Sectona at Infosecurity Europe 2025 | June 3–5 | ExCeL London
Stop by our booth (Stand C 95) for live demo of Sectona’s Modern Infrastructure Access Platform
Passwords are widely used to secure accounts and systems. However, managing multiple passwords can be difficult for users. As a result, many people reuse passwords across different accounts or store them insecurely.
Poor password practices create opportunities for cybercriminals to exploit compromised credentials. One of the most common examples of this cyber-attack is credential stuffing.
To reduce these risks, organisations use password management practices to secure credentials throughout their lifecycle and improve overall security. To better understand why it matters, it is important to understand how credential stuffing attacks work and why they are so dangerous.
Credential stuffing is a cyberattack in which hackers use stolen usernames and passwords to access accounts on other websites. These login details are usually obtained from previous data breaches and tested across multiple platforms using automated tools.
This attack is highly effective because many people reuse the same password for several online accounts. Once hackers find a working username and password combination, they can access personal information, make unauthorised purchases, or steal money.
Let’s understand how the attack works.
Credential stuffing follows a simple process. First, cybercriminals collect leaked login credentials from compromised websites or online databases. They then use automated bots to test those credentials on various platforms, including email accounts, banking applications, shopping websites, and social media platforms.
If the password matches, attackers can gain access within seconds. This is why using a unique password for every account is critical.
Although credential stuffing is often confused with other password-based attacks, it works differently in several important ways.
Credential stuffing and brute force attacks are both account takeover methods, but they operate differently.
In a brute force attack, cybercriminals repeatedly guess passwords until they find the correct one. These guesses are usually based on common password patterns or randomly generated combinations. The attacker has no prior knowledge of the actual password and relies entirely on trial and error.
Credential stuffing, however, does not involve guessing passwords. Instead, attackers use real usernames and passwords that have already been exposed in previous data breaches. They simply test these stolen credentials across multiple websites to see where they still work.
Australian Superannuation Incident
In April 2025, several major Australian superannuation funds, including AustralianSuper, Rest, and HostPlus, were hit by a cyberattack. Over $500,000 in retirement savings was stolen.
The attackers did not use advanced hacking methods. They used credential stuffing instead.
Some stolen logins still worked. Attackers were able to access accounts quietly and move money without immediate detection.
The North Face, luxury jeweller Cartier, reported a credential stuffing attack in April 2025 that exposed personal customer data, including names, email addresses, shipping details, and purchase history, and confirmed that users were asked to reset their passwords. Cartier also disclosed a separate incident in which an unauthorised party gained temporary access to its systems, resulting in the exposure of limited client information.
Privileged Access Management (PAM) solutions help organisations reduce the impact of credential stuffing attacks. These tools secure privileged accounts, strengthen authentication, and reduce the risk of credential misuse.
Some of the most important PAM features include:
1. Secure Password Management for Privileged Accounts
PAM solutions help organisations enforce strong and unique passwords for privileged accounts. In addition, privileged credentials are securely stored in password vaults.
A password vault is a secure system that stores passwords in encrypted form. When users need access to a system or application, the vault automatically retrieves and securely provides the required credentials. This reduces the need for users to manually handle sensitive passwords.
Another key feature is automated password rotation. This process changes passwords at scheduled intervals, reducing the risk of stolen credentials remaining valid for long periods.
The frequency of password rotation usually depends on:
To improve security further, organisations often combine password rotation with multi-factor authentication (MFA) and password management tools.
While strong password management is important, passwords alone are no longer enough to protect privileged accounts. This is where MFA becomes essential.
2. Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) requires users to verify their identity using more than one authentication method before accessing sensitive systems or accounts.
In privileged access management, MFA is especially important because it protects high-level accounts such as:
These accounts have elevated permissions and can make critical changes to systems and data.
Instead of relying only on passwords, MFA adds additional layers of verification, including:
Even if a password is stolen, attackers would still need the additional authentication level.
3. Continuous Monitoring
Another feature is continuous monitoring. It helps organisations to keep a close watch on privileged access and user activity at all times. PAM solutions can track sessions in real time, send alerts when suspicious behaviour is detected, and automatically enforce security policies to prevent unauthorised access. Many platforms support secure RDP and SSH access controls, approval-based access requests, and detailed audit logs for compliance and investigations.
Some solutions even offer searchable session recordings, allowing security teams to quickly review user actions and respond faster to potential threats. With better visibility into login activity and account behaviour, PAM solutions can also help reduce the risk of credential stuffing attacks before they escalate.
While strong password management and MFA are essential, organisations also employ advanced security controls to defend against credential-stuffing attacks more effectively.
Some of the most common security measures include:
By combining these security measures with PAM solutions and MFA, organisations can build stronger protection against credential stuffing attacks and reduce the risk of account compromise.
Credential stuffing is one of the most common cyber threats in recent years. Although the attack looks relatively simple, it can cause serious damage when users reuse passwords across multiple platforms.
To reduce the risk, organisations and individuals must take proactive steps to secure their accounts and sensitive information.
Using strong and unique passwords, enabling MFA, monitoring data breaches, and implementing PAM solutions can significantly improve security and reduce the risk of account compromise.
Also read: Stop Ransomware Privilege Escalation without Breaking Productivity – Sectona