This advisory provides information about credential stuffing as a method of attack, and gives advice on how to protect an organisation against it.
Introduction
Credential stuffing takes advantage of people reusing username and password combinations across different accounts. By fraudulently gaining valid combinations for one site, and successfully using them on other sites an attacker can access legitimate accounts. The primary motivation is financial, but it can lead to identity theft.