OTBOYOTBOY
Back

Why one password can sink you

When a website is hacked, the email addresses and passwords stored there leak out. Criminals then try that same email-and-password pair on hundreds of other sites — and get in wherever you reused the same password. This trick, called "credential stuffing," is behind a huge share of account takeovers.

The most important password to keep separate is your email password. Whoever controls your email can reset the password on almost everything else.

What to do: use a different password for every important account, and store them in a password manager so you don't have to remember them all. You can check whether your email has turned up in a known breach at haveibeenpwned.com, and change any password it flags.

Threat examples

A breach notification

A service you signed up for was hacked, and the password you saved there was exposed. If you used that same password anywhere else, those accounts are now at risk too.