One Account. One Unique Password.
Use unique passwords, a password manager and MFA, and respond quickly when a password is exposed.
Illustrative scenario
How It Looks in Real Life
A shopping site you used years ago is breached. Attackers take the leaked email and password and automatically try them on email, social media and work portals.
Understand it
How the Attack Works
When one service is breached, attackers replay the same email and password on many other services, a technique known as credential stuffing. Reusing a password turns a single leak into many compromised accounts.
Red flags
Warning Signs
- The same password, or small variations of it, on several accounts.
- Passwords built from names, birthdays or keyboard patterns.
- Passwords stored in notes, spreadsheets or chat messages.
- Sign-in alerts or reset emails you did not request.
Safer habits
What to Do Instead
- 1Use a password manager to generate and store a long, unique password for every account.
- 2Turn on multi-factor authentication for email, banking and work accounts first.
- 3Change exposed passwords promptly, including any account that shared them.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: entered credentials or shared a code
- 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
- 2Change the password from a trusted device by typing the real address yourself.
- 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
- 4Review recovery email, phone number and forwarding rules for unexpected changes.
Knowledge Check
What Would You Do?
A breach notification says your password for an old forum was leaked. You used a similar password for your email. What is the best response?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.