Skip to content
POPCyber

POPCyber

Cybersecurity for all

  • Helpful links
  • Sextortion – Were you aware of it?
  • ‘ishing
  • About
  • Privacy Policy
  • OSINT – Tools of the trade
    • Judy Records
  • Toggle search form

Credential Stuffing

Posted on January 30, 2024September 16, 2024 By Griz 62No Comments on Credential Stuffinghttps%3A%2F%2Fpopcyber.net%2F2024%2F01%2F30%2Fcredential-stuffing%2FCredential+Stuffing2024-01-31+03%3A19%3A08Grizhttps%3A%2F%2Fpopcyber.net%2F%3Fp%3D62

I know that you must get quite tired of hearing about your password. We tell you to keep it strong, use multi-factor authentication, blah blah blah…

We often hear the same kinds of responses back, but it is just my email… I have nothing of interest in there. Yes, we know… and we sympathize. In the end we are just trying to help you. I have had other posts about the significance of strong passwords, I have talked about password lockers/services.

Lets talk about a different direction. Credential stuffing. Now, I am going to admit that the phrase was one that I had seen, but never looked into. As you can imagine, in my role, I encounter a ton of new terms and phrases and often do not have to time to keep up on them all. I will try to do a better job of selecting one and sharing it with you so that you can get nuggets of skills along the way with me.

When we have talked about passwords in the past, I have mentioned that when companies have their networks get breached and data is stolen, sometimes that data is our personal data, but sometimes it is our username and passwords.

Since we on the whole (myself included but I am getting it fixed) are horrible for password reuse, this makes credential stuffing a danger.

So Mr. Blackhat gets their hands on a data dump, they then build a spreadsheet with your email address(es) and the password(s) that you have been known to use. Since the majority of the United States banks at one of a few national banks, they start testing to see if they can log in. if they can… great!

Fortunately banks are getting smarter and are pushing us all to more secure login methods. If you bank is behind the times, AND you use one password all over the internet, you may well become a victim.

I wish I could tell you how many times I have seen “my [social media account] got hacked”. They were probably not hacked at all. they likely either fell for a credential harvester scan, or… were reusing their social media account password on other services that were compromised.

This brings us back to the common pleas of the cybersecurity professionals. Please, PLEASE, use strong and unique passwords and when you are able to, enable multi-factor logins. Yes, it is that important, unless you feel that donating your funds to who knows what country is a suitable form of charity work, one that you cannot even deduct form your taxes.

Uncategorized Tags:Credential, Password, Password Reuse, Reuse, Stuffing

Post navigation

Previous Post: Why is it dangerous to click on a random QR code?
Next Post: The Human Firewall: Your First Line of Defense

Related Posts

Are your smart devices listening to you? Uncategorized
OSINT and leveraging the internet to your favor Uncategorized
Why is it dangerous to click on a random QR code? Uncategorized
What is Phishing? Uncategorized
Please stand by Uncategorized
Just how much data do you volunteer in social media? Uncategorized

Leave a Reply Cancel reply

You must be logged in to post a comment.

Recent Posts

  • Telegram scammers
  • Site focus
  • Ransomware
  • Do you like to write on technical subjects?
  • It is coming together

Recent Comments

  1. Griz on Time to do some shakedown testing

Archives

  • March 2026
  • January 2025
  • September 2024
  • April 2024
  • March 2024
  • January 2024
  • June 2023
  • April 2023
  • April 2022
  • March 2022
  • April 2021
  • March 2021
  • July 2020
  • April 202

Categories

  • Consumer
  • General
  • Uncategorized
<script async src="https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-9333262976044598"
     crossorigin="anonymous"></script>

Copyright © 2026 POPCyber.

Powered by PressBook Masonry Dark