All glossary terms
Glossary
Credential stuffing
Credential stuffing is an automated attack that tries large lists of stolen username and password pairs on a login page, betting that people reuse passwords across sites.
Attackers buy breached credentials in bulk and run them through bots, often spread across residential proxies so each IP sends only a few attempts. Success rates are low per attempt but meaningful at scale.
Defenses combine bot detection, rate limits per account and per device, and monitoring of failed-login patterns. Overly aggressive controls lock out real customers, so tuning matters.
Where Huskeys fits
Huskeys recommends login-specific rules and rate limits based on each application's real login traffic.
