Skip to main content
Back to Threat Intelligence
MediumGovernmentPublic Sector Procurement

Credential-Stuffing Activity Against Government Vendor Portals

Multiple opportunistic actors · 2026-05-14

Observed TTPs

  • · Automated credential-stuffing using breached password lists
  • · Low-and-slow request pacing to evade rate limiting
  • · Targeting of vendor/procurement portals with weaker MFA enforcement

Over the past reporting period, our security monitoring across several government-adjacent deployments has recorded a sustained increase in credential-stuffing attempts specifically targeting vendor and procurement portals — systems that, in our experience, are held to a lower authentication bar than the core agency systems they connect to.

The activity we've observed is deliberately paced: request volumes stay well under naive per-IP rate limits by distributing attempts across large residential proxy pools, and login attempts are spread out over hours rather than concentrated in bursts.

This isn't a novel technique, but the consistent targeting of vendor-facing rather than citizen-facing portals is a meaningful pattern — these systems often have access to sensitive procurement data and, in some configurations, downstream access to the agencies they serve.

Agencies running vendor portals should confirm MFA is enforced for all vendor accounts (not just staff accounts), and that rate-limiting is evaluated on a rolling window rather than a fixed per-minute bucket, which is what most low-and-slow credential-stuffing is specifically designed to evade.