Credential Stuffing: The Foundation of Fraud Through Social Engineering 2.0
Credential stuffing automatically tests leaked passwords from previous breaches, at scale, until it finds one that works. Nobody needs to be tricked into handing over a password anymore: it’s bought on underground forums, reused from an earlier leak, or validated this way, by brute force against the login portal. Then social engineering takes over and does the rest. This combination, legitimate credentials obtained through credential stuffing plus targeted human manipulation, is what the industry is starting to call Social Engineering 2.0. Access is no longer the attacker’s main barrier. The challenge lies in what happens right after, when someone with real credentials convinces a system, or a person, that they’re acting legitimately.
The human element was present in 62% of the security breaches analyzed worldwide.
Verizon, Data Breach Investigations Report (DBIR) 2026.
What Has Changed in Social Engineering Fraud
Traditional social engineering relied entirely on manipulation. A fake call, a well-crafted phishing email, a fabricated sense of urgency. The goal was to get the password directly from the victim.
Today that password can arrive earlier, without the victim taking part in that first step at all. Credential stuffing automatically tests millions of leaked username-password pairs from previous breaches against login portals. Cloudflare detects an average of 6.9 billion suspicious login attempts a day across its network. In 2025, Verizon estimated that 19% of daily login attempts on corporate single sign-on portals were credential stuffing.
The result is a growing pool of valid credentials available for fraud. In the first half of 2025 alone, 1.8 billion credentials stolen by infostealer malware were detected, according to Flashpoint. Starting from that point, social engineering no longer needs to convince anyone to hand over their password. It just needs to convince someone, or a system, that whoever is using it is who they claim to be.
The Human Element Is Still the Entry Point
Automation solves access, but not the rest of the fraud. A person is still involved there. According to Verizon’s Data Breach Investigations Report 2026, the human element was present in 62% of the breaches analyzed.
The channel has changed too. The same report notes that mobile phishing simulations show a 40% higher engagement rate than email phishing simulations. Attacks are shifting toward WhatsApp, social media, and personal email, channels where corporate controls have less visibility.
Technology isn’t the weak point. Trust is, the trust placed in a communication that looks legitimate, especially when whoever is reaching out already knows real details about the account.
Anatomy of a Two-Phase Attack
A Social Engineering 2.0 attack combines automation and manipulation in sequence, not as alternatives.
First, the automated phase. Bots test leaked credential pairs against login portals. The success rate per attempt is low, between 0.1% and 2%, according to Imperva data. Volume makes up for that low conversion rate.
Then, the human phase. With access confirmed, or partially confirmed, an operator contacts the victim or the support team to get past whatever barriers remain: account recovery, device changes, adding a new payment recipient. We’ve already covered this second phase in detail, when login stops being the problem, in our article on social engineering attacks using valid credentials.
Traditional Social Engineering vs. Social Engineering 2.0
| Dimension | Traditional social engineering | Social Engineering 2.0 |
| Credential origin | The victim hands it over during the scam | Already valid: obtained beforehand via credential stuffing |
| How it’s obtained | Direct manipulation: a call, phishing, fabricated urgency | Large-scale automated attack, followed by selective manipulation |
| Scale | One-to-one, manual | Thousands or millions of automated attempts in parallel |
| Main control point | Login | The processes after login: recovery, device changes, adding beneficiaries |
| Cost per victim for the attacker | High: time and effort per target | Low in the automated phase; high only in the final selective manipulation |
| Effectiveness of classic controls | Partial: an anomalous login can trigger alerts | Limited: login uses real credentials and doesn’t trigger alerts |
Separating both phases in risk analysis is what makes it possible to anticipate them. Treating them as a single event is what lets them slip through unnoticed.
The Cost of Not Separating Both Vectors
In the United States, account takeover fraud generated $16 billion in consumer losses in 2024, according to Javelin Strategy & Research. Account takeover reports grew 36% year-over-year between 2023 and 2024, according to Federal Reserve and FinCEN data.
Globally, 22% of the breaches Verizon analyzed had stolen credentials as the entry vector. In regulated sectors (banking, fintech, insurance) that impact isn’t only financial. It also means answering to regulators, demonstrating traceability, and in some cases, facing litigation from customers. The banking and fintech threat landscape for 2026 covers other vectors tied to this same underlying problem: 5 cybersecurity threats reshaping KYC, fraud, and AML in banking and fintech in 2026.
How to Protect Digital Identity Against This Dual Threat
Stopping Social Engineering 2.0 requires acting on both phases of the attack, not just one.
Against the automated phase, reducing reliance on static passwords limits the value of any leaked credential. Passwordless, phishing-resistant authentication strips value from leaked credential databases: Facephi Authentication.
Against the human phase, initial access is no longer sufficient proof of identity. Behavioural biometrics continuously evaluates usage patterns, device, and context throughout the entire session, not just at login: Behavioural Biometrics.
Both capabilities work better together when they’re part of a single continuous identity strategy, rather than being bolted on as isolated controls: Facephi’s anti-fraud solutions.
Frequently Asked Questions
It’s an automated attack that tests leaked username-password combinations from previous breaches against login portals at scale, exploiting the fact that many people reuse passwords across services.
Traditional social engineering manipulates the victim to obtain the password. In the 2.0 version, the attacker already has valid credentials obtained through credential stuffing and uses manipulation to get past the controls that come after login.
It significantly reduces the risk, but doesn’t eliminate it. Not every authentication factor is phishing-resistant, and many impersonation attacks don’t target login at all, but the processes that follow it: account recovery, device changes, adding beneficiaries.
It makes it possible to continuously assess whether behaviour during the session is consistent with the real account holder, regardless of whether the credentials used to log in were correct.
By reviewing what controls exist after login, not just at access: account recovery, device changes, adding recipients, and high-risk operations. Facephi offers a compliance and identity checklist for this self-assessment.
Social engineering no longer acts alone, and neither does credential stuffing. It’s the combination of both vectors that defines the fraud organizations need to anticipate in 2026, not each one on its own.