One Leaked Password, Six Broken Accounts: How Credential Stuffing Works
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Affiliate disclosure: This article contains affiliate links. If you click a link and buy a subscription, we may earn a commission at no cost to you. Our editorial recommendations are never influenced by commissions — read the full disclosure.
Almost nobody is targeted. The overwhelming majority of account takeovers are not the result of anyone deciding to attack you personally — they are the result of a password you set years ago, on a site you have forgotten, being tried automatically against every service that matters. The mechanism has a name, credential stuffing, and understanding it changes what you spend your security effort on. It also explains something people find counter-intuitive: why a VPN, which is genuinely useful for other things, does almost nothing about this one.
Why a Leak Somewhere Else Becomes Your Problem
When a company is breached, the immediate damage is usually confined — a forum loses its user table, a retailer loses order records. What escapes is a list of email addresses paired with passwords, and that list does not stay with the people who took it. It gets traded, merged with other lists, cleaned up and eventually circulated widely enough that it costs nothing to obtain. The breached company may notify you, reset your password on their service, and consider the matter closed, and from their perspective it is. The problem is that the pair that leaked was never really about them. If the password on that forum is also the password on your email, your bank or your cloud storage, then a forum with weak security has just published the key to accounts that had nothing to do with it. This is the single most important thing to understand about password security, and it is why advice focuses so heavily on uniqueness rather than complexity: a long, clever, memorable password that you have used in four places offers no protection at all once any one of those four is breached.
What Credential Stuffing Actually Is
Credential stuffing is the automated replay of leaked pairs against services that never leaked. Software takes a list of email-and-password combinations and tries them at scale against login pages — banks, retailers, streaming services, webmail, anything worth having. There is no cleverness in it and no exploit involved; every login attempt is a completely ordinary one that the service is designed to accept. That is exactly what makes it hard to stop from the defender side and cheap from the attacker side. The success rate per attempt is very low, often a fraction of a percent, and that does not matter in the slightest, because the cost per attempt is close to zero and the list has millions of rows. A tiny percentage of an enormous number is still a good day. It also means the attacker never needs to know or care who you are. You are a row.
Why the Defences People Reach For Do Not Help
Three instincts are common here and all three are misdirected. The first is complexity: adding symbols and numbers to a reused password does nothing, because the attacker is not guessing it, they already have it exactly as you typed it. The second is frequent changes. Requiring a new password every sixty or ninety days was standard advice for decades, and the current guidance from the United States National Institute of Standards and Technology now explicitly tells organisations not to do it — users respond to forced rotation by making minimal edits, appending a digit or bumping a number, which is trivially predictable and measurably worse than leaving a strong password alone. NIST's position is that passwords should change when there is evidence of compromise, not on a calendar. The third instinct is to rely on the service to notice. Some do, through rate limiting and anomaly detection, and their defences are worth having — but a login from a plausible device with the correct password is a hard thing to refuse without also refusing real customers.
The Account That Matters Most Is Your Email
If you are going to fix one account first, fix the mailbox, because it is not really an account — it is the recovery mechanism for every other account you own. Anyone who controls your email can request a password reset almost anywhere else and receive the link themselves, which converts a single compromise into a general one. That is why attackers prize webmail credentials disproportionately, and why a mailbox should carry a unique password and the strongest second factor you are willing to live with. The same logic applies, in descending order, to your phone-carrier account, your password manager, your cloud storage and any account tied to a payment method. Everything else can be re-secured from those. If those fall, the rest falls with them, and the order in which you spend your effort should follow that dependency rather than following how much you happen to use each service.
What Actually Stops It
The countermeasure is unglamorous and close to total. Give every account its own password, so that a breach at one service leaks exactly one credential and the replay finds nothing anywhere else. That is impossible to do from memory across the number of accounts a normal person now has, which is the entire practical argument for a password manager: not that it is more secure to type, but that it makes uniqueness achievable rather than aspirational. Add a second factor everywhere it is offered, so that a correct password on its own is not sufficient, and prefer an app-based code or a security key over SMS where you have the option. Better still, use a passkey where the service supports one, since there is no shared secret to leak in the first place. Finally, check your addresses against known breach corpuses — the same practice NIST asks organisations to perform against new passwords — and treat any hit as a prompt to change that password and anywhere you reused it. Our best password managers of 2026 compares the options on encryption and features, and the NordPass review is the detail on the one we rate first.
Why a VPN Does Not Help Here — and What It Is For
This is worth stating plainly on a VPN site. A VPN encrypts the connection between your device and a server you chose, which defeats an untrusted local network: the café, the hotel, the airport, the shared office. It does nothing whatsoever about credential stuffing, because nothing in that attack happens on your network. The leak occurred at a company you do not control, the replay happens from the attacker's infrastructure against the service's login page, and your own connection is not involved at any point. Selling a VPN as protection against account takeover would be a false claim, and we would rather say so than sell it. The two products solve different problems and you should buy them for different reasons: a VPN for the network you are on, a password manager for the accounts you own. If you want the honest version of what a VPN does and does not cover, do you really need a VPN and the VPN privacy guide are the two to read, and VPN vs antivirus is the same argument applied to a different neighbour.
Frequently Asked Questions
What is credential stuffing?
The automated replay of email-and-password pairs from an old breach against services that were never breached. Every attempt is an ordinary login, which is why it is cheap for the attacker and hard for the service to refuse without also refusing real customers.
Does a complicated password protect me from it?
No. Complexity helps against guessing, and credential stuffing does not guess — the attacker already has the password exactly as you typed it. Only uniqueness helps, because it confines a leak to the one service that leaked it.
Should I change my passwords every few months?
No. NIST guidance now tells organisations not to force periodic rotation, because users respond by making small predictable edits. Change a password when there is evidence of compromise, and otherwise leave a strong unique password alone.
Which account should I secure first?
Your email. It is the password-reset route for nearly everything else, so whoever controls it can take the rest. Then your phone-carrier account, your password manager, your cloud storage, and anything holding a payment method.
Will a VPN stop my accounts being taken over?
No, and no honest VPN review should claim otherwise. Nothing in a credential-stuffing attack touches your network — the leak happened at another company and the replay runs from the attacker's own infrastructure. A VPN protects the network you are on; a password manager protects the accounts you own.
Also worth comparing
Other providers we recommend for this topic. Sponsored links — we may earn a commission at no extra cost to you.
VPNTex is published by NorwegianSpark SA (Org no: 834 984 172). We may earn commissions on qualifying purchases via affiliate links. This does not affect our editorial independence. Full disclosure · Privacy policy