Lesson 4 of 4 · Module 03

Credential Attacks Explained

Attackers do not always need to break software to access an account. They may guess passwords, reuse stolen credentials, or trick someone into approving a sign-in.

4 min lesson · Beginner friendly

Different routes to the same account

Password guessing tries possible passwords. Password spraying tries a small number of common passwords against many accounts. Credential stuffing reuses username and password combinations stolen elsewhere. These are different techniques, even though each can lead to an unauthorized sign-in.

A reused password connects accounts

Imagine two unrelated services share the same email address and password. If one service exposes that combination, the other account becomes a possible target. Unique passwords limit this connection between breaches. A password manager can make unique credentials easier to maintain.

Recognize suspicious prompts

Repeated verification prompts you did not initiate are not a reason to approve one. Deny or ignore them and review the account through its official app or site. Additional authentication helps, but stolen sessions and deceptive approval requests mean activity monitoring still matters.

  • Protect the email account used for recovery.
  • Avoid reused passwords.
  • Report unexpected work-account authentication prompts to the appropriate team.