Home › Knowledgebase › KB-311

How to recognise and protect against credential stuffing attacks on your business accounts

Summary

This guide helps you troubleshoot and resolve: How to recognise and protect against credential stuffing attacks on your business accounts. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Credential stuffing is a type of automated cyber attack where criminals use large lists of usernames and passwords stolen from other data breaches to try and log into unrelated accounts. Because many people reuse the same password across multiple services, these attacks are surprisingly effective. For Australian small businesses, a successful credential stuffing attack can lead to stolen data, fraudulent invoices, hijacked email accounts, and significant reputational damage. The good news is that recognising the warning signs early and putting a few protective measures in place can dramatically reduce your risk.

Warning Signs of a Credential Stuffing Attack

Because credential stuffing is automated, the first clue is usually a sudden, unusual spike in activity. Watch for the following indicators across your business accounts:

If you receive an unexpected MFA prompt, treat it as a serious warning. It usually means someone, somewhere, has your password and is trying to use it.

Quick Fix Steps

These are the highest-impact actions you can take right now to reduce your exposure. If you manage the accounts yourself, work through them in order. If 220 manages your environment, open a ticket and we will action these on your behalf.

  1. Enforce multi-factor authentication (MFA) on every business account, with no exceptions. MFA is the single most effective control against credential stuffing.
  2. Force a password reset for any user showing signs of compromise, and reset passwords for any accounts that share credentials with breached services.
  3. Block legacy authentication in Microsoft 365, as attackers frequently bypass modern security by targeting older protocols.
  4. Review sign-in logs in the Microsoft 365 admin centre and disable any active sessions that look suspicious.
  5. Remove any unauthorised mail rules and revoke any app permissions you do not recognise.

Detailed Protective Measures

Enforce Multi-Factor Authentication in Microsoft 365

If your business uses Microsoft 365, MFA should be mandatory for every user. Modern attackers can guess or purchase valid passwords, but they cannot easily bypass a second factor.

  1. Sign in to the Microsoft Entra admin centre at entra.microsoft.com using an administrator account.
  2. Navigate to Protection > Multifactor authentication.
  3. Select the users you want to protect, then choose Enable from the bulk actions menu.
  4. For stronger protection, go to Protection > Conditional Access and create a policy that Requires multifactor authentication for all users, all cloud apps, and all device platforms.
  5. Encourage staff to use the Microsoft Authenticator app rather than SMS, as SMS-based codes can be intercepted.
Never approve an MFA prompt you did not initiate. If you receive one, change your password immediately and report it to your IT contact.

Block Legacy Authentication

Legacy authentication protocols (such as POP, IMAP, and older Outlook versions) do not support MFA, making them a common entry point for credential stuffing.

  1. In the Microsoft Entra admin centre, go to Protection > Conditional Access.
  2. Create a new policy and configure the Conditions to include Client apps > Exchange ActiveSync clients and Other clients.
  3. Set the Grant control to Block access.
  4. Apply the policy to All users and enable the policy.

Review Sign-In Activity and Audit Logs

Regular log reviews help you catch attacks early, before significant damage occurs.

  1. In the Microsoft Entra admin centre, go to Identity > Monitoring & health > Sign-in logs.
  2. Filter by Failure reason and look for repeated failures from unfamiliar locations.
  3. Click any suspicious entry and choose Disable user or Revoke sessions if you confirm malicious activity.
  4. Also check the Unified Audit Log in the Microsoft Purview compliance portal for mailbox rule changes, mailbox delegations, and app consent grants.

Use a Password Manager and Unique Passwords

Credential stuffing works because people reuse passwords. A password manager removes the temptation by generating and storing a unique, complex password for every service.

Enable Brute-Force Protections on Other Platforms

If your business uses Google Workspace, cPanel, or other admin portals, apply similar protections:

What to Do If You Suspect a Successful Breach

If you believe an attacker has successfully logged into one of your business accounts, act quickly. The longer an attacker has access, the more damage they can do.

  1. Disable the affected account immediately in the Microsoft 365 admin centre to stop further access.
  2. Reset the password and revoke all active sessions.
  3. Remove any suspicious mail rules, forwarding rules, and app permissions the attacker may have set up.
  4. Check for sent mail the attacker may have used to phish your contacts, and notify any recipients.
  5. Review connected services such as OneDrive, SharePoint, and Teams for unauthorised file access or sharing.
  6. Document the incident with timestamps and affected accounts, then open a ticket with 220 so we can assist with containment, eradication, and recovery.
  7. Consider reporting the incident to the Australian Cyber Security Centre at cyber.gov.au/report, particularly if customer data may have been accessed.
Time is critical during a suspected breach. Disable the affected account first, then work through the remaining steps. Do not wait until you have completed your investigation before taking action.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket