Cybersecurity alert: credential stuffing

04/06/2021 Terry Inskip 5 min read

Why reusing login credentials on a variety of webpages is a very bad idea.

kyle-glenn-MbPDSi0ILMo-unsplash.jpg

What is credential stuffing?

Even if it was only because the title piqued your interest, we’re happy you’re here because we want to warn about the latest in personal cybersecurity attacks; it comes from you reusing login credentials. It’s such an important topic that we believe it’s worth its own article.

We all did it, especially on our early days of creating online accounts. We all made that password (or even more than one!) that combines:

  • The name of a pet, a friend or a relative;
  • Two or three super easy digits –something like a year, or even easier yet, 001, 100 or even the all-time favorite 123; plus
  • One of those symbols that online systems always want us to use, like ¡”#%&()/?
And we were so proud of ourselves when the system told us it was a strong password. Truth be told, in their days those passwords were indeed very safe; that’s likely why we felt we could use them easily on a variety of webpages.

A variety of webpages

We all have one or more of these passwords that we have been using for years now on various webpages. When we forget the login credentials on a page we seldom visit, we always try these passwords first, before we have to click that “forgot password” button. Because it’s easy and it works often, right?

The root of the problem

Credential stuffing comes precisely from that bad habit of hours, one that over 80% of web users have* had at some point. Reusing login credentials on a variety of webpages is a mistake that cybercriminals are cashing in on right now.

Unravelling a person’s identity

Let’s imagine Anthony, who has password “Max123?” because Max is his dog’s name. Anthony has used that password for the following:
  • In 2016 he created a profile on his favorite online newspaper so he could get a few free articles a month.
  • In 2017, because everyone at work was doing it, he created a LinkedIn account; he forgot about that because he had a great job.
  • He signed up on a forum for model airplane builders in 2018.
  • In 2020, he created an account at his alma mater to request transcripts and a copy of his diploma.

Pandora’s Box

A hacker breaks in to the model airplane aficionado’s forum and steals everyone’s credentials. He uses specialized software to test their credentials on a bunch of other webpages; this is what is commonly referred to as credential stuffing. As it’s an automated tracking system, the hacker can afford to check thousands upon thousands of websites. This is what he obtains using Anthony’s login credentials:
  • His full name and date of birth (he gets that from the newspaper site).
  • His previous address, phone number and works history from LinkedIn, as well as his photo.
  • Anthony’s current address, tax ID number and full information on his college history.
  • Full information on two bank cards: Anthony’s debit card that he’s had since 2020 and that he uses to pay a quarterly subscription at the newspaper these days; and his credit card, which he used to pay for his transcripts and diploma.
  • Several answers to Anthony’s standard security questions on the various web portals the hacker was able to access.
The hacker puts up all the login credentials plus the personal information of not just Anthony’s, but everyone else’s too, for sale on the dark web for about $10 per person. Within a month Anthony has unauthorized purchases on his credit card and checking account. When going to set a fraud alert on his credit report, he finds a couple of loans in his name that are not his, as he is also the victim of identity theft.

Statistics

This is happening worldwide every day. An in-depth report from F5, a global enterprise dedicated to application delivery networking and app security** indicates:
  • The number of successful cyberattacks with credentials theft has doubled between 2016 and 2020.
  • Both companies and organizations are failing to detect these intrusions, taking on average 327 days to detect them.
  • In 2017 credential theft affected 17 million individuals.

An important lesson

As you can see, the use of strong, exclusive passwords is the key to protecting yourself from identity theft and fraud in general. We urge you to take action now:
  1. Examine all the passwords that you know you use on several webpages, and visit those pages to change each one to a unique, strong password.
  2. Use your browser’s built-in password manager to assist you: Safari, Chrome and Firefox all have integrated password managers. Another option is to use the one that comes built-in with your Antivirus software.
 

* Study by SecureAuth in 2017: https://www.secureauth.com/resource/infographic-poor-password-habits/

** 2021 Credential Stuffing Report: https://www.f5.com/labs/articles/threat-intelligence/2021-credential-stuffing-report

Share this page
Sign Up for Updates & Insights

Would you like to know when we have a new insight or resource posted for you?

View More
What they're up to - Impersonating OAS FCU on social media!

02/21/2025 Terry Inskip

We publish this extra issue of the blog as a security warning to our members and any consumers that may find themselves affected.

About the SSN data breach

08/30/2024 Terry Inskip

A massive data breach has compromised the information of millions of people in the US and abroad.

Elder financial abuse, part II

12/11/2023 Terry Inskip

This second post on the topic of senior financial abuse is directed at you, our elders.

Elder financial abuse, part I

12/01/2023 Terry Inskip

When elder financial abuse comes from those who are closest to their victim.

Tax Identity Theft – 9 tips to help you avoid it

01/30/2023 Terry Inskip

Because tax identity theft starts the same day as tax season.

6 steps to prevent child identity theft

10/21/2022 Terry Inskip

For National Cybersecurity Awareness Month, we want to bring your attention to the risk of child identity theft, something that often goes unnoticed because of their age and lack of credit use.

Is a Home Equity Investment worth it?

11/19/2025 Terry Inskip

Home Equity Investment vs. HELOC: What you need to know before you tap your home's value.

How does OAS FCU insure your deposits?

09/26/2025 Terry Inskip

If you have ever wondered whether all your savings are protected by deposit insurance at the Credit Union, you're not alone.

How to send money with Zelle® safely

03/14/2025 Terry Inskip

Zelle® is a fast, safe and easy way to send and receive money with people you trust, like your babysitter, coworkers, fellow PTA mom, or your son's soccer coach. Whether you just enrolled with Zelle® or have been an active user for a while, there are a few tips you should always keep in mind to ensure you are being safe when sending money.

Personalized Playlist

03/22/2026

Get your personalized playlist.

Call Us
202-458-3834
Message Us
Email Us
Virtual Appointment
Book Now
Support & Help Page
View All Contact Information
Call Us Message Us Virtual Appointment