All glossary terms
Glossary

Credential stuffing

Credential stuffing is an automated attack that tries large lists of stolen username and password pairs on a login page, betting that people reuse passwords across sites.

Attackers buy breached credentials in bulk and run them through bots, often spread across residential proxies so each IP sends only a few attempts. Success rates are low per attempt but meaningful at scale.

Defenses combine bot detection, rate limits per account and per device, and monitoring of failed-login patterns. Overly aggressive controls lock out real customers, so tuning matters.

Where Huskeys fits

Huskeys recommends login-specific rules and rate limits based on each application's real login traffic.

Related terms

Further reading