Americans hit by 87 million credential-stuffing attacks daily: How to stop it

credential stuffing
(Image credit: Shutterstock)

Hackers are conducting credential stuffing attacks on Americans over 87 million times every day, according to a blog post by a U.S-based VPN provider.

Atlas VPN distilled data from publicly available studies summarizing research by security firms Akamai and F5. The two security firms found that credential-stuffing attacks are quickly growing in the U.S., with 3.6 million taking place every hour. 

Atlas VPN says that credential stuffing is the rise due to the high number of data breaches in the past few years.

Credential stuffing -- which represents 44% of all financial-services attacks -- are when cybercriminals systematically try to gain access to personal or company accounts by using credentials stolen in past data breaches involving other accounts. 

Credential stuffing works for one simple reason: because people reuse passwords. If you use strong, unique passwords for each and every online account, and keep track of them with one of the best password managers or other method, then credential stuffing will not be a problem for you.

Victims of successful credential-stuffing attacks can not only experience financial loss, but if the hacker gets hold of personal information, they can also fall victim to identity theft

Between December 1, 2017 and November 30, 2018, Akamai observed nearly 64 billion attempted credential-stuffing attacks in the U.S. Presumably, most of them were not successful, but many were.

Countries such as India, China, Canada, the U.K., Brazil, the United Arab Emirates, Australia, Italy and Switzerland accounted for only 16.9 billion credit-stuffing attacks combined in that period, according to the Akamai report.

That's just 26.4% of the total number in the U.S., a discrepancy that Atlas VPN attributed to a higher number of leaked records in the U.S.

  • Read more: Americans, keep your data safe with the best US VPN

Two-factor authentication could be the answer

Rachel Welch, COO of Atlas VPN, said: “Individuals that wish to protect themselves from credential-stuffing attacks should set up two-factor authentication [2FA] whenever possible."

“When hackers discuss credential stuffing attacks on the dark web, they often complain that two-factor authentication is the biggest roadblock to a successful cyber-attack.“

That's true, and we recommend turning on 2FA whenever possible as it helps protect your accounts from several different kinds of attacks. But not reusing passwords is even simpler, and will stop credential stuffing dead in its tracks.

Atlas VPN also looked at a report by security firm Recorded Future and an article on the Help Net Security website. 

Those sources included findings that online criminals often need automated credential checkers (costing $150) and network proxies ($250 per week) to help carry out these attacks, and that cyber criminals are selling hacked eBay, Amazon and PayPal accounts on the dark web for as little as $3.50, $2 and $1 respectively.

  • Read more: Stay protected for less with the best cheap VPN
TOPICS

Nicholas Fearn is a freelance technology journalist and copywriter from the Welsh valleys. His work has appeared in publications such as the FT, the Independent, the Daily Telegraph, The Next Web, T3, Android Central, Computer Weekly, and many others. He also happens to be a diehard Mariah Carey fan!

Read more
Surfshark graphic of 2024 data breaches
Nearly 700 million American records were leaked in 2024
Red computer security warning
2.8 million IP addresses being used in brute force attack on VPNs
An open lock depicting a data breach
The top 10 data breaches of 2024
VPN on phone in front of US flag
43% of Americans use VPNs – should you?
Cartoon of person peering through US flag
Western governments want your data and big tech is happy to provide – how to slow them down
Graphic of fibre optic cables attacking code
An estimated 46,000 VPN servers are vulnerable to being hijacked
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones