Credential stuffing

You may have heard before that one of the best things you can do to stay safe online is to ensure that you use a unique password for every site. But why?

The answer is because criminals can get your password on a relatively insecure site, and then reuse that email/password combination on a different site that itself hasn't been breached.

Credential stuffing is when criminals take usernames and passwords stolen from one website and automatically try them on other websites.

How credential stuffing works

There are many things that companies can do to secure your password. (For example, they can salt, pepper, and hash them. No joke.) The problem is that many places might use one safeguard, but not all of them.

If a criminal gains access to a site that doesn't properly secure its passwords, then they may be able to recover your password, and then they know that apple.pie.baker@example.com likes to use the password 123AppleCinnamon.

Now that they have that combination, along with thousands of others, they can start going to other sites that haven't been compromised and try to log in. This could be a bigger website that you want to keep secure, like Google, Facebook, or even Chase or Vanguard. If those accounts have the same email and password, then the criminal just hacked you.

Imagine using the exact same key for your house, car, storage unit, bike lock, and safe. If someone managed to copy the key to your bike lock, they would now have access to your safe.

These attacks don't target just one person, either — criminals can obtain millions of stolen usernames and passwords, then use automated tools to try them against many other websites. Even if only a small percentage work, that can still mean thousands of compromised accounts.

How to check if you are vulnerable

Ask yourself: if you had to create a new password right now, what would it be? Would you generate a random password or come up with a unique passphrase (these are good options), or would you take your old standby Judy1952 and make it Judy1952! or Judy1952@?

If you have ever used the same password on two websites, you are vulnerable. If you have ever used variations of the same password, those passwords are vulnerable as well.

Please don't use the same password, or the same base password.

Do this today

Type your email address into Have I Been Pwned. It will tell you which known data breaches included your address and what other kinds of information were exposed. It's free, it doesn't want an account, and it doesn't email you unless you ask it to.

Don't be surprised if your address appears in several breaches. That's common, and it isn't cause for panic. Start with any account where you realize that you use that same password elsewhere.

How to protect yourself