Skip to content
Cyber Unboxed
Credential Attacks

Credential Theft: How One Stolen Password Opens Every Door

Stolen logins are behind a large share of intrusions. Here are the common routes and what they look like to a defender.

4 min readIntermediate Jul 27, 2026

Explain Like I'm Not a Hacker

Credential theft is like a thief copying your house key instead of breaking the door down โ€” once they have the copy, they just walk in like they belong there.

The 30-second explanation

Why break a door down when you can copy the key instead? Attackers very often skip exploiting a technical vulnerability entirely and just obtain a real, working login: through a fake sign-in page, malware that quietly reads passwords saved in a browser, or a password recycled from a site that leaked years ago. Once they have it, they walk in through the front door like any other employee. That's why credential theft is so hard to catch quickly.

How it works

  1. 1

    1. Phish

    A cloned sign-in page, often reached via a shortened or lookalike-domain link, captures the password, and sometimes the MFA code, as it's typed.

  2. 2

    2. Malware

    Infostealer malware installed via a malicious attachment or cracked-software download reads saved passwords and session cookies from browser storage and exfiltrates them in bulk.

  3. 3

    3. Reuse

    A password from an unrelated, previously leaked breach dataset is tried automatically against many accounts on a different service โ€” a technique called credential stuffing.

  4. 4

    4. Sign in

    The attacker authenticates normally with the stolen credential, or replays a stolen session cookie, appearing to every downstream system as the legitimate account holder.

Most people picture hacking as forcing a way through a technical defence. It's very often much simpler than that: the attacker just obtains a login that already works. That can happen through a fake sign-in page that copies a password as it's typed, through infostealer malware that quietly reads the passwords and session cookies a browser has saved locally and uploads them to the attacker, or through reusing a password that leaked from an entirely unrelated website years earlier and testing it against a work account. Once the attacker holds a working login, every action they take is authenticated as a real user. There's no exploit to trip an intrusion-detection signature, and often no malware even running on the target system at all. That's why unusual behaviour after sign-in, rather than the sign-in itself being blocked, is what defenders end up watching for.

Real-world example

A person reuses the same password across an old forum account and their work email. The forum's user database is leaked and later circulated. An automated tool tries that same password, paired with the person's email address, against dozens of unrelated services' login pages, and it succeeds on the work sign-in page simply because nothing else stood in the way: no MFA, no unusual-location check. A quieter pattern skips password guessing entirely. An employee's laptop gets infected by malware bundled with a cracked application download, and within minutes the malware has read every saved password and active session cookie out of the browser's local storage and sent them to the attacker in a single archive.

How to spot it

  • Repeated failed sign-ins across many accounts

    A burst of authentication failures targeting different usernames from a small set of source IP addresses points to automated credential stuffing or spraying.

  • Sign-ins from unexpected infrastructure

    A successful login from a new device fingerprint, an unfamiliar country, or a known hosting or VPN provider rather than a residential or corporate network.

  • Sudden access to unfamiliar systems

    An account reaching a file share, admin console or application it has no history of ever using before.

  • Security changes immediately after a login

    A password reset or a new MFA device or method registered in the minutes right after an unusual sign-in โ€” a common sign the attacker is locking the real owner out.

What to do

  1. 1Never reuse a password across services โ€” a password manager that generates and stores unique passwords per site makes this realistic to maintain.
  2. 2Turn on MFA everywhere it's offered, prioritising a phishing-resistant method like a passkey or security key over SMS codes.
  3. 3If you suspect reuse or a leak, change the password immediately, sign out of all active sessions where the option exists, and review recent sign-in activity and MFA-method changes on the account.

Stay curious. Stay safer.

This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.

Explore More

Keep reading