Smarter sites, safer businesses — no strings attached.
Short answer: Password hygiene mainly means never reusing a password, because one leaked in an unrelated breach gets automatically tried against your other accounts. Current guidance favors long, unique passwords kept in a password manager over forced complexity or frequent changes.
The MFA post mentioned credential stuffing in passing — a password leaked from one unrelated breach getting tried against all your other accounts. This post is the one that actually explains it, and the good news is the fix isn't the password rules most people were taught to dread. It's one specific habit: stop reusing passwords.
Credential stuffing doesn't guess anything. It replays real, already-known username-and-password pairs, leaked from some completely unrelated site's breach, against thousands of other websites automatically, all at once. If you've ever reused a password anywhere — even somewhere that feels low-stakes, like a forum or a shopping site — and that site is ever breached, every other account using that same password is exposed the moment an automated tool gets around to trying it, which is usually fast.
This is different from someone guessing your password. The attacker already has it, correct and complete, in a giant list of real leaked credentials traded and reused across countless breaches. The only thing standing between that leaked password and your other accounts is whether you used it anywhere else.
Many people were taught: use a password with an uppercase letter, a number, a
symbol, and change it every 90 days. As of NIST Special Publication 800-63B
Revision 4 (finalized in 2025 — the current U.S. government standard for
digital identity), that specific advice has been formally dropped. Verifiers
are now explicitly barred from requiring periodic password changes without
evidence of an actual compromise, and mandatory complexity rules (one symbol, one number,
one capital) are no longer required either — both tend to push people toward
predictable patterns (Password1!, then Password2!) that don't meaningfully
improve security. What the current guidance actually emphasizes instead:
longer passwords, and never reusing them. Length and uniqueness do the
real work; forced complexity and rotation mostly just make passwords more
annoying without making them safer.
(A composite, illustrative pattern — not one specific business's story.)
A business owner uses the same password for their business's social media account and the account at their domain registrar — the service that controls where their actual website domain points. It's convenient, and the two accounts have never felt connected in any way that seemed to matter.
Months later, an unrelated breach at a completely different platform exposes a large batch of credentials, including — because it was reused there too — this exact password. An automated credential-stuffing run eventually tries it against major registrar and hosting platforms as a matter of routine, and it works. Whoever has access to the domain registrar account can redirect where the business's actual website points, hold the domain for ransom, or simply take the site offline — none of which has anything to do with the site's own code, hosting, or security headers. The weak point was a password reused somewhere the owner never thought to connect to anything important.
A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.
Both the ransomware and malware posts named this as a common way in — what "unpatched" actually means, and why the update you keep postponing matters more than it seems.
Security awarenessAll sectorsThe classic warning is outdated for most browsing today, but one real risk hasn't gone away. What's actually changed, what still matters, and how to stay safe on public Wi-Fi.
Security awarenessAll sectorsThe fake email that looks just real enough to trust. How phishing actually works, and the one habit that catches almost all of it.
Security awareness