Password reuse risk: how one old breach unlocks your other accounts

Password & accounts. Updated 2026-09-13. About 5 minutes to read.

Change your email password first, then banking, and let a password manager give every other account its own password as you sign in.

Reusing a password does not put one account at risk. It puts every account with that password at the security level of the weakest site you ever signed up to. When that site is breached, your email and password pair gets tested automatically against banks, shops, streaming services and email providers. This is called credential stuffing.

It is not a rare, targeted attack. Verizon's 2025 Data Breach Investigations Report found that credential stuffing made up a median of 19 percent of all daily sign in attempts in the single sign on logs it analysed, and that in the median case only 49 percent of a user's passwords across different services were distinct.

This guide walks through how the attack works step by step, then gives you a priority order for fixing reuse without trying to change 200 passwords in one night.

What happens to your password after a breach

  1. A site is breached. Passwords are stolen in plain text, or as hashes that attackers crack. Weak and common passwords crack quickly.
  2. Email and password pairs are compiled into combolists: text files with one email:password per line, merged from many breaches and traded or shared on criminal forums and chat channels.
  3. An attacker loads a combolist into a credential stuffing tool along with a config file describing a target site's login form, including extra steps and security tokens.
  4. The tool routes attempts through large pools of residential proxies, so each attempt appears to come from a different home internet connection and slips under rate limits.
  5. Successful logins are saved as hits. Attackers drain stored card details, loyalty points and gift card balances, take over email accounts, or sell the verified accounts to others.

Why a tiny success rate still does serious damage

Most pairs in a combolist fail. It does not matter. A list of millions of pairs, tested automatically at almost no cost, produces thousands of working accounts.

The 23andMe breach shows how far that goes. In 2023 an attacker used credentials reused from other breaches to log in to about 14,000 accounts. Through the DNA Relatives feature, those accounts exposed data on about 6.9 million people who had never had their own passwords stolen. The UK Information Commissioner's Office later fined 23andMe 2.31 million pounds, finding it had failed to put appropriate security in place.

Verizon's 2025 DBIR found compromised credentials were the initial access route in 22 percent of breaches it reviewed, the most common route for the second year running.

The reuse patterns attackers try first

Cracking and stuffing tools apply these transformations automatically. A variation that feels unique to you is a rule someone already wrote.

  • The exact same password on another site.
  • The same password with the number incremented: Summer2024 becomes Summer2025.
  • The same base with the site name added: Rover!Netflix and Rover!Amazon.
  • Capitalisation and symbol swaps: password1 becomes Password1!.
  • The same password with a different email address you are known to use.

Infostealers: when reuse is not the only problem

Infostealer malware, often hidden in pirated software, fake game cheats and malicious browser extensions, copies saved browser passwords, cookies and autofill data from an infected computer. The logs include the exact site each password was used on, which makes them more valuable to attackers than old breach dumps.

If your password shows up in stealer logs, changing it is not enough. Clean the infected device first, or the new password will be captured too. Then change passwords from a clean device and sign out of all sessions, because stolen session cookies can bypass passwords and some two factor prompts.

Fix reuse in priority order

  1. Install a password manager and create a long master passphrase you have never used anywhere else.
  2. Change your primary email password first. Email resets every other account, so it is the master key.
  3. Change banking, investment, tax, government and superannuation or retirement accounts next.
  4. Change your mobile carrier account and your Apple or Google account.
  5. Change shopping sites with stored cards, then social media, then everything else as you log in to it.
  6. Turn on two factor authentication for the top two tiers, using an authenticator app, passkey or security key.
  7. Run your password manager's security report and clear the remaining reused passwords over the next month.

You do not need to change every password tonight. Fix email and money today, then let the password manager catch the rest as you sign in to each site.

What actually stops credential stuffing

  • Unique passwords per site, generated by a password manager. A stolen password then works in exactly one place.
  • Passkeys, which are tied to the website they were created for and cannot be replayed on another site or typed into a phishing page.
  • Two factor authentication, which stops most stuffing attempts even when the password is right.
  • Breach screening. NIST's digital identity guidelines require services to check new passwords against lists of known compromised passwords, and say services should not force routine periodic password changes.
  • Sign in alerts, so you hear about a successful login from a new device immediately.

Frequently asked questions

Is it OK to reuse a password on unimportant sites?

Only if that password is used nowhere else that matters. The danger is not the unimportant site itself, it is that attackers test its password against your email and bank. A password manager makes unique passwords effortless, so there is little reason to accept the risk.

How do hackers know that I reuse passwords?

They do not need to know. Automated tools test every stolen pair against many sites at once and keep whatever works. You become a target simply by being in a combolist.

How often should I change my passwords?

Change a password when it has been exposed in a breach, reused, or you suspect compromise. NIST guidance says services should not force periodic changes, because forced rotation leads to predictable variations. A unique, strong password can stay in place.

Is adding a number or the year to my password enough?

No. Incrementing numbers and adding site names are among the first transformations cracking tools apply. Use a password manager to generate a random password for each site.

What is a combolist?

A combolist is a file of email and password pairs, usually compiled from many breaches and stealer logs, used as input for credential stuffing tools. Combolists are widely shared, which is why a breach from years ago can still cause an account takeover today.

Tools that help

Related guides

Sources