Imagine an employee who signs up for a fitness app, a shopping site or a hobby forum using her work email address and the same password she uses at work. A year later, that site is breached. Her email and password join millions of others in a list that criminals trade and sell. Soon, automated tools are trying that exact combination against your email, VPN and cloud applications.
That is credential stuffing, and it works because people reuse passwords. Your own systems may never have been hacked, yet the attacker still walks in the front door.
A breach elsewhere. A third-party service is compromised, and its user database, including email addresses and passwords, is stolen or leaked.
Lists circulate. The data is traded or sold, often combined with data from other breaches.
Automated testing. Attackers use scripts to try those combinations against many login pages, often using networks of compromised devices to avoid being blocked.
Valid hits. A small fraction work, because some people reuse passwords. That fraction is enough, since the attempts are cheap and automated.
Account takeover. The attacker reads email, sets up forwarding rules, sends convincing phishing messages from a trusted account or looks for access to patient data and financial systems.
Because the logins use correct credentials, they can look like legitimate activity unless you are watching for patterns.
Staff members often use many systems: email, the EHR, payroll, vendor portals, pharmacy and lab sites. The more accounts a person has, the more tempting it is to reuse one password. Shared workstations, high turnover and agency staff add to the challenge. An account takeover can expose protected health information, which brings HIPAA breach notification obligations.
Many failed sign-ins from a variety of locations in a short period
Successful sign-ins from unusual countries or at odd hours
Users locked out repeatedly with no clear reason
New mailbox forwarding rules or unfamiliar sent messages
Multi-factor authentication prompts users did not initiate
This is the single most effective defense. A stolen password alone is not enough if a second factor is required. Prioritize email, remote access, administrator accounts and any system holding patient data. Where possible, prefer authenticator apps or security keys to text messages, and enable number matching or similar protections to reduce approval fatigue attacks.
Provide a business password manager so employees can create unique, strong passwords without memorizing them.
Train staff in plain terms: never use a work password anywhere else, and avoid using work email to sign up for personal services.
Favor long passphrases over complexity rules. The NIST digital identity guidance, for example, emphasizes length and screening over frequent forced changes.
Many identity platforms can block passwords that appear in known breach lists, or alert you to accounts whose credentials have been exposed. Turn those features on if your licensing includes them.
Disable legacy sign-in methods that cannot support multi-factor authentication.
Use conditional access rules to block or challenge sign-ins from countries where you have no staff.
Rate-limit and monitor login pages you host yourself, and consider bot protection for public-facing portals.
Alert on bursts of failed log-ins and on impossible travel, where one account appears in two distant places in a short time.
Review mailbox forwarding rules and sign-in logs regularly.
Have a quick process for resetting a password, revoking sessions and checking for forwarding rules when a compromise is suspected.
Document your password and multi-factor requirements, including consequences and support. Make it easy for staff to report a suspected compromise without fear of blame, since speed matters.
UnityCare IT helps healthcare organizations roll out multi-factor authentication and password managers, tighten sign-in policies and monitor for the patterns that suggest credential stuffing, so one employee's old password does not become your breach.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172