Back to Glossary

Glossary Term

Stolen Credentials

Usernames, passwords, or authentication tokens obtained by attackers without authorization.

1 min read

Share this definition

Post it to your feed or send it to teammates.

What it is

Stolen credentials are acquired through phishing attacks, malware (such as keyloggers or infostealers), data breaches, or insecure storage practices. Once captured, credentials are often sold, shared, or immediately used to gain unauthorized access to systems, cloud services, VPNs, or SaaS platforms.

Why it matters

Credentials remain one of the most reliable ways for attackers to bypass security controls. Many breaches begin not with technical exploits, but with valid logins obtained illicitly. Stolen credentials allow attackers to move quietly, evade detection, and access sensitive systems as legitimate users.

How to reduce risk

External resources

  • https://www.ncsc.gov.uk/guidance/phishing
  • https://www.cisa.gov/secure-our-world/use-strong-passwords
  • https://owasp.org/www-community/attacks/Credential_stuffing