This is the most widespread habit on the internet and, at the same time, the cause of most break-ins against ordinary people. Not a weak password, not a missing antivirus — reuse.
A forum you signed up to ten years ago is breached. Your address and password are in the dump. They are tried automatically across hundreds of sites — and wherever the password matches, someone walks in without breaking anything.
How it actually works
-
A service you forgot about is breached
Not a bank and not your email — usually a small shop or forum where nobody handled security.
-
The database becomes public
Sooner or later it turns up in open collections assembled from dozens of breaches at once.
-
The pairs are tried automatically
A program feeds your address and password to mail providers, social networks, banks and marketplaces. Nobody studies you personally: millions of pairs go through in sequence.
-
A match opens everything
If the email matched, recovery opens the rest — even where the password was different.
What counts as a different password
- Summer2026! and Summer2026!!
- qwerty123 and Qwerty123
- MyPass1 and MyPass2
- One base plus the site name: pass-fb, pass-tw
- 7kJ#pQ2vLm@9xZaR
- fRt3!wQ8zLp%2Nbv
- anchor-breeze-sealwax-noonday
- No relationship between them at all
The last item on the left deserves its own word: the “base plus site name” scheme feels clever and collapses instantly. One password leaks, the scheme becomes visible, and the rest are worked out in your head.
Where to start fixing it
You do not need to change everything at once, and you will not manage to. The order is the same as in the one-evening audit.