Safe attack demonstrations

Understand how passwords are attacked.

No real accounts, credentials, or services are used.

Interactive attack lab

See the attack.
Then stop it.

Safe, simplified simulations show how password attacks work without targeting an account, service, or real credential.

One leak. Many doors.

Credential stuffing

Watch one leaked sign-in get tested on other fictional services. Reuse lets the same stolen password open more than one account.

Fictional demonstration · no real accounts, passwords, or attacks
READY TO RUN0 / 4
01
Shopping appEmail + password exposed
WAITING
02
EmailSame password reused
WAITING
03
StreamingSame password reused
WAITING
04
BankingDifferent password + MFA
WAITING
WHAT HAPPENED

Two more accounts opened because they reused the leaked password. Banking stayed protected because its password was unique and MFA stopped the sign-in.

DEFENSE

Use a different password for every account and enable MFA.

CHECK YOUR UNDERSTANDING

What makes credential stuffing work?