Credential Abuse
Credential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.
Term
description · examples · notesCredential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.
Description
This technique is particularly dangerous because it requires no vulnerability exploitation, and the attacker's activities are hard to distinguish from normal authorized user behavior.
Examples
- Logging into a corporate VPN with credentials stolen via an infostealer
- Using leaked passwords to access an email account
- Logging into an admin panel with credentials purchased on an underground market
Notes
- Multi-factor authentication significantly hinders abuse even of compromised credentials.
Mentioned in the news
- 23. JUN 2026. FortiBleed: Fabrika ukradenih kredencijala →
- 11. MAR 2026. Napadi na kritičnu infrastrukturu u Aziji koriste eksploataciju web servera i Mimikatz →
- 21. JUL 2026. Obrisan rumunski RGZ →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 19. JUN 2026. FortiGate lozinke na globalnoj mreži: proizvođač tvrdi da incident nije nov, ali lozinke i dalje rade →
- 20. MAJ 2026. CISA ostavila javni GitHub repozitorijum sa lozinkama i ključevima →
- 15. APR 2026. Lozinke za stotine naloga mađarske vlade procurele uoči izbora →
- 2. APR 2026. Ukradeni logini postali su osnova za ransomware i državne sajber napade →
- 4. MAR 2026. Ransomver grupe sve više koriste krađu identiteta i AI alate →
- 17. FEB 2026. Studija otkrila 25 ranjivosti u mehanizmima za oporavak lozinki →
- 12. FEB 2026. Cephalus ransomver cilja javno izložene RDP servise →
Threats
used by 40Threats that use it. Select one to open its page.
- Infostealer→
- Spear Phishing→
- Account Takeover→
- Phishing→
- Business Email Compromise→
- Backdoor→
- Insider Threat→
- Trojan→
- Privilege Escalation→
- Credential stuffing→
- Cloud IAM misconfiguration→
- Shadow IT→
- Whaling→
- SMS phishing - Smishing→
- Authentication Bypass→
- SQL Injection→
- Token Theft→
- Brute-force attack→
- IoT Device Compromise→
- Session Hijacking→
- API Abuse→
- Password spraying→
- Third-Party Compromise→
- SSRF→
- Shared Account Abuse→
- Pass-the-Hash→
- Cross-Site Scripting→
- MFA Fatigue→
- SIM Swapping→
- Evil Twin→
- Privilege Misuse→
- QR phishing - Quishing→
- Contractor Abuse→
- Deepfake Attack→
- Pretexting→
- Service Abuse→
- voice phishing - Vishing→
- Kerberoasting→
- Physical Access Attack→
- Cross-Site Request Forgery→
Defenses
countered by 15How it is countered. Select one to open its page.
- Logging & Monitoring→
- Identity & Access Management→
- Multi-Factor Authentication→
- Security Awareness→
- Privileged Access Management→
- Password Manager→
- Virtual Private Network→
- Zero Trust→
- Mobile Device Security→
- Security Policies→
- Deception Technology→
- Regulatory Compliance→
- Secrets Management→
- Security Champions→
- Certificate Management→