The Times Australia
The Times World News

.

What is credential stuffing and how can I protect myself? A cybersecurity researcher explains

  • Written by David Tuffley, Senior Lecturer in Applied Ethics & CyberSecurity, Griffith University
What is credential stuffing and how can I protect myself? A cybersecurity researcher explains

Cyber-skulduggery is becoming the bane of modern life. Australia’s prime minister has called it a “scourge[1]”, and he is correct. In 2022–23, nearly 94,000 cyber crimes were reported[2] in Australia, up 23% on the previous year.

In the latest high-profile attack[3], around 15,000 customers of alcohol retailer Dan Murphy, Mexican restaurant chain Guzman y Gomez, Event Cinemas, and home shopping network TVSN had their login credentials and credit card details used fraudulently to buy goods and services in what is known as a “credential stuffing[4]” attack.

So what is credential stuffing – and how can you reduce the risk of it happening to you?

A Dan Murphy's liquor store sign reflects golden sunlight.
Many customers of alcohol retailer Dan Murphy are among those hit by the latest round of credential stuffing cyber attacks. ArliftAtoz2205/Shutterstock[5]

Read more: An expert reviews the government’s 7-year plan to boost Australia’s cyber security. Here are the key takeaways[6]

Re-using the same login details

Credential stuffing is a type of cyber attack where hackers use stolen usernames and passwords to gain unauthorised access to other online accounts.

In other words, they steal a set of login details for one site, and try it on another site to see if it works there too.

This is possible because many people use the same username and password combination across multiple websites.

It is common for people to use the same password[7] for multiple accounts (even though this is very risky).

Some even use the same password for all their accounts. This means if one account is compromised, hackers can potentially access many (or all) their other accounts with the same credentials.

‘Brute force’ attacks

Hackers purchase job lots of login credentials (obtained from earlier data breaches[8]) on the “dark web[9]”.

They then use automated tools called “bots” to perform credential stuffing attacks. These tools can also be purchased on the dark web.

Bots are programs that perform tasks on the internet much faster and more efficiently than humans can.

In what is colourfully termed a “brute force” attack, hackers use bots to test millions of username and password combinations on different websites until they find a match. It’s easier and quicker than many people realise.

It is happening more often because the barrier to entry for would-be cybercriminals has never been lower. The dark web is readily accessible and the resources needed to launch attacks are available to anyone with cryptocurrency to spend and the will to cross over to the dark side.

How can you protect yourself from credential stuffing?

The best way is to never reuse passwords across multiple sites or apps. Always use a unique and strong password for each online account.

Choose a password or pass phrase that is at least 12 characters long, is complex, and hard to guess. It should include a mix of uppercase and lowercase letters, numbers, and symbols. Don’t use pet names, birthdays or anything else that can be found on social media.

You can use a password manager[10] to generate unique passwords for all your accounts and store them securely. These use strong encryption and are generally regarded as pretty safe.

Another way to protect yourself from credential stuffing is to enable two-factor authentication (2FA) for your online accounts.

Two-factor authentication is a security feature that requires you to enter a code or use a device in addition to your password when you log in.

This adds an extra layer of protection in case your password is stolen. You can use an app[11], a text message, or a hardware device[12] (such as a little “key” you plug into a computer) to receive your two-factor authentication code.

Monitor your online accounts regularly to look for any suspicious activity. You can also check if your email or password has been exposed in a data breach by using the website Have I Been Pwned[13].

You may be surprised by what you see. If you do discover your login details on there, use this as a timely warning to change your passwords as soon as possible.

Have your passwords and login details been exposed in a data breach? Tada Images/Shutterstock[14]

Read more: What is LockBit, the cybercrime gang hacking some of the world's largest organisations?[15]

Eternal vigilance

In today’s world of rising cyber crime, your best defence against credential stuffing and other forms of hacking is vigilance. Be proactive, not complacent about online security.

Use unique passwords and a password manager, enable two-factor authentication, monitor your accounts, and check breach notification sites (like Have I Been Pwned).

Remember, the recent attacks on Dan Murphy, Guzman y Gomez and others show how readily our online lives can be disrupted. Don’t let your credentials become another statistic. As you are reading this, the criminals are thinking up new ways to exploit our vulnerabilities.

By adopting good digital hygiene and effective security measures, we can take back control of our online identities.

Read more: An AI-driven influence operation is spreading pro-China propaganda across YouTube[16]

References

  1. ^ scourge (www.news.com.au)
  2. ^ reported (www.cyber.gov.au)
  3. ^ attack (www.cyberdaily.au)
  4. ^ credential stuffing (owasp.org)
  5. ^ ArliftAtoz2205/Shutterstock (www.shutterstock.com)
  6. ^ An expert reviews the government’s 7-year plan to boost Australia’s cyber security. Here are the key takeaways (theconversation.com)
  7. ^ same password (us.norton.com)
  8. ^ data breaches (www.oaic.gov.au)
  9. ^ dark web (en.wikipedia.org)
  10. ^ password manager (www.forbes.com)
  11. ^ app (au.pcmag.com)
  12. ^ hardware device (www.nytimes.com)
  13. ^ Have I Been Pwned (haveibeenpwned.com)
  14. ^ Tada Images/Shutterstock (www.shutterstock.com)
  15. ^ What is LockBit, the cybercrime gang hacking some of the world's largest organisations? (theconversation.com)
  16. ^ An AI-driven influence operation is spreading pro-China propaganda across YouTube (theconversation.com)

Read more https://theconversation.com/what-is-credential-stuffing-and-how-can-i-protect-myself-a-cybersecurity-researcher-explains-221401

Times Magazine

DIY Is In: How Aussie Parents Are Redefining Birthday Parties

When planning his daughter’s birthday, Rich opted for a DIY approach, inspired by her love for drawing maps and giving clues. Their weekend tradition of hiding treats at home sparked the idea, and with a pirate ship playground already chosen as t...

When Touchscreens Turn Temperamental: What to Do Before You Panic

When your touchscreen starts acting up, ignoring taps, registering phantom touches, or freezing entirely, it can feel like your entire setup is falling apart. Before you rush to replace the device, it’s worth taking a deep breath and exploring what c...

Why Social Media Marketing Matters for Businesses in Australia

Today social media is a big part of daily life. All over Australia people use Facebook, Instagram, TikTok , LinkedIn and Twitter to stay connected, share updates and find new ideas. For businesses this means a great chance to reach new customers and...

Building an AI-First Culture in Your Company

AI isn't just something to think about anymore - it's becoming part of how we live and work, whether we like it or not. At the office, it definitely helps us move faster. But here's the thing: just using tools like ChatGPT or plugging AI into your wo...

Data Management Isn't Just About Tech—Here’s Why It’s a Human Problem Too

Photo by Kevin Kuby Manuel O. Diaz Jr.We live in a world drowning in data. Every click, swipe, medical scan, and financial transaction generates information, so much that managing it all has become one of the biggest challenges of our digital age. Bu...

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Times Features

How artificial intelligence is reshaping the Australian business loan journey

The 2025 backdrop: money is moving differently If you run a small or medium-sized business in Australia, 2025 feels noticeably different. After two years of stubbornly high bo...

Top Features of Energy‑Efficient Air Conditioners for Australian Homes

In recent years, energy efficiency has become more than just a buzzword for Australian households—it’s a necessity. With energy prices rising and climate change driving hotter su...

Long COVID is more than fatigue. Our new study suggests its impact is similar to a stroke or Parkinson’s

When most people think of COVID now, they picture a short illness like a cold – a few days of fever, sore throat or cough before getting better. But for many, the story does...

What Makes Certain Rings or Earrings Timeless Versus Trendy?

Timeless rings and earrings are defined by designs that withstand the test of time, quality craftsmanship, and versatility. Trendy pieces, on the other hand, often stand testimony ...

Italian Street Kitchen: A Nation’s Favourite with Expansion News on Horizon

Successful chef brothers, Enrico and Giulio Marchese, weigh in on their day-to-day at Australian foodie favourite, Italian Street Kitchen - with plans for ‘ambitious expansion’ to ...

What to Expect During a Professional Termite Inspection

Keeping a home safe from termites isn't just about peace of mind—it’s a vital investment in the structure of your property. A professional termite inspection is your first line o...