Credential stuffing

Credential stuffing is somebody taking passwords leaked from one website and trying them, automatically, on hundreds of others.

Nothing is being cracked. No clever code is involved. It works purely because people use the same password in more than one place, so a leak from a forum nobody remembers joining becomes a way into an email account that matters. This is the entire reason "do not reuse passwords" is repeated so often. The attack needs nothing except your habit. A different password everywhere, which realistically means a password manager, removes the whole problem.

Checked against the primary source.

More on Identity & access