Tag

#credential stuffing

7 stories taggedcredential stuffing.

A digital illustration showing a hacker targeting Microsoft 365 through OAuth
Identity & Access

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences

Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do about it.

5 min read
Full-frame overhead view of a generic fast-food mobile ordering app open on a smartphone resting on a wooden table, next to a paper cup and a red drink tray, wa
Breaches

Chick-fil-A customer accounts hit in June credential-stuffing wave

The chicken chain says attackers used passwords stolen elsewhere to break into Chick-fil-A One accounts over three days in June 2026.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a laboratory glass vial containing a coiled DNA double helix model, sitting on a dark reflective surfa
Breaches

23andMe to pay $18 million after 43 states found 'flimsy' security let hackers steal 6.9 million profiles

A coalition of state attorneys general says the DNA testing firm lacked basic protections like multifactor authentication before the 2023 breach that exposed genetic data on nearly seven million customers.

4 min read
Photoreal editorial shot of a modern smartphone on a dark desk, screen showing a generic fingerprint unlock prompt glowing softly, a faint blurred laptop keyboa
Identity & Access

Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.

Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.

3 min read
Identity & Access

Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months

Nathan Austad gets a year and a half in federal prison, plus $1.8 million in forfeiture and restitution, closing out the last of the DraftKings account-takeover prosecutions.

2 min read
Threat Intelligence

FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest

Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

2 min read
Policy & Regulation

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach

AG Rob Bonta is going after Chrome Holding Co. — the shell 23andMe rebranded into after its bankruptcy — arguing the company failed to adequately protect the genetic and personal data of millions of users.

2 min read
© 2026 Threat Vectr