Credential Stuffing:
Article

Credential Stuffing: The Foundation of Fraud Through Social Engineering 2.0

Credential stuffing automatically tests leaked passwords from previous breaches, at scale, until it finds one that works. Nobody needs to be tricked into handing over a password anymore: it’s bought on underground forums, reused from an earlier leak, or validated this way, by brute force against the login portal. Then social engineering takes over and does the rest. This combination, legitimate credentials obtained through credential stuffing plus targeted human manipulation, is what the industry is starting to call Social Engineering 2.0. Access is no longer the attacker’s main barrier. The challenge lies in what happens right after, when someone with real credentials convinces a system, or a person, that they’re acting legitimately.

The human element was present in 62% of the security breaches analyzed worldwide.

Verizon, Data Breach Investigations Report (DBIR) 2026.

What Has Changed in Social Engineering Fraud

Traditional social engineering relied entirely on manipulation. A fake call, a well-crafted phishing email, a fabricated sense of urgency. The goal was to get the password directly from the victim.

Today that password can arrive earlier, without the victim taking part in that first step at all. Credential stuffing automatically tests millions of leaked username-password pairs from previous breaches against login portals. Cloudflare detects an average of 6.9 billion suspicious login attempts a day across its network. In 2025, Verizon estimated that 19% of daily login attempts on corporate single sign-on portals were credential stuffing.

The result is a growing pool of valid credentials available for fraud. In the first half of 2025 alone, 1.8 billion credentials stolen by infostealer malware were detected, according to Flashpoint. Starting from that point, social engineering no longer needs to convince anyone to hand over their password. It just needs to convince someone, or a system, that whoever is using it is who they claim to be.

The Human Element Is Still the Entry Point

Automation solves access, but not the rest of the fraud. A person is still involved there. According to Verizon’s Data Breach Investigations Report 2026, the human element was present in 62% of the breaches analyzed.

The channel has changed too. The same report notes that mobile phishing simulations show a 40% higher engagement rate than email phishing simulations. Attacks are shifting toward WhatsApp, social media, and personal email, channels where corporate controls have less visibility.

Technology isn’t the weak point. Trust is, the trust placed in a communication that looks legitimate, especially when whoever is reaching out already knows real details about the account.

Anatomy of a Two-Phase Attack

A Social Engineering 2.0 attack combines automation and manipulation in sequence, not as alternatives.

First, the automated phase. Bots test leaked credential pairs against login portals. The success rate per attempt is low, between 0.1% and 2%, according to Imperva data. Volume makes up for that low conversion rate.

Then, the human phase. With access confirmed, or partially confirmed, an operator contacts the victim or the support team to get past whatever barriers remain: account recovery, device changes, adding a new payment recipient. We’ve already covered this second phase in detail, when login stops being the problem, in our article on social engineering attacks using valid credentials.

Traditional Social Engineering vs. Social Engineering 2.0

DimensionTraditional social engineeringSocial Engineering 2.0
Credential originThe victim hands it over during the scamAlready valid: obtained beforehand via credential stuffing
How it’s obtainedDirect manipulation: a call, phishing, fabricated urgencyLarge-scale automated attack, followed by selective manipulation
ScaleOne-to-one, manualThousands or millions of automated attempts in parallel
Main control pointLoginThe processes after login: recovery, device changes, adding beneficiaries
Cost per victim for the attackerHigh: time and effort per targetLow in the automated phase; high only in the final selective manipulation
Effectiveness of classic controlsPartial: an anomalous login can trigger alertsLimited: login uses real credentials and doesn’t trigger alerts

Separating both phases in risk analysis is what makes it possible to anticipate them. Treating them as a single event is what lets them slip through unnoticed.

The Cost of Not Separating Both Vectors

In the United States, account takeover fraud generated $16 billion in consumer losses in 2024, according to Javelin Strategy & Research. Account takeover reports grew 36% year-over-year between 2023 and 2024, according to Federal Reserve and FinCEN data.

Globally, 22% of the breaches Verizon analyzed had stolen credentials as the entry vector. In regulated sectors (banking, fintech, insurance) that impact isn’t only financial. It also means answering to regulators, demonstrating traceability, and in some cases, facing litigation from customers. The banking and fintech threat landscape for 2026 covers other vectors tied to this same underlying problem: 5 cybersecurity threats reshaping KYC, fraud, and AML in banking and fintech in 2026.

How to Protect Digital Identity Against This Dual Threat

Stopping Social Engineering 2.0 requires acting on both phases of the attack, not just one.

Against the automated phase, reducing reliance on static passwords limits the value of any leaked credential. Passwordless, phishing-resistant authentication strips value from leaked credential databases: Facephi Authentication.

Against the human phase, initial access is no longer sufficient proof of identity. Behavioural biometrics continuously evaluates usage patterns, device, and context throughout the entire session, not just at login: Behavioural Biometrics.

Both capabilities work better together when they’re part of a single continuous identity strategy, rather than being bolted on as isolated controls: Facephi’s anti-fraud solutions.

Frequently Asked Questions

It’s an automated attack that tests leaked username-password combinations from previous breaches against login portals at scale, exploiting the fact that many people reuse passwords across services.

Traditional social engineering manipulates the victim to obtain the password. In the 2.0 version, the attacker already has valid credentials obtained through credential stuffing and uses manipulation to get past the controls that come after login.

It significantly reduces the risk, but doesn’t eliminate it. Not every authentication factor is phishing-resistant, and many impersonation attacks don’t target login at all, but the processes that follow it: account recovery, device changes, adding beneficiaries.

It makes it possible to continuously assess whether behaviour during the session is consistent with the real account holder, regardless of whether the credentials used to log in were correct.

By reviewing what controls exist after login, not just at access: account recovery, device changes, adding recipients, and high-risk operations. Facephi offers a compliance and identity checklist for this self-assessment.

Social engineering no longer acts alone, and neither does credential stuffing. It’s the combination of both vectors that defines the fraud organizations need to anticipate in 2026, not each one on its own.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link