Password & accounts. Updated 2026-09-13. About 5 minutes to read.
Change your email password first, then banking, and let a password manager give every other account its own password as you sign in.
Reusing a password does not put one account at risk. It puts every account with that password at the security level of the weakest site you ever signed up to. When that site is breached, your email and password pair gets tested automatically against banks, shops, streaming services and email providers. This is called credential stuffing.
It is not a rare, targeted attack. Verizon's 2025 Data Breach Investigations Report found that credential stuffing made up a median of 19 percent of all daily sign in attempts in the single sign on logs it analysed, and that in the median case only 49 percent of a user's passwords across different services were distinct.
This guide walks through how the attack works step by step, then gives you a priority order for fixing reuse without trying to change 200 passwords in one night.
Most pairs in a combolist fail. It does not matter. A list of millions of pairs, tested automatically at almost no cost, produces thousands of working accounts.
The 23andMe breach shows how far that goes. In 2023 an attacker used credentials reused from other breaches to log in to about 14,000 accounts. Through the DNA Relatives feature, those accounts exposed data on about 6.9 million people who had never had their own passwords stolen. The UK Information Commissioner's Office later fined 23andMe 2.31 million pounds, finding it had failed to put appropriate security in place.
Verizon's 2025 DBIR found compromised credentials were the initial access route in 22 percent of breaches it reviewed, the most common route for the second year running.
Cracking and stuffing tools apply these transformations automatically. A variation that feels unique to you is a rule someone already wrote.
Infostealer malware, often hidden in pirated software, fake game cheats and malicious browser extensions, copies saved browser passwords, cookies and autofill data from an infected computer. The logs include the exact site each password was used on, which makes them more valuable to attackers than old breach dumps.
If your password shows up in stealer logs, changing it is not enough. Clean the infected device first, or the new password will be captured too. Then change passwords from a clean device and sign out of all sessions, because stolen session cookies can bypass passwords and some two factor prompts.
You do not need to change every password tonight. Fix email and money today, then let the password manager catch the rest as you sign in to each site.
Only if that password is used nowhere else that matters. The danger is not the unimportant site itself, it is that attackers test its password against your email and bank. A password manager makes unique passwords effortless, so there is little reason to accept the risk.
They do not need to know. Automated tools test every stolen pair against many sites at once and keep whatever works. You become a target simply by being in a combolist.
Change a password when it has been exposed in a breach, reused, or you suspect compromise. NIST guidance says services should not force periodic changes, because forced rotation leads to predictable variations. A unique, strong password can stay in place.
No. Incrementing numbers and adding site names are among the first transformations cracking tools apply. Use a password manager to generate a random password for each site.
A combolist is a file of email and password pairs, usually compiled from many breaches and stealer logs, used as input for credential stuffing tools. Combolists are widely shared, which is why a breach from years ago can still cause an account takeover today.