AnalysisDispatch N°05

A million attempts at your Shopify login form costs about twenty dollars

Account-checking software has been sold openly for over a decade. In 2019 Recorded Future priced the tools at $12 to $50; the equivalents are now given away. The credentials they consume are close to free. Published hit rates run from 0.1 to 2 percent, and the bottom of that range is sufficient. What changes the arithmetic is charging the attacker per attempt.

In 2019, Recorded Future's Insikt Group priced the credential stuffing supply chain end to end and found that $550 of tooling could return at least twenty times that on the resale of compromised accounts. Seven years on, most of the tools it named are given away free, and the credentials they consume have multiplied.

Over the same period competition drove the price of a compromised account of the kind that has a resale market, meaning streaming, gaming and marketplace logins, from over $10 down to between $1 and $2. Combo lists of a million credentials trade for a few dollars.

None of which would concern a Shopify merchant except that their store has a login form, an account registration form and a password reset form, all three publicly addressable, and all three attract this traffic whether or not the store holds anything worth stealing. Account takeover on a small store is not targeted. It is a by-product of a campaign running against thousands of sites at once.

The tooling, and what it sells for

The software is neither exotic nor hidden. Insikt Group's 2019 survey named the tools and quoted the prices, and they were modest even then.

Sentry MBA, one of the longest-running account checkers, is distributed with over a thousand configuration files; individual configs sold for between $5 and $20. SNIPR, written in C and supporting both online stuffing and offline dictionary attacks, retailed at $20 and shipped with more than a hundred configs. Private Keeper, popular in Russian-speaking forums, was priced from around eighty US cents. One tool the researchers examined sold for $12 and cleared a list of several thousand addresses in under two minutes.

Those prices are historical, and the direction of travel since has not been the one a vendor would prefer to report. Sentry MBA is largely defunct. OpenBullet 2 and SilverBullet, its successors, are free and open source. The tooling did not get cheaper so much as go to zero, and the money moved one step along the chain. The config, not the checker, is what the market actually prices.

"A working config for a specific target represents the reverse-engineering of that target's anti-bot stack: which CSRF tokens to grab, which fingerprint values to send, which proxy types still work, which response shapes correspond to which outcomes. Configs for popular targets are sold for $50 to $500 each. Configs for new targets get released within days of any anti-bot deployment that breaks the previous one."

Foil, security vendor documentation, Credential stuffing, May 2026. We have not been able to verify this price range against a second source and it should be treated as one vendor's estimate.

That is the competitive dynamic. A defence is broken once, and the break is then sold on to people who could not have produced it. The relevant question for a merchant is therefore not whether their protection can be broken, but whether their store is worth someone writing a config for. For most stores it is not, which is why ordinary defences hold.

The cost stack

Set out end to end, the inputs are individually cheap. Below is the stack, sized for a campaign of one million login attempts spread across many targets rather than aimed at one store. Tooling prices are 2019 figures; proxy and solver rates are 2026. Both figures below are models built from published rates, not measurements of any specific campaign.

Figure 01 — Inputs to one million login attemptsN°01
1 Combo listEmail and password pairs from breach dumps, stealer logs or SQL injection. Bulk lists from older breaches sell cheaply; fresh and pre-sorted lists cost more. ~$5PER MILLION PAIRS
2 Account checkerOpenBullet 2 and SilverBullet are free and open source. Priced tools existed in 2019 at $12 to $50; today this line is realistically zero. $0–$50ONE OFF, 2019 PRICES
3 Config for the targetThe reverse-engineered login flow. Community configs for common platforms circulate free; bespoke work for a hardened target is the expensive line. $0–$500ONE OFF
4 Residential proxiesExit IPs on consumer ISP connections, priced by the gigabyte at roughly $1 to $15. The per-attempt cost turns entirely on how much traffic each attempt consumes, which varies by an order of magnitude depending on whether the checker reads full response bodies. $5–$75PER MILLION ATTEMPTS
5 CAPTCHA solving, if requiredOnly billed on attempts that actually meet a challenge. Published rates run $1 to $5 per thousand solves. variable$1–$5 PER 1,000
Campaign cost, before any challenge
Free tooling and config, cheapest proxies at the low end; realistic bandwidth at the high end
$10–$70
Line 5 is the only one a merchant influences. Everything above it is a fixed cost of doing business that no individual store affects. Adding a challenge does not remove the attacker's margin. It adds a per-attempt charge, and the next figure shows what that charge does. Sources: Recorded Future 2019 (tooling), published residential proxy and solver rates, 2026.

Against that outlay, the return, and then the same return once the merchant charges for entry. Published hit rates for credential stuffing run between 0.1 and 2 percent, depending on the freshness of the list and the target. For the challenged column we have used $1.50 per thousand solves, the rate we established in our first dispatch, applied to every attempt.

Figure 02 — Yield on one million attemptsN°02
At published hit rates and resale values
Hit rateAccountsIf every hit resold at $1–$2Against $22, no challengeAgainst $1,522, challenged
0.1%stale list, hardened target1,000$1,000–$2,00045× to 91×0.7× to 1.3×
0.5%typical5,000$5,000–$10,000227× to 455×3.3× to 6.6×
2.0%fresh list, weak target20,000$20,000–$40,000909× to 1,818×13× to 26×
The right-hand column is the argument. A per-attempt charge does not end the attack at any hit rate, but at the low end it inverts it: against a stale list and a challenged form, the campaign returns roughly what it costs. That is the whole mechanism by which a small control works, and it only works on the marginal target. Three caveats, all of which favour the attacker in the middle columns. Most hits will not resell at $1–$2, because there is no market for a login at one small store; the saleable asset is the validated pair, which is worth something because it works elsewhere. What the attacker takes from your store directly is the stored payment method, gift-card balance or loyalty points. Recorded Future's own 2019 estimate was a return of roughly twenty times, not several hundred; our middle columns are larger because they price tooling at its cheapest and assume universal resale. Treat them as a ceiling. And a million attempts is a campaign figure, not a per-store one. A store with 20,000 customers cannot supply a million meaningful attempts.

Three forms, three purposes

On a Shopify storefront this traffic arrives through three forms, and merchants tend to notice only the symptoms rather than the mechanism.

Figure 03 — What each form is used forN°03
Login

The credential stuffing target proper. Pairs from a combo list are replayed against your customer base to find password reuse.

What you seeA failure rate far above normal, thousands of distinct addresses, roughly one attempt each.
Registration

Disposable account creation. Sometimes the goal itself, often a side effect of checkout bot activity that creates an account per attempt.

What you seeHundreds of accounts with no orders, no sessions and addresses at disposable domains. It is also the most reliable enumeration oracle you have, because "this email is already registered" confirms an account exists.
Password reset

Two uses. Enumeration, to learn which addresses have accounts. And amplification, because each request sends mail from your domain to an address the attacker chose.

What you seeReset requests for addresses that have no account, in volume.
The third one connects to a different attack entirely. A password reset form that mails anyone on request is an amplifier of exactly the kind described in our second dispatch on subscription bombing, where the store's own transactional mail is used to bury a fraud confirmation in a stranger's inbox.

All three are ordinary Shopify storefront forms. Unlike the checkout endpoint examined in our fourth dispatch, they can be scored, rate-limited and gated by anything a merchant chooses to install.

All three, in about two minutes

Score login, registration and password reset before the next list runs

Spambuster puts invisible Google reCAPTCHA on all three account forms, plus contact, newsletter, comments and reviews. It provisions its own keys, logs every decision with the score behind it, and never shows a real customer a puzzle. Basic is $3 a month. A year of it costs less than the proxy bandwidth for a single campaign.

Start the free 14-day trial →
No credit card to try·Live in 2 minutes·Billed through Shopify

Telling it apart from real traffic

Credential stuffing is easy to identify once you know to look at the ratio rather than the volume, because it inverts the normal shape of login failure.

A real customer who cannot log in fails several times on the same address, then requests a reset. Credential stuffing produces the opposite: an enormous number of distinct addresses, each attempted once or twice, with a failure rate that in a serious campaign runs well above 90 percent. A login form whose failure rate has moved from a normal ten or fifteen percent to ninety is not experiencing a usability problem.

The other reliable signature is on the reset form. A burst of password reset requests for addresses that have no account on the store is enumeration, and it usually precedes something else.

One practical caveat. Shopify does not expose customer login failure logs to merchants, so the ratio described above is not something most readers can query directly. What is visible in the admin is the Customers list, where a stuffing or registration campaign shows up as a cluster of accounts with no orders, no sessions and addresses at disposable domains, created within a narrow window. If you run a form-scoring app, its own decision log is the other place the pattern appears.

If accounts have already been taken

Credential stuffing succeeds against password reuse, which means a successful hit on your store is also a successful hit somewhere else. Force a reset on affected accounts, and be careful how you word the notice: telling customers their account "was accessed" without explaining that the password came from another service's breach tends to produce the conclusion that your systems were compromised. They were not, and saying so plainly is fair.

Do not assume that distinction discharges your obligations. Unauthorised access to customer data you hold can still be a notifiable breach under the GDPR, the Australian Notifiable Data Breaches scheme and several US state laws, regardless of where the password came from. We are not lawyers and this is not advice. Take some before deciding not to notify.

What actually raises the price

The objective is not to make the attack impossible. It is to make your store more expensive than the next entry in the list, which against a campaign running over thousands of targets is generally sufficient.

Most published advice on credential stuffing assumes you control the login endpoint. On Shopify you do not. /account/login, /account and /account/recover are served by Shopify, and rate limiting, password policy and response shaping are Shopify's to set rather than yours. This is the same constraint documented in our fourth dispatch, and it is worth separating what you can change from what you cannot.

What Shopify controls, and you cannot tune

What you control

Our third dispatch reached the same conclusion from the other direction. Every control in this category is a price, not a wall. The right-hand column of Figure 02 is what a price looks like when it works, and the three columns to its left are what the same campaign looks like against a store that never set one.

About this report

Spambuster builds form-spam protection for Shopify storefronts and sells scoring on the three account forms described above, which is a commercial interest in the conclusion of Figure 02. Tooling prices are quoted from Recorded Future's 2019 research and we have not re-verified them against current markets; we would expect them to have fallen, since most of the tools named are now distributed free, but we have not established that. Figures 01 and 02 are models built from published rates rather than measurements of any campaign. We have no first-party telemetry in this report, which is its main limitation. Corrections to contact@jola.com.au

Make your store the expensive one.

Invisible Google reCAPTCHA scoring on login, registration and password reset, plus contact, newsletter, comments and reviews. Two minutes to set up, no keys to paste, and a full log of every decision.

Start your free 14-day trial →
From $3/mo·No credit card to try·Cancel anytime