Credential stuffing is an automated attack that tries usernames and passwords leaked from other services across many sites, taking advantage of people reusing their passwords. Unlike brute force, it does not guess passwords: it replays real ones. It is countered with unique passwords, MFA, bot detection and monitoring for mass login attempts or sign-ins from unusual locations.
Related term in this glossary: Password manager
password reuse attack, account takeover, credential attack