Skip to content

Credential Stuffing

What is Credential Stuffing?

An automated attack that uses stolen username-password pairs from previous data breaches to attempt to log into other services. Exploits the tendency of users to reuse passwords across multiple sites.

Information Security

Each of these is named in at least one of the same controls as credential stuffing. The number is how many controls name both.

What the standards actually require on credential stuffing

Requirements naming credential stuffing across 6 standards, quoted from the control text.

Secure e-commerce + mobile + in-store technology + IoT per NRF framework and OWASP + vendor-specific guidance. E-commerce security must (a) protect against OWASP Top 10 + API Top 10 vulnerabilities + skimming + form-jacking via subresource integrity + Content...

NRFCS-5 · E-Commerce, Mobile, Store Technology, and IoT Security

GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary;

GLI33-Geolocation-Mobile-Internet-Wagering · GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management

Operate log analysis per NIST SP 800-92 Chapter 5 (Operational Processes) + Section 5.12 (Performing Log Analysis). Correlation and detection rules per Section 5.12.1: implement correlation rules combining signals across sources (authentication + endpoint + ne...

NISTSP92-5 · Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review

Address API2:2023 Broken Authentication + token management per OWASP API Security Top 10 2023. Broken Authentication occurs when authentication mechanisms are weak + improperly implemented + or bypassable.

OWASPAPI-2 · Broken Authentication and Token Management
OWASP ASVS1 control

Per OWASP ASVS V2 + V2.4: implement strong authentication + credential storage. Requirements include (a) implement password strength requirements aligned with NIST SP 800-63B + reject compromised passwords against published breach lists + (b) implement secure...

OWASPASVS-2 · Authentication and Credential Storage (V2 + V2.4)

Address OWASP Top 10 A07 Identification and Authentication Failures per OWASP Top 10:2025. Identification and Authentication Failures arise from weak password + session management + credential storage + recovery + reuse attacks + credential stuffing + session...

OWASPTOP10-7 · A07:2025 Identification and Authentication Failures

Questions people ask about credential stuffing

What is Credential Stuffing?
An automated attack that uses stolen username-password pairs from previous data breaches to attempt to log into other services. Exploits the tendency of users to reuse passwords across multiple sites.
Why is Credential Stuffing important for compliance?
Credential Stuffing is a key concept in Information Security. Understanding credential stuffing helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Credential Stuffing?
Credential Stuffing appears in the requirement text of NRF Cybersecurity and Data Privacy Framework (National Retail Federation), GLI-33 - Gaming Laboratories International Event Wagering Systems, NIST SP 800-92, OWASP API Security Top 10 - 2023, OWASP ASVS. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Credential Stuffing?
Explore our compliance framework pages to see how credential stuffing applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Credential Stuffing applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.