<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>repetition &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/repetition/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Mon, 18 Aug 2025 12:43:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>repetition &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Credential stuffing: the risk of repeating passwords and how to protect yourself</title>
		<link>https://bitfinance.news/en/credential-stuffing-the-risk-of-repeating-passwords-and-how-to-protect-yourself/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 18 Aug 2025 12:00:37 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[credential stuffing]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ESET Latin America]]></category>
		<category><![CDATA[ESET Venezuela]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[repetition]]></category>
		<category><![CDATA[Research Lab]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Warning]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=115364</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="667" src="https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET advierte que si se utiliza la misma contraseña en diversas cuentas y servicios entonces podemos ser víctimas de credential stuffing, y comparte información sobre cómo funciona y de qué manera protegerse" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2.jpg 1000w, https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2-768x512.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p>Credential stuffing is a type of cyberattack in which malicious actors use leaked usernames and passwords to log in to accounts and services other than the one that was leaked. The success of these attacks relies on the habit of reusing the same password for different accounts or services. Therefore, if a password is leaked, [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/credential-stuffing-the-risk-of-repeating-passwords-and-how-to-protect-yourself/">Credential stuffing: the risk of repeating passwords and how to protect yourself</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="667" src="https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET advierte que si se utiliza la misma contraseña en diversas cuentas y servicios entonces podemos ser víctimas de credential stuffing, y comparte información sobre cómo funciona y de qué manera protegerse" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2.jpg 1000w, https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/08/Imagen-referencial-Credential-stuffing-el-riesgo-de-repetir-contrasenas-y-como-protegerse-Suministrada-por-ESET-y-Comstat-R-2-768x512.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p style="text-align: justify;"><strong>Credential stuffing</strong> is a type of cyberattack in which malicious actors use leaked usernames and passwords to log in to accounts and services other than the one that was leaked. The success of these attacks relies on the habit of <a href="https://www.eset.com/latam/blog/cultura-y-seguridad-digital/riesgos-usar-misma-contrasena/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=contraseas&amp;utm_term=es" target="_blank" rel="noopener">reusing the same password for different accounts or services</a>. Therefore, if a password is leaked, attackers only need to try it on other sites where the user already has an account, since if there is a match, they gain access without needing to breach the system. <a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a>, a leading company in proactive threat detection, analyzes what a credential stuffing attack looks like, why they&#8217;re so effective, what their consequences can be, and how to avoid them.</p>
<p style="text-align: justify;">&#8220;Repeating passwords is like using the same key to open your house, car, office, and safe. Paying attention and managing passwords properly is as important as locking your front door. Simple habits can make a difference: avoiding password reuse, enabling two-factor authentication, and using a secure password manager are practices we need to incorporate to stay protected against this type of threat and many others,&#8221; says <strong>Camilo Gutiérrez Amaya, Head of the ESET Latin America Research Lab.</strong></p>
<p style="text-align: justify;">The start of a credential stuffing attack is when a cybercriminal obtains leaked credentials. These are triggered by <a href="https://www.welivesecurity.com/es/seguridad-digital/5-filtraciones-de-datos-ultimos-10-anos/" target="_blank" rel="noopener">data breaches</a> from important and well-known companies and organizations, and <a href="https://www.welivesecurity.com/es/contrasenas/16-mil-millones-credenciales-filtradas-que-significa/" target="_blank" rel="noopener">involve the exposure of millions of data points.</a></p>
<p style="text-align: justify;">With this sensitive information available, and <a href="https://thehackernews.com/2025/03/how-new-ai-agents-will-transform.html" target="_blank" rel="noopener">using bots or automated scripts,</a> these passwords are tested on various sites, accounts, or services (such as Netflix, Gmail, banks, social networks, among others). Thousands of logins are tested per minute.</p>
<p style="text-align: justify;">If a match is found, the accounts are logged in. This login would be identical to that of the legitimate user, making it difficult to detect, as there is no suspicious activity, such as repeated failed attempts.</p>
<h4 style="text-align: left;">To better understand the impact of these attacks, ESET reviews two specific cases that show how credential stuffing can compromise thousands of accounts</h4>
<ul style="text-align: justify;">
<li><strong>PayPal case:</strong> Between December 6 and 8, 2022, <a href="https://www.welivesecurity.com/la-es/2023/01/19/paypal-sufrio-incidente-expuso-informacion-personal-varios-usuarios/" target="_blank" rel="noopener"><strong>PayPal suffered a credential stuffing attack</strong></a> that compromised nearly <strong>35,000 accounts</strong>, exposing sensitive information such as names, addresses, dates of birth, and tax identification numbers.</li>
<li><strong>Snowflake:</strong> <strong>More than 165 organizations</strong> were affected when attackers accessed <a href="https://www.welivesecurity.com/es/privacidad/filtraciones-datos-2024-se-cuentan-miles-millones/#:~:text=el%20grupo%20que%20se%20atribuyo%20el%20ataque%2C%20shinyhunters%2C%20habia%20utilizado%20credenciales%20de%20ticketmaster%20comprometidas%20que%20no%20tenian%20activado%20la%20autenticacion%20multifactor%2C%20lo%20que%20les%20permitio%20acceder%2" target="_blank" rel="noopener">Snowflake utilizando credenciales robadas mediante malware tipo infostealer</a>. Although Snowflake&#8217;s infrastructure was not directly compromised, attackers took advantage of the lack of multi-factor authentication and the use of old passwords.</li>
</ul>
<p style="text-align: justify;"><em>&#8220;Large data breaches are the primary way cybercriminals obtain these credentials, and they are occurring more frequently than expected,&#8221;</em> adds the ESET specialist.</p>
<p style="text-align: justify;">In June 2025, another example was a series of databases totaling <a href="https://www.welivesecurity.com/es/contrasenas/16-mil-millones-credenciales-filtradas-que-significa/" target="_blank" rel="noopener">16 billion records</a> that were hosted in misconfigured repositories that were left exposed and public. Although the exposure was temporary, it was enough for researchers, or anyone else, to access the data, which included username and password combinations for online services such as Google, Facebook, Meta, Apple, and other accounts.</p>
<p style="text-align: justify;">But it wasn&#8217;t the only one of the year: in May, security researcher <strong>Jeremiah Fowler</strong> revealed the public exposure of <a href="https://www.welivesecurity.com/es/seguridad-digital/184-millones-credenciales-expuestas-base-desprotegida/" target="_blank" rel="noopener">184 million login credentials</a> for users&#8217; accounts around the world. This included information from various email server providers, Apple products, Google, Facebook, Instagram, Snapchat, and Roblox, to name just the most well-known. Not only that: the records included credentials from banks and other financial institutions, healthcare platforms, and government portals from several countries.</p>
<h3 style="text-align: left;">To avoid a credential stuffing attack, ESET recommends several actions</h3>
<ol style="text-align: justify;">
<li>Essential: Do not reuse the same password across different accounts, platforms, and services.</li>
<li>Have <a href="https://www.welivesecurity.com/es/contrasenas/contrasenas-que-tan-seguras-son/" target="_blank" rel="noopener">strong, secure, and unique passwords</a> for each account. For this purpose, a <a href="https://www.eset.com/latam/blog/cultura-y-seguridad-digital/gestor-contrasena-que-es/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=contraseas&amp;utm_term=es" target="_blank" rel="noopener">password manager</a> is very useful. This tool is designed to store login credentials and protect them through encryption, and also includes a dedicated feature for generating complex and strong passwords.</li>
<li>Enable <a href="https://www.welivesecurity.com/la-es/2022/12/22/doble-factor-autenticacion-que-es-porque-lo-necesito/" target="_blank" rel="noopener">doble factor de autenticación</a> on as many accounts and services as possible. This second factor is key if a password falls into the wrong hands, as a cyberattacker won&#8217;t be able to access the accounts without it.</li>
<li>Check if passwords or login credentials have already been leaked in a data breach, and change them immediately. For example, visit the website <a href="https://haveibeenpwned.com/" target="_blank" rel="noopener">haveibeenpwned.com</a>.</li>
</ol>
<p style="text-align: justify;">ESET invites you to learn more about computer security by visiting: <a href="https://www.welivesecurity.com/es/" target="_blank" rel="noopener">https://www.welivesecurity.com/es/</a>.</p>
<p style="text-align: justify;">For other useful preventive information, it is also available in Venezuela: <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a>, and its social media channels @eset_ve. Also available on Instagram (<a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>) and Facebook (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p style="text-align: justify;"><em>With information and main image provided by ESET and Comstat Rowland</em></p>
<p>Visit our news channel on <a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener"><strong>Google News</strong></a> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on <a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><strong>X/Twitter</strong></a> and <a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><strong>Instagram</strong></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/credential-stuffing-the-risk-of-repeating-passwords-and-how-to-protect-yourself/">Credential stuffing: the risk of repeating passwords and how to protect yourself</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
