Credential stuffing – how one leaked password puts all your accounts at risk
Keytrade Bank
keytradebank.be
July 29, 2026
3 minutes to read
An online shop you ordered something from years ago is hacked. Annoying, sure, but it isn't as though there's anything left to steal, right? There's actually more than you think. If you use that same password for the online shop to secure your email account or an online bank account, this means criminals now hold the key to your digital life.
Credential stuffing is one of the most common and underestimated types of cyberattack right now. The principle is rather simple – criminals collect huge lists of usernames and passwords that have been stolen from previous data breaches. They then put bots to work to try the combinations on hundreds of other websites, such as email accounts, online shops, social media accounts, streaming services and banking and investment platforms.
The attack relies on one human habit: reusing passwords. An analysis in the Data Breach Investigations Report shows that on average, only 49% of passwords held by an individual are unique (source). That means half of our passwords are used in several locations. For criminals, one leaked password therefore gives them a 50% chance of gaining access to another account. The same report states that 88% of attacks on web applications involve the use of stolen credentials.
The numbers leave you dizzy, with 26 billion credential stuffing attempts per month (source). In June 2026, another publicly accessible database was discovered with 24 billion stolen login records: email addresses, passwords and the websites they belong to (source).
Hackers don't need to crack accounts – they simply log in
What makes credential stuffing so deceptive is that it seems like a completely normal login attempt. After all, the criminals are using your real username and password. Nothing is forced, security vulnerabilities are not exploited, and no firewalls are bypassed. The front door simply opens with the right key.
What's more, the raw materials for such an attack are also very cheap. The stolen credentials are traded in what are known as combolists, which are often available for a few cents per thousand combinations on dark web marketplaces and Telegram channels. The software to test such lists automatically is just as affordable and requires hardly any technical knowledge.
The chance of success for each attempt is small – typically somewhere between 0.1% and 2% (source). That sounds reassuring – until you do the maths and realise that a list of 100 million credentials can still give criminals access to 100,000 accounts with a 0.1% success rate.
Where do all these passwords come from?
In the past, data breaches at large companies were the main source of passwords. Today, this has shifted to what are known as "infostealers": malware that goes undetected on your computer or smartphone through a phishing email or a download hiding a virus, for example. Such programs silently steal all the passwords stored in your browser, along with cookies and completed form data.
The targeted data is bundled together and sold on. The data consists of live, working credentials, which makes it extremely valuable to criminals.
Investors are also a target
Credential stuffing doesn't just affect streaming services or online shops. Financial accounts are the grand prize in criminals' eyes. In March 2025, several Australian pension funds were targeted at the same time using stolen credentials. Most of the attacks were foiled, but members of one pension fund jointly lost around €300,000 (source).
The logic is simple – anyone who gains access to your email inbox using a reused password can reset passwords for other accounts from there. And anyone who logs in to an investment platform can act on your behalf or attempt to channel assets away. This makes your email account the crown jewel – whoever controls that, controls almost everything.
TIP: Not sure whether a message, phone call or email really is from Keytrade Bank? Use the call function in the Keytrade Bank app when calling us. This way, you can be 100% sure that you're speaking to an official staff member.
Belgians also choose passwords that are too easy to crack
Research by Belgian cybersecurity company Spotit shows that the problem also affects us in Belgium. Ethical hackers tested the passwords of more than 67,000 employees at Belgian companies, and found that they were able to recover the passwords in 58% of cases within an hour. Combinations involving a company name and a year or season – think Welkom2025, for example – proved particularly popular (source). What is a weak password at work is usually a weak password at home.
How can you protect yourself?
1. Use a unique password for each account
This is at the heart of the matter. Credential stuffing only works if you reuse passwords. If you use a different password for each account, the damage caused by a data breach is limited to just the one account.
2. Let a password manager do the work
Remembering a whole host of unique, strong passwords is hard work. A password manager generates and stores them for you, so you only need to remember one strong master password.
3. Enable two-step authentication
Even if criminals obtain your password, a second authentication step using your smartphone or an authenticator app keeps them out. This is a must – and not optional – when it comes to financial accounts.
4. Check if your data has already been leaked
Use the free Have I Been Pwned service to check whether your email address is already listed in known data breaches. If that is indeed the case, change your password for that account as well as any other accounts where the same password was used straight away – and start with your email account.
5. Use passkeys where possible
More and more services offer passkeys: a login method linked to your device and secured with your fingerprint or face, with no need for a password. A passkey cannot be stolen in a data breach, making it immune to credential stuffing.
6. Be careful with your browser
Infostealers target the passwords stored in your browser. You should be careful with downloads and suspicious links, keep your software up to date and use a reputable virus scanner.
7. Respond to anything suspicious immediately
If you've received a message about a login attempt that you don't recognise or had an email informing you that your password has been changed without your knowledge, don't hang about. Change your password and notify your bank if necessary.
Stay safe online with Keytrade Bank
At Keytrade Bank, security is a top priority. If your personal bank details have been listed on a suspicious website, your personal details have been shared with an unknown person over the phone or you've spotted an unknown payment that you didn't make, you can call us 24/7 on +32 (0)2 679 90 00.


