Yes.
Credential stuffing attacks are designed to mimic legitimate logins. If the correct email and password are used, the system may record the access as ordinary activity.
A “normal” login record does not automatically mean it was you.
Full explanation:
👉 How It Happens: Data Breaches & Credential Reuse
