🔐 Credential Stuffing Statistics 2026: 52 Data-Backed Facts
These credential stuffing statistics are drawn from primary sources published in 2024, 2025 and 2026: Akamai's State of the Internet research, Cloudflare's network telemetry, the Verizon Data Breach Investigations Report, Have I Been Pwned, the FBI Internet Crime Complaint Center (IC3), the LastPass Psychology of Passwords study, NordPass, Okta, the FIDO Alliance and NIST. Every figure is attributed inline so journalists, researchers and AI assistants can cite the original.
What is credential stuffing? It is an attack in which criminals take username-and-password pairs leaked in one breach and use bots to try them, at massive scale, against logins on unrelated websites. Because so many people reuse passwords, a small fraction of those attempts succeed. The numbers below answer four questions: how big the attack volume is, how many logins are already compromised, why reuse keeps it alive, and what stops it.
Key Statistics at a Glance
The Scale of Credential Stuffing
Credential stuffing is industrial. Bots replay stolen logins around the clock, and the volume is measured in billions. The figures below come from Akamai and Cloudflare, two of the largest content-delivery and security networks on the internet.
- Akamai has measured credential-stuffing traffic at roughly 26 billion login attempts per month across its network. (Akamai, 2024)
- In a single earlier year, Akamai recorded 193 billion credential-stuffing attempts against the sites it protects. (Akamai, State of the Internet)
- Cloudflare detects on the order of billions of suspicious login attempts every day across the roughly 20% of the web behind its network. (Cloudflare, 2024)
- 95% of login attempts that use a leaked password are made by bots, not humans — the signature of automated credential stuffing. (Cloudflare, 2025)
- During large attack surges, automated traffic can make up more than 60% of all login-page requests. (Cloudflare, 2024)
- Only an estimated 0.1% to 2% of credential-stuffing attempts succeed — but at billions of attempts, even a fraction yields millions of hijacked accounts. (Industry analysis, 2024)
How Many Logins Already Use Leaked Passwords
In March 2025 Cloudflare published an analysis of authentication traffic across roughly 30 million websites — about a fifth of the internet — observed between September and November 2024. The findings show how deeply leaked credentials have penetrated everyday logins.
- 41% of all successful logins involved a password that had already been leaked in a known breach. (Cloudflare, 2025)
- When automated attempts are included, 52% of all authentication requests used a leaked credential — more than one in two. (Cloudflare, 2025)
- On popular content-management systems such as WordPress, 76% of login attempts using a leaked password succeeded. (Cloudflare, 2025)
- The average user was found to reuse a password across at least four different accounts, spreading the risk from any one breach. (Cloudflare, 2025)
The Supply of Stolen Credentials
Every credential-stuffing attack is fed by leaked data. In late 2025 threat-intelligence firm Synthient handed one of the largest credential datasets ever assembled to Have I Been Pwned.
- Have I Been Pwned indexed 1,957,476,021 unique email addresses (about 2 billion) from aggregated credential-stuffing data on 5 November 2025. (Have I Been Pwned / Synthient, 2025)
- The same dataset contained 1.3 billion unique passwords. (Have I Been Pwned, 2025)
- Of those, 625 million passwords had never been seen before in the Pwned Passwords service — and many were still in active use. (Have I Been Pwned, 2025)
- Infostealer malware alone harvested an estimated 1.8 billion credentials in the first half of 2025, continuously refilling the pool attackers draw from. (Threat-intelligence estimate, 2025)
- Among devices infected by infostealers, a median of only 49% of a user's saved passwords were distinct from one another — direct evidence of mass reuse. (Verizon DBIR, 2025)
Password Reuse: The Fuel
Credential stuffing only works because people reuse passwords. If every account had a unique password, a leak from one site could not unlock another. These findings come from the LastPass Psychology of Passwords study and the UK Information Commissioner's Office.
- 91% of people know that reusing passwords is insecure — yet do it anyway. (LastPass, Psychology of Passwords)
- Nearly two-thirds of people reuse the same password or a variation across accounts. (LastPass)
- 59% use the same or a similar password for multiple accounts. (LastPass)
- An estimated 65% of people reuse passwords across some or all of their accounts. (UK ICO)
- 60% say fear of forgetting is their number-one reason for reusing passwords. (LastPass)
- Only 55% would update a password even after that account was hacked. (LastPass)
- After cybersecurity education, only 31% of users stopped reusing passwords. (LastPass)
Credential Stuffing and Breaches
The 2025 Verizon Data Breach Investigations Report (DBIR) analysed more than 12,000 confirmed breaches. Stolen and replayed credentials remain the number-one way in.
- Stolen credentials were the initial access vector in 22% of breaches — the single most common entry point. (Verizon DBIR, 2025)
- 88% of basic web-application attacks involved the use of stolen credentials. (Verizon DBIR, 2025)
- In analysed single-sign-on logs, credential stuffing accounted for a median 19% of all daily authentication attempts. (Verizon DBIR, 2025)
- Exploited vulnerabilities were the second most common entry point at 20% of breaches, just behind credentials. (Verizon DBIR, 2025)
- The human element — including the use of stolen credentials — was involved in roughly 60% of breaches. (Verizon DBIR, 2025)
The Passwords That Make It Easy
Credential stuffing is joined by password spraying, in which attackers try a handful of extremely common passwords against many accounts. NordPass analysed public breaches and dark-web repositories from September 2024 to September 2025.
- "123456" is again the world's most common password — topping the list in six of the past seven years. (NordPass, 2025)
- 78% of the world's most common passwords can be cracked in under one second, up from 70% a year earlier. (NordPass, 2025)
- "admin" is the second most common password globally — and the single most common in the United States. (NordPass, 2025)
- Microsoft observed an average of more than 7,000 password attacks per second — roughly 600 million a day. (Microsoft Digital Defense Report, 2025)
- 97% of identity attacks are password-spray attacks, trying one common password against many accounts. (Microsoft, 2025)
The Cost of Account Takeover
Successful credential stuffing leads to account takeover (ATO): fraudsters drain balances, place orders, or resell access. The FBI Internet Crime Complaint Center (IC3) and fraud researchers at Javelin track the damage.
- Account-takeover fraud cost U.S. victims more than $16 billion in a single year. (Javelin, 2025)
- Account takeover affected an estimated 6 million U.S. consumers in that period. (Javelin, 2025)
- Internet crime overall caused reported losses of $16.6 billion in 2024. (FBI IC3, 2024)
- That was a 33% increase in losses over 2023. (FBI IC3, 2024)
- The IC3 received 859,532 complaints of suspected internet crime in 2024. (FBI IC3, 2024)
- Phishing and spoofing were the top complaint type — a primary source of the credentials later stuffed — with 193,407 reports. (FBI IC3, 2024)
Data Visualisation: The Leaked-Credential Login Problem
The clearest single picture of credential stuffing comes from Cloudflare's 2025 analysis. The bar chart below shows how prevalent leaked credentials are in real login traffic, and how automated the abuse has become.
Data visualisation: a horizontal bar chart. Reading top to bottom — 95% of leaked-password login attempts come from bots, 76% of such attempts succeed on content-management systems like WordPress, 52% of all authentication requests use a leaked credential, and 41% of successful logins use a password that has already been breached. Source: Cloudflare analysis of ~30 million websites, September–November 2024, published March 2025.
What Actually Stops Credential Stuffing
The defences are well established and the data backs them up. Multi-factor authentication breaks the attack even when the password is correct; passkeys remove the reusable secret entirely.
- More than 99.9% of accounts that are compromised do not have MFA enabled. (Microsoft, 2025)
- Phishing-resistant MFA blocks over 99% of identity-based attacks. (Microsoft, 2025)
- Workforce MFA adoption reached 70% of users as of January 2025 — meaning nearly a third still sign in with a password alone. (Okta, 2025)
- At the smallest firms (up to 25 employees), MFA adoption is just 27%. (Okta, 2025)
- 91% of admins use MFA, versus 66% of non-admin end users. (Okta, 2025)
🔐 The one habit that ends credential stuffing
Every statistic on this page traces back to a single behaviour: password reuse. If the password stolen from one site is unique to that site, it is worthless everywhere else — and the entire credential-stuffing model collapses. NordPass generates a unique, maximum-entropy password for every account, stores them behind XChaCha20 encryption and a zero-knowledge architecture, and warns you the moment a saved password appears in a breach or credential-stuffing list like the ones referenced above.
Get NordPass →Affiliate link — we may earn a commission at no extra cost to you.
Passkeys: Removing the Reusable Secret
The long-term fix is to stop having a password to steal. Passkeys — phishing-resistant credentials backed by the FIDO Alliance — cannot be reused or replayed, which makes credential stuffing impossible against them.
- More than 15 billion online accounts can now use passkeys, roughly double the year before. (FIDO Alliance, 2025)
- Over 1 billion people have activated at least one passkey. (FIDO Alliance, 2025)
- Google reports more than 800 million accounts using passkeys and over 2.5 billion passkey sign-ins. (Google, 2025)
- Amazon has more than 175 million customers with passkeys enabled. (Amazon, 2025)
- Because a passkey is unique to each site and never leaves the device as a reusable secret, it cannot be credential-stuffed the way a password can. (FIDO Alliance)
What NIST Recommends Against Reuse
The most-cited authority on password policy is NIST Special Publication 800-63B, the U.S. Digital Identity Guidelines. Its modern guidance targets exactly the habits that make credential stuffing work.
- NIST recommends screening new passwords against lists of known-breached passwords and rejecting matches — directly disarming credential stuffing. (NIST SP 800-63B)
- NIST recommends a minimum length of 8 characters and support for at least 64, because length beats forced complexity. (NIST SP 800-63B)
- NIST advises against mandatory periodic password changes unless there is evidence of compromise, since forced resets push users toward predictable, reused patterns. (NIST SP 800-63B)
- NIST advises against forced composition rules (mandatory mixes of symbols, digits and cases), which also encourage reuse. (NIST SP 800-63B)
What These Numbers Mean
Read together, the 52 statistics tell one story. Attackers rarely need to brute-force a strong password; they log in with one that already leaked somewhere else. Reuse turns a single breach into dozens of account takeovers, which is why 41% of successful logins now involve a leaked credential. The defences that keep validating in the data are simple: a unique password on every account from a password generator, a second factor — ideally a passkey — and providers that screen against breached-password lists. For the wider view, see our roundups of password reuse statistics and password security statistics.
Frequently Asked Questions
What is credential stuffing?
Credential stuffing is a cyberattack in which criminals take username-and-password pairs stolen in one data breach and use bots to automatically try them against logins on many other websites. Because people reuse passwords, a small percentage of those attempts unlock a working account, which the attacker then takes over or sells.
How common is credential stuffing in 2026?
It is the dominant login threat. Akamai has measured credential-stuffing traffic at roughly 26 billion attempts per month, and Cloudflare's 2025 analysis found that 41% of successful logins across the web use a password that has already been leaked — rising to 52% of all authentication requests once automated attempts are counted.
How is credential stuffing different from brute force?
Brute force guesses a password by trying many possible combinations against one account. Credential stuffing does not guess at all — it replays real passwords that already leaked in other breaches, betting that the victim reused them. That is why unique passwords defeat credential stuffing completely, even if the password is not especially long.
How much does account takeover from credential stuffing cost?
Account-takeover fraud cost U.S. victims more than $16 billion in a single year and affected around 6 million consumers, according to Javelin. Separately, the FBI's IC3 recorded $16.6 billion in total internet-crime losses in 2024, with phishing — a major source of stolen credentials — the most-reported crime.
How do I protect myself from credential stuffing?
Use a unique password for every account so that a leak from one site cannot unlock another, ideally generated and stored by a password manager. Turn on multi-factor authentication — Microsoft found that more than 99.9% of compromised accounts had no MFA — and switch to passkeys where they are offered, since a passkey cannot be reused or replayed.
Methodology and Sources
Every statistic on this page is attributed inline to the organisation that published it, with the year of the source. Figures are quoted as reported by each primary source and were current as of August 2026. Primary sources:
- Akamai — State of the Internet / application-security research on credential stuffing
- Cloudflare — leaked-credential login analysis, March 2025
- Verizon — 2025 Data Breach Investigations Report (DBIR)
- Have I Been Pwned / Synthient — Credential-stuffing dataset, November 2025
- FBI Internet Crime Complaint Center (IC3) — 2024 Internet Crime Report
- Javelin Strategy & Research — Identity Fraud Study (account takeover)
- LastPass — Psychology of Passwords; UK Information Commissioner's Office (ICO)
- NordPass — Top 200 Most Common Passwords, 2025
- Microsoft — Digital Defense Report 2025
- Okta — Secure Sign-in Trends Report 2025
- FIDO Alliance — Passkey Index 2025; Google and Amazon passkey disclosures
- NIST — Special Publication 800-63B, Digital Identity Guidelines
Note: where a statistic is a median or depends on a defined sample (for example, credential-stuffing rates from SSO logs, infostealer-infected devices, or Cloudflare's ~30-million-site sample), that context is stated with the figure. Percentages are reproduced as published and are not combined across differing denominators. Attack-volume figures reflect the network measured by each vendor and are not internet-wide totals.