Blog

Credential stuffing: why your login form is the real target

Attackers do not guess passwords anymore. They replay millions of leaked ones through rented networks. Here is how to spot the attempt before an account falls.

Most account takeovers do not start with a clever hack. They start with a spreadsheet. Someone buys a list of email-and-password pairs leaked from another company, and tries every pair against your login form to see which ones your users reused.

This is called credential stuffing, and it works because people reuse passwords. If even one in a thousand pairs works, an attacker running a million attempts walks away with a thousand live accounts.

What the attack looks like from your side

You will see a flood of login attempts, almost all of them failing, spread across thousands of different usernames rather than hammering one. The requests usually come from rented infrastructure: datacenter servers, proxy pools and VPN exits, because an attacker needs to rotate addresses to stay under your rate limits.

That last detail is the opening. Real people log in from home broadband and mobile networks. A burst of login traffic from datacenter and proxy networks is almost never your customers.

Screen the connection, not just the password

Password rules and rate limits help, but they treat every visitor the same. Checking the network behind each login attempt lets you treat a request from a rented proxy differently from one off a home connection, before you even look at the password.

  • Add friction to logins from proxy and datacenter networks: a second factor, an email code, or a CAPTCHA.
  • Rate-limit by network, not just by IP, so rotating through a proxy pool does not reset the counter.
  • Log the verdict on every login for a week and compare it to which accounts later got flagged for fraud. The overlap is usually stark.

Why this beats a blocklist

Static lists of bad IPs go stale within hours because attackers rent fresh addresses constantly. Looking at the type of network behind an address holds up, because the economics do not change: stuffing a million credentials from home connections is slow and expensive, so attackers keep using cheap, disposable infrastructure.

Fraudex returns a VPN, proxy and datacenter verdict for any IP in under a millisecond, so you can run it inline on your login route without slowing real users down. Start by logging the verdict, then decide what deserves a challenge.