Credential stuffing
An automated attack that replays username and password pairs leaked in one breach against other services, succeeding wherever a user has reused the same password.
Credential stuffing takes pairs of usernames and passwords exposed in an earlier breach and submits them, usually with automated tools, to the login pages of unrelated services. Each attempt uses a credential that was valid somewhere, and it succeeds on any account whose owner reused that password. Because the attacker needs only one or a few attempts per account, per-account lockout thresholds are seldom reached.
It is easily confused with its neighbours. Password spraying tries a few common passwords against many accounts, and a dictionary attack works through a list of likely passwords. Credential stuffing is defined by its input: real credentials from someone else’s breach. Controls that help include multi-factor authentication, which makes a correct password insufficient on its own; screening new passwords against a blocklist, which NIST SP 800-63B-4 section 3.1.1.2 says may include passwords from previous breach corpuses; and rate limiting. Passwordless authentication removes the reusable password where it replaces it rather than sitting beside it.
Exam relevance: a scenario is likely to describe a wave of successful logins after a breach at a different company, or many accounts each tried once. Candidates are expected to name credential stuffing, to trace it to password reuse, and to prefer MFA over account lockout, which is poorly matched to one attempt per account.