All posts
May 2022·5 min read

Credential stuffing: the attack your password policy alone can't stop

Credential stuffing is different from brute force. It doesn't guess passwords — it uses leaked username and password combinations from breaches of other services. If your users reuse passwords, their WordPress login is only as secure as the weakest site they've ever registered on.

What credential stuffing is

Credential stuffing is an attack method that uses username and password combinations leaked from breaches of other services — email providers, e-commerce sites, social networks, any service that's been compromised and had its user database exposed. These credentials are available in bulk on criminal marketplaces and in public data dumps.

The attack is simple: automate login attempts on WordPress sites using those leaked credentials. If a user registered on your WordPress site with the same email and password they use on a service that's been breached, the attacker has valid credentials without ever needing to guess anything.

Why it's different from brute force

Classic brute force attacks try many passwords against one account or one password against many accounts. Rate limiting and account lockouts are effective countermeasures because the attack requires many attempts per target.

Credential stuffing uses already-valid passwords. The attacker isn't guessing — they're checking. The number of attempts per credential pair is typically one or very few. Per-account lockouts don't help when the correct password is used on the first attempt. It also often runs with low request rates spread across many IPs to avoid triggering rate limits.

The scale of the problem

The breach data available to attackers is vast. Have I Been Pwned, the credential breach aggregation service run by Troy Hunt, had indexed over 11 billion compromised accounts by 2022. These are real email/password combinations that were in use on real services.

Password reuse is extremely common despite years of advice against it. People use the same password across multiple services because managing unique passwords for every service they use is genuinely difficult without a password manager. Attackers rely on this behaviour.

What actually helps

Unique passwords on every site

The only way to prevent credential stuffing from succeeding with your credentials is to use a unique password on every service. A breach of one service then has no value against any other. A password manager makes this practical — you only need to remember one master password, and the manager generates and stores unique passwords for everything else.

Two-factor authentication

Even if an attacker has a valid username and password, 2FA requires a second factor they don't have. This is the most reliable defence against credential stuffing specifically — correct credentials are insufficient to complete the login.

Protecting the login endpoint

Blocking wp-login.php from public internet access entirely — requiring authentication via a portal before WordPress's login form is accessible — means that even valid credentials can't be submitted directly. The login form simply isn't reachable by automated tools.

Advising your users

If your WordPress site has user accounts — WooCommerce customers, members, subscribers — your security posture depends partly on their behaviour. Adding a note to your registration flow encouraging unique passwords and pointing to Have I Been Pwned for credential checking is a low-effort step that can make a meaningful difference.


At DownUnder WP, wp-admin access is protected at the portal level by default — the WordPress login form isn't directly accessible to the internet, making credential stuffing attacks against site administrators structurally impossible without a valid portal session.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.