thousands of websites. This is what he obtains using Anthony’s login credentials:- His full name and date of birth (he gets that from the newspaper site).
- His previous address, phone number and works history from LinkedIn, as well as his photo.
- Anthony’s current address, tax ID number and full information on his college history.
- Full information on two bank cards: Anthony’s debit card that he’s had since 2020 and that he uses to pay a quarterly subscription at the newspaper these days; and his credit card, which he used to pay for his transcripts and diploma.
- Several answers to Anthony’s standard security questions on the various web portals the hacker was able to access.
Statistics
This is happening worldwide every day. An in-depth report from F5, a global enterprise dedicated to application delivery networking and app security** indicates:- The number of successful cyberattacks with credentials theft has doubled between 2016 and 2020.
- Both companies and organizations are failing to detect these intrusions, taking on average 327 days to detect them.
- In 2017 credential theft affected 17 million individuals.
An important lesson
As you can see, the use of strong, exclusive passwords is the key to protecting yourself from identity theft and fraud in general. We urge you to take action now:- Examine all the passwords that you know you use on several webpages, and visit those pages to change each one to a unique, strong password.
- Use your browser’s built-in password manager to assist you: Safari, Chrome and Firefox all have integrated password managers. Another option is to use the one that comes built-in with your Antivirus software.
* Study by SecureAuth in 2017: https://www.secureauth.com/resource/infographic-poor-password-habits/
** 2021 Credential Stuffing Report: https://www.f5.com/labs/articles/threat-intelligence/2021-credential-stuffing-report
What they're up to - Impersonating OAS FCU on social media!
02/21/2025 Terry Inskip
We publish this extra issue of the blog as a security warning to our members and any consumers that may find themselves affected.
About the SSN data breach
08/30/2024 Terry Inskip
A massive data breach has compromised the information of millions of people in the US and abroad.
Elder financial abuse, part II
12/11/2023 Terry Inskip
This second post on the topic of senior financial abuse is directed at you, our elders.
Elder financial abuse, part I
12/01/2023 Terry Inskip
When elder financial abuse comes from those who are closest to their victim.
Tax Identity Theft – 9 tips to help you avoid it
01/30/2023 Terry Inskip
Because tax identity theft starts the same day as tax season.
6 steps to prevent child identity theft
10/21/2022 Terry Inskip
For National Cybersecurity Awareness Month, we want to bring your attention to the risk of child identity theft, something that often goes unnoticed because of their age and lack of credit use.
Is a Home Equity Investment worth it?
11/19/2025 Terry Inskip
Home Equity Investment vs. HELOC: What you need to know before you tap your home's value.
How does OAS FCU insure your deposits?
09/26/2025 Terry Inskip
If you have ever wondered whether all your savings are protected by deposit insurance at the Credit Union, you're not alone.
How to send money with Zelle® safely
03/14/2025 Terry Inskip
Zelle® is a fast, safe and easy way to send and receive money with people you trust, like your babysitter, coworkers, fellow PTA mom, or your son's soccer coach. Whether you just enrolled with Zelle® or have been an active user for a while, there are a few tips you should always keep in mind to ensure you are being safe when sending money.
Sign Up for Updates & Insights
Be the first to know when we have a new insight or resource posted!
Article Title