Primary Country (Mandatory)

Other Country (Optional)

Set News Language for United States

Primary Language (Mandatory)
Other Language[s] (Optional)
No other language available

Set News Language for World

Primary Language (Mandatory)
Other Language(s) (Optional)

Set News Source for United States

Primary Source (Mandatory)
Other Source[s] (Optional)

Set News Source for World

Primary Source (Mandatory)
Other Source(s) (Optional)
  • Countries
    • India
    • United States
    • Qatar
    • Germany
    • China
    • Canada
    • World
  • Categories
    • National
    • International
    • Business
    • Entertainment
    • Sports
    • Special
    • All Categories
  • Available Languages for United States
    • English
  • All Languages
    • English
    • Hindi
    • Arabic
    • German
    • Chinese
    • French
  • Sources
    • India
      • AajTak
      • NDTV India
      • The Hindu
      • India Today
      • Zee News
      • NDTV
      • BBC
      • The Wire
      • News18
      • News 24
      • The Quint
      • ABP News
      • Zee News
      • News 24
    • United States
      • CNN
      • Fox News
      • Al Jazeera
      • CBSN
      • NY Post
      • Voice of America
      • The New York Times
      • HuffPost
      • ABC News
      • Newsy
    • Qatar
      • Al Jazeera
      • Al Arab
      • The Peninsula
      • Gulf Times
      • Al Sharq
      • Qatar Tribune
      • Al Raya
      • Lusail
    • Germany
      • DW
      • ZDF
      • ProSieben
      • RTL
      • n-tv
      • Die Welt
      • Süddeutsche Zeitung
      • Frankfurter Rundschau
    • China
      • China Daily
      • BBC
      • The New York Times
      • Voice of America
      • Beijing Daily
      • The Epoch Times
      • Ta Kung Pao
      • Xinmin Evening News
    • Canada
      • CBC
      • Radio-Canada
      • CTV
      • TVA Nouvelles
      • Le Journal de Montréal
      • Global News
      • BNN Bloomberg
      • Métro
How hackers use leaked login ID and passwords to launch credential stuffing attacks | Explained

How hackers use leaked login ID and passwords to launch credential stuffing attacks | Explained

The Hindu
Monday, October 16, 2023 06:58:48 AM UTC

23andMe, a U.S. biotechnology firm, confirmed stolen customer data was being sold on the dark web. Data included full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location. Attackers used credential stuffing, a form of brute force attack, to gain access. Poor password hygiene is a main factor behind successful credential stuffing attacks.

In October 2023, 23andMe a U.S. biotechnology and genomic firm offering genetic testing services to customers confirmed that stolen data of its customers being sold by threat actors on the dark web was legitimate. The data included full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location. The company further shared that the data being sold was stolen using a credential-stuffing attack.

Credential stuffing is a form of brute force attack that involves trial and error on the hackers’ part to crack passwords, login credential, and encryption keys.

Brute force attacks are categorised under four categories, namely simple brute force attacks, dictionary attacks, hybrid brute force attacks, reverse brute force and credential stuffing.

Amongst these, credential stuffing preys on user’s weak password hygiene. Attackers collect stolen username and password combinations from data leaks. These are tested on other websites to check if they can be used to gain access to additional accounts. This form of attack method is successful when users use the same password combination or reuse passwords for various accounts and social media platforms.

Hackers may also use automated bots to repeatedly try to access a website with credentials purchased on the dark web. Making use of known (breached) usernames / passwords pairs of websites against other websites.

When attackers discover a set of credentials that work, they may also illegitimately try to access a company’s network using them or sell the validated credentials to other criminals who can use them to launch further attacks.

One of the main factors behind the successful launch of credential stuffing attacks is poor password hygiene. In credential stuffing, attackers target popular websites with high brand recognition where user credentials leaked from earlier data breaches are readily available on the dark web.

Read full story on The Hindu
Share this story on:-
More Related News
TVK challenges two provisions of T.N. government’s SOP for political rallies before Madras High Court

TVK challenges Tamil Nadu's SOP for political rallies in Madras High Court, alleging unconstitutional restrictions on political activities.

Congressmen know how to hit back, says Manickam Tagore

Congress MP Manickam Tagore demands action against DMK's Thalapathi, asserting Congress's strength ahead of upcoming elections in Madurai.

T.N. Assembly election 2026: AIADMK sharpens booth-level focus, rolls out data-driven campaign to recapture ‘missing votes’

AIADMK launches a data-driven campaign to regain missing votes, combining booth-level analysis with a cost-of-living outreach initiative.

Education not just means of getting degree or employment: Karnataka Governor Thawar Chand Gehlot

Karnataka Governor Thawar Chand Gehlot emphasizes role of education in fostering morality and social responsibility at convocation of Davangere University.

₹40 lakh released for 20 Kambalas in Dakshina Kannada, Udupi districts by government of Karnataka

Karnataka government allocates ₹40 lakh for 20 Kambalas in Dakshina Kannada and Udupi districts to support traditional events.

No opposition to Sunetra Pawar becoming NCP legislature party leader: Praful Patel

Praful Patel confirms no opposition to Sunetra Pawar's leadership in NCP, pending family consent for key appointments.

World Cancer Day | How psycho-oncology is changing cancer care by making room for the mind

On World Cancer Day, a cancer survivor examines how treating the mind alongside the tumour is finally becoming a critical pillar of oncology in India

Programme on ‘Gandhi, Music, and the Plurality of Civilisation’ held in Bengaluru

Bengaluru university hosts programme on Gandhi, music, and civilizational plurality, urging students to embrace Gandhian ideals and constitutional values.

Hyderabad’s Begumpet Airport gates opened for Wings India 2026 visitors; people look up to witness spectacle

Wings India 2026 captivates Hyderabad as families and aviation enthusiasts flock to Begumpet Airport for a festive aviation experience.

'Inhuman' to talk about Ajit Pawar's successor right now, says Sanjay Raut

Sanjay Raut criticizes discussions on NCP leadership post-Ajit Pawar's death, calling it "inhuman" and lacking compassion.

Triple murder case: After three-day search, police recover missing woman’s body from Perungudi dump yard

Police recover the body of a missing woman from a Chennai dump yard in a triple murder investigation involving her family.

World’s youngest woman jet commander, Nivedita Bhasin lights way for women in aviation

Nivedita Bhasin shares her pioneering journey as the youngest female jet commander and advocating for gender diversity.

Kudumbashree volunteers of Choornikara panchayat in Kerala deliver books at homes there to promote reading among women and children

Kudumbashree volunteers in Choornikara deliver library books to homes, fostering reading among women and children in the community.

Water level in Mullaperiyar dam stands at 123.95 feet

Water level in Mullaperiyar dam on Friday stood at 123.95 feet (the maximum permissible level is 142 ft.) with an inflow of 45 cusecs and a discharge of 933 cusecs.

GVMC Council meeting in Vizag witnesses ‘chaos’; media denied access

GVMC Council meeting in Vizag erupts in chaos as YSRCP and NDA clash over land regularisation, with media barred from entry.

Police to enforce strict rules to reduce accidents in Belagavi

Belagavi Police implement strict rules to curb road accidents during the sugarcane harvest season, ensuring public safety.

When the State enters the cradle: How China and India are engineering early childhood for economic growth Premium

Explore how China and India are transforming early childhood education to enhance cognitive development and secure economic futures.

Two arrested for sharing content derogating Sai Baba Temple

The Brahmavar police have arrested two persons on the charge of sharing content derogating Sai Baba Temple on social media

AKPL launches training on Miyawaki method of afforestation

AKPL launches Miyawaki afforestation training in Nellore to empower villagers in sustainable forest development and ecosystem preservation.

No items used for manufacture of drugs found during NCB search in Mysuru: Home Minister

NCB's search in Mysuru found no drugs, clarifies Home Minister G. Parameshwara amid concerns over local drug networks.

Devotee rush intensifies at Medaram after Sammakka’s arrival

Families spanning three generations were a common sight

Paddy on 300 acres wilting as no water released in Third, Fourth Reaches of Manimuthar Dam, farmers complain

Paddy on 300 acres wilting as no water released in Third, Fourth Reaches of Manimuthar Dam, farmers complain

Asian Waterbird Census 2026 records 60% jump in Kollam’s waterbird count

The Asian Waterbird Census 2026 reveals a 60% increase in Kollam's waterbird count, but also troubling ecological trends.

Dharmasthala case: Suresh Kumar asks govt. to make SIT report public

Senior BJP member and former Minister S. Suresh Kumar on Friday demanded that the report of the Special Investigation Team (SIT) that probed the alleged mass burial case at Dharmasthala be tabled in the Legislative Assembly.

Cafe murder case: Criminal held after shootout in northeast Delhi

A 23-year-old criminal, Mohammad Moin Qureshi, arrested after a shootout in Delhi, confessed to murdering a man in a cafe.

© 2008 - 2026 Webjosh  |  News Archive  |  Privacy Policy  |  Contact Us