• Resources
  • Blogs
  • Credential Stuffing and ATO: 16 Billion Reasons Brands Are at Risk 

Credential Stuffing and ATO: 16 Billion Reasons Brands Are at Risk 

Netacea logo
Netacea
07/08/25
4 Minute read

Article Contents

    Account takeover (ATO) is one of the most consistent and costly threats facing consumer-facing businesses in 2025. And this year, the problem has been supercharged by the Mother of All Breaches (MOAB), a credential leak containing 16 billion username and password combinations. 

    It rarely begins with a breach of your own systems. More often, it starts with someone else’s data leak. Credentials are reused, recompiled, and redeployed across platforms you may not even realise are vulnerable. 

    The method of choice for attackers is credential stuffing: using these stolen pairs to automate login attempts across retail, travel, fintech, and subscription services. When those logins succeed, the fallout is immediate. In many cases, stolen accounts are used to commit fraud worth thousands per day. Across industries, losses linked to credential stuffing attacks are now estimated in the billions annually. 

    The diagram below outlines a typical ‘credential washing’ workflow. It begins with a credential breach, usernames and passwords that are harvested or leaked. These credentials are then tested at scale across thousands of websites using automated tools. Valid credentials are used or sold for account takeover, while failed attempts help attackers refine and grow their combo lists. The process ultimately fuels a cycle of ongoing fraud, powered by recycled and repurposed login data. 

    Why Credential Stuffing Is Surging in 2025 

    The landscape has shifted in three key ways, all of which make credential stuffing far more dangerous now than even a year ago. The volume of available credentials available to attackers has exploded. Attackers are adapting their methods to avoid detection. And the sectors being targeted are expanding rapidly. This isn’t just a spike in traffic. Credential stuffing has shifted from being noisy and brute-force to subtle and distributed. Attackers now move slowly, disguise their behaviour, and are applying the technique across a wider range of industries. 

    1. Volume: 
      In June, a single leak known as the ‘Mother of All Breaches’ (MOAB) exposed 16 billion credentials compiled from infostealers, browser caches, cloud buckets, and public breaches. Combo lists of this scale are now widely available and refreshed regularly. 
    1. Behaviour: Attackers have changed tactics. Instead of launching obvious, high-volume login attempts, they now pace their attacks to avoid detection. They use scripts that simulate real users, route traffic through residential proxies, and structure sessions to blend in. These techniques make credential stuffing campaigns harder to spot using traditional security controls, especially as they are designed to avoid volume-based thresholds. 

    Targets: 
    Ecommerce, travel, food delivery, and media platforms have all become key targets. Attackers using stolen credentials are looking for anything that can be monetised or resold, stored payment methods, saved delivery addresses, loyalty points, subscription details, discount codes, or personal information that can be reused elsewhere. 
     

    Unlike phishing or malware, credential stuffing doesn’t need to convince the user of anything. It only needs to find the right combination. 

    2025 YTD: A Year of Breaches Feeding the Fire 

    Credential stuffing is being fuelled by a steady stream of data breaches that expose usernames and passwords to attackers. In 2025 alone, several high-profile incidents have added millions of fresh credentials to attacker toolkits: 

    • AT&T (March 2025): Over 73 million current and former customer records were leaked. Data included names, Social Security numbers, and account passcodes. 
    • LoanDepot (January 2025): 16.6 million customer records were compromised in a ransomware attack. Exposed data included personal and financial details relevant to loan accounts. 
    • Welltok (disclosed in 2025): Nearly 8.5 million patients were affected by a breach exposing healthcare-related personal data, increasing the risk of identity misuse across consumer platforms. 
    • UnitedHealth/Change Healthcare (February 2025): One of the largest healthcare-related breaches in U.S. history, exposing potentially millions of patient and provider records with sensitive credentials and access tokens. 
    • Gen Digital (Norton LifeLock) (January 2025): Thousands of accounts were accessed in a credential stuffing attack linked to reused passwords, including stored password managers and login credentials. 

    These breaches feed a broader ecosystem where stolen credentials are compiled into massive combo lists and used in credential stuffing attacks across unrelated platforms. 

    The Cost of ATO to Brands 

    Account takeover is not just a technical issue. It’s a business risk that affects multiple functions across an organisation. The cost isn’t limited to IT or security. It drives fraud losses, damages customer relationships, increases support workloads, and impacts commercial performance. Brands that rely on accounts to store value or drive repeat business are especially vulnerable, as attackers often extract financial, operational, and reputational value from every successful login. 

    • Fraud losses: Successful ATO results in direct financial loss through refunds, loyalty redemptions, and chargebacks. 
    • Operational burden: Helpdesk volumes spike as legitimate users are locked out or report suspicious activity. 
    • Brand impact: Users often blame the platform, not the attacker. Reputational damage and churn are real outcomes. 

    We’ve seen first-hand that some businesses are losing more than 10% of revenue to credential-stuffing related fraud. In one example, we helped a UK loyalty program reduce £1.4 million in monthly fraud by blocking automated login attempts before they could succeed. 

    Why Legacy Bot Management Falls Short 

    Old approaches such as: 

    • CAPTCHA 
    • Rate limiting 
    • Device fingerprinting 
    • JavaScript-based detection 

    are no longer enough. These techniques were built to stop bots that acted differently to real users, faster, more repetitive, more obviously scripted. But today’s attackers use residential IPs, run scripts that replicate real behaviour, and often rotate infrastructure to avoid detection. The result is traffic that looks genuine on the surface. 

    Many of these bots operate slowly, imitate mobile patterns, or target forgotten surfaces like customer service portals or loyalty redemption flows. They blend in by design. 

    How Netacea Helps 

    Netacea focuses specifically on the intent behind traffic. Their server-side engine detects credential stuffing by analysing decision paths, not device traits. 
    It operates agentlessly, so attackers can’t see or adjust to it. 
    It blocks high-risk logins while allowing genuine customers through. 
    It continuously updates detection based on data from over 3,000 attacker communities. 
    In the UK loyalty scheme case, Netacea blocked 650,000 credential stuffing attempts per week, helping reduce fraud by £1.4 million per month
    Learn more here: https://netacea.com/case-studies/credential-stuffing-loyalty-scheme/ 
    Shape 
    Final Thought 
    Credential stuffing is not a legacy threat. It’s evolving in scale, technique, and impact. If your customers log in to access value, they are a target, whether you’ve been breached or not. 

    Block Bots Effortlessly with Netacea

    Book a demo and see how Netacea autonomously prevents sophisticated automated attacks.
    Book

    Related Blogs

    14/05/26

    From Blocking to Trust: Why Detection Alone Isn’t Enough

    Blog
    Blog
    Netacea | 
    14/05/26
    Built from networks of compromised devices and rented out on criminal marketplaces, botnets are essential as-a-service components of any cyberfraudster’s toolkit. 
    23/03/26

    Netacea’s new Trust Layer launches for enterprises operating in the agentic economy 

    Blog
    Blog
    Netacea | 
    23/03/26
    Built from networks of compromised devices and rented out on criminal marketplaces, botnets are essential as-a-service components of any cyberfraudster’s toolkit. 
    09/02/26

    The 2026 Forecast for AI-Driven Threats

    Blog
    Blog
    Netacea | 
    09/02/26
    Built from networks of compromised devices and rented out on criminal marketplaces, botnets are essential as-a-service components of any cyberfraudster’s toolkit. 

    Block Bots Effortlessly with Netacea

    Demo Netacea and see how our bot protection software autonomously prevents the most sophisticated and dynamic automated attacks across websites, apps and APIs.
    • Agentless, self managing spots up to 33x more threats
    • Automated, trusted defensive AI. Real-time detection and response
    • Invisible to attackers. Operates at the edge, deters persistent threats

    Book a Demo