Credential Stuffing
What is Credential Stuffing?
An automated attack that uses stolen username-password pairs from previous data breaches to attempt to log into other services. Exploits the tendency of users to reuse passwords across multiple sites.
Terms that appear alongside credential stuffing
Each of these is named in at least one of the same controls as credential stuffing. The number is how many controls name both.
- authentication 6 shared controls
- nist 5 shared controls
- account lockout 4 shared controls
- owasp 4 shared controls
- multi factor authentication 3 shared controls
- ransomware 3 shared controls
- pci dss 3 shared controls
- oauth 2 shared controls
Frameworks that govern credential stuffing
What the standards actually require on credential stuffing
Requirements naming credential stuffing across 6 standards, quoted from the control text.
Secure e-commerce + mobile + in-store technology + IoT per NRF framework and OWASP + vendor-specific guidance. E-commerce security must (a) protect against OWASP Top 10 + API Top 10 vulnerabilities + skimming + form-jacking via subresource integrity + Content...
NRFCS-5 · E-Commerce, Mobile, Store Technology, and IoT Security →GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary;
GLI33-Geolocation-Mobile-Internet-Wagering · GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management →Operate log analysis per NIST SP 800-92 Chapter 5 (Operational Processes) + Section 5.12 (Performing Log Analysis). Correlation and detection rules per Section 5.12.1: implement correlation rules combining signals across sources (authentication + endpoint + ne...
NISTSP92-5 · Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review →Address API2:2023 Broken Authentication + token management per OWASP API Security Top 10 2023. Broken Authentication occurs when authentication mechanisms are weak + improperly implemented + or bypassable.
OWASPAPI-2 · Broken Authentication and Token Management →Per OWASP ASVS V2 + V2.4: implement strong authentication + credential storage. Requirements include (a) implement password strength requirements aligned with NIST SP 800-63B + reject compromised passwords against published breach lists + (b) implement secure...
OWASPASVS-2 · Authentication and Credential Storage (V2 + V2.4) →Address OWASP Top 10 A07 Identification and Authentication Failures per OWASP Top 10:2025. Identification and Authentication Failures arise from weak password + session management + credential storage + recovery + reuse attacks + credential stuffing + session...
OWASPTOP10-7 · A07:2025 Identification and Authentication Failures →Questions people ask about credential stuffing
What is Credential Stuffing?
Why is Credential Stuffing important for compliance?
Which compliance frameworks address Credential Stuffing?
Where can I learn more about Credential Stuffing?
See how Credential Stuffing applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.