Credential Stuffing
CAPEC-600 · Standard · Stable
An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticated access. Credential Stuffing attacks rely upon the fact that many users leverage the same username/password combination for multiple systems, applications, and services.
likelihood: High
severity: High