Password re-use: why one leak puts your other accounts at risk

Password re-use video thumbnail: a pixel-art office manager looks worried beside the words Password re-use, Game over, on a 1980s computer screen

When we check a business’s staff email addresses against known data breaches, we find the same password, or one that’s nearly the same, used everywhere. If one website you signed up to gets hacked, criminals’ tools try that email and password, and small changes to it, on your email, your bank and your work accounts. This short video, played as a 1980s computer game, shows how it happens and the four steps to take: a password manager, three random words, two-step sign-in and a free check at haveibeenpwned.com.

Why is password re-use a risk?

Say you once signed up to a fun run website with your work email and your usual password. If that site is hacked, your email address and password can end up on a list that criminals share. Their tools then try the same pair on other websites automatically, including email, banking and work accounts. The NCSC calls this credential stuffing, and says it works because many people use the same password for different accounts.

Your email is the account to protect first. If a criminal gets into it, the NCSC warns they could reset your other account passwords and send messages pretending to be you. From a work mailbox, that could be an email to your accounts team asking them to pay an invoice to new bank details, a trick we cover in our guide to phishing, spear phishing and whaling.

Changing Summer2024! to Summer2025! doesn’t help much either. Small, predictable changes are a habit attackers know and exploit. In one study, a guessing tool given someone’s leaked password guessed 30% of their changed versions within 100 tries. Our guide to the risks of using the same password goes into more detail.

What to do about password re-use

  1. Use a different password for every account. A password manager is a secure app that creates a strong password for each account and remembers them all, so you only need to remember its own password. If you’d like one for your whole team, see our business password manager page.
  2. Use three random words for the few passwords you must remember, such as your password manager’s own password. The NCSC’s example is “coffeetrainfish”.
  3. Turn on two-step sign-in, starting with your email account. It asks for your password plus a code, usually from your phone, so a leaked password alone won’t get someone in. You may also see it called two-step verification (2SV), two-factor authentication (2FA) or multi-factor authentication (MFA).
  4. Check your email address for free at haveibeenpwned.com. It lists the known data breaches your address has appeared in. If it’s there, change that password on every account where you’ve used it, starting with your email.

Video transcript

Read the full transcript

Narrator: Password re-use? That’s when you use the same password, or one that’s nearly the same, on more than one account.

Game voice: Level one.

Narrator: Say you signed up to a website once, with your work email and your usual password. Then that site gets hacked. And your email and password end up on a list criminals share.

Game voice: Level two.

Narrator: And their tools automatically try that email and password on your email, your bank, and your work accounts. They only need that one password to get into all three.

Game voice: Access granted.

Narrator: And once they’re in your email, they can reset your other passwords, and send messages as you.

Game voice: Game over. Level three.

Narrator: So you change Summer2024 to Summer2025. Or Password1 to Password2. But criminals know that trick. Their tools try small changes like that too. So don’t rely on a tweak.

Narrator: Here at Ingenio, when we check staff emails against leaked lists like these, we find this everywhere.

Game voice: Continue?

Narrator: Yes. Use a different password for every account, and let a password manager remember them all for you. And for the few you have to remember, like the manager’s own password? Use three random words. Turn on two-step sign-in, so a leaked password alone won’t get them in. And check your email address for free, at haveibeenpwned.com.

Narrator: Every account gets its own password. Talk to Ingenio.

Frequently asked questions

What is password re-use?

Password re-use means using the same password, or one that’s nearly the same, on more than one account. If the password leaks from one of those websites in a data breach, criminals can use it to try the others.

What is credential stuffing?

Credential stuffing is when criminals take email addresses and passwords stolen in one data breach and use automated tools to try them on other websites. The NCSC says it works because many people use the same password for different accounts.

Is changing one number in my password enough?

No. Changing Summer2024! to Summer2025! is a small, predictable change, and attackers’ tools try changes like that. In one study, a guessing tool given someone’s leaked password guessed 30% of their changed versions within 100 tries. Use a completely different password for each account instead.

Does Have I Been Pwned show my password?

No. It shows which known data breaches your email address has appeared in. Its own FAQ says that when email addresses from a data breach are loaded into the site, no passwords are loaded with them. If your address appears, change the password you used on that site and anywhere else you’ve used it.

Why should my email have its own password?

Whoever gets into your email can reset the passwords for your other accounts and send messages pretending to be you. The NCSC advises a strong password for your email that you don’t use anywhere else, at home or at work, plus two-step sign-in.

Are passkeys better than passwords?

The NCSC recommends making passkeys your first choice of login wherever they’re offered. A passkey lets you sign in the way you already open your phone or laptop, such as with a fingerprint, face check or passcode. For accounts that don’t offer passkeys yet, use a strong, unique password and two-step sign-in. Our guide to what a passkey is explains how they work.

How we help

At Ingenio, we check your staff email addresses against known data breaches, so you can see whose details have appeared in one. We can set up a business password manager for your team and help you turn on two-step sign-in for Microsoft 365. Our Microsoft 365 identity protection service, powered by Huntress, watches for attackers signing in with stolen passwords. We’re based in Brighton and support businesses across Sussex and the South East.

Final thought

You don’t need to remember a different password for every account; a password manager does that for you. Add two-step sign-in, and a password that leaks from one website won’t be enough on its own to get into your email.

👉 Talk to us about checking your team’s passwords. We’re happy to talk it through.

Sources