Module 3 of StartCloud's Cyber Hygiene for Staff learning pathway, in six short units with a knowledge check: how passwords leak from breached websites and get reused against you, why passphrases beat complex passwords, how a password manager makes unique passwords realistic, what MFA is and why authenticator apps beat SMS, and the MFA fatigue and fake verification tricks scammers use.
Password and MFA Habits That Actually Hold Up
How passwords actually get stolen
Let us clear something up first. Nobody is guessing your dog's name, your footy team, or your birthday. Real password theft is boring, industrial, and it almost never starts with you.
It starts with someone else's website getting breached. Passwords leak in bulk, millions at a time, and then criminals run a trick called credential stuffing: take every leaked email-password combo and try it on every other site that matters. It works for one reason only. People reuse passwords.
That pizza shop loyalty site, the forum from 2018, the online store you ordered from once. Their whole customer database, emails and passwords included, ends up for sale.
Criminals bundle millions of leaked email-password pairs into lists and trade them. Yours is probably in a few already. That is not an insult, it is just the internet.
Automated tools fire your old pizza-shop password at banks, email providers and Microsoft 365 sign-in pages, thousands of accounts a minute. If you reused it at work, they are in.
That is the whole scam. One reused password quietly connects a forgotten loyalty account to your work email, and the attacker never had to be clever. The fix, as we are about to see, is not remembering harder. It is making reuse impossible.
Visit haveibeenpwned.com and type in your email address. It is a free, widely trusted service that tells you which known breaches your address has appeared in. Most people find a few. If a password you still use anywhere shows up, change it today, starting with anything work related.