Week 16: One password for multiple accounts – a big risk
The NCSC regularly receives reports from people whose online accounts have been hacked, even though they’ve never shared their passwords. What many people don’t realise is that often, a single compromised password is enough to put not just one, but multiple accounts at risk. Anyone who uses the same password for different online services makes it possible for cybercriminals to trigger a whole chain reaction with a single successful attack. The consequences are particularly serious if further accounts can be reset and taken over via the "Reset password" function.
Millions of stolen login credentials from previous data breaches are circulating online, often freely available on forums or the dark web. Cybercriminals specifically use this data for "credential stuffing" attacks.
What is "credential stuffing"?
"Credential stuffing" involves automatically testing large numbers of known username-password combinations on various platforms. The effort involved is minimal, as software – or a bot – does the work. Anyone who uses the same password across multiple online services runs the risk of a chain reaction and having several accounts compromised as a result.
Why email accounts are particularly important
The consequences are particularly far-reaching if attackers gain access to an email account. As most platforms allow users to reset their passwords via a link sent to their registered email address, this means that all other accounts can also be compromised. By taking over a single email account, cybercriminals can gradually take over all of a person’s linked accounts, from social media to online shops.
The attackers’ tricks
To ensure that the victim remains unaware of what is happening for as long as possible, cybercriminals employ particularly devious tactics. In some cases, they set up a silent forwarding rule in the compromised email account. This automatically forwards incoming messages to an address controlled by the criminals without the victim noticing. In other cases, the inbox is deliberately flooded with a deluge of spam mails. As a result, important notifications – such as confirmation emails regarding password changes or account takeovers on other services – get lost in the mass of spam and remain hidden from the victim. By the time the victim realises what has happened, the cybercriminals have already taken control of several accounts.
Following data breaches, stolen login credentials are often published or sold in large quantities. Services such as Have I Been Pwned allow you to check your email address and find out whether it has appeared in a known data breach. Often, those affected are unaware that their data has been in circulation for years and that their password has long since fallen into the hands of cybercriminals.
Recommendations
- Use a different, strong password for each online service. A password that is only used once can only be compromised once.
- Use a password manager. These tools generate and store complex, unique passwords for each service. All you need to do is remember a single master password.
- Enable two-factor authentication wherever possible. Even if a password falls into the wrong hands, two-factor authentication prevents unauthorised access.
- Check regularly to see if your email address has appeared in a data breach, for example via Have I Been Pwned or the Hasso Plattner Institute’s Identity Leak Checker.
- Change your passwords immediately if you find out that a service you use has been the victim of a data breach.
- Pay particular attention to the security of your email account, as this serves as the key to all your other accounts. It should be protected with a unique, strong password and two-factor authentication.
Further information
When one password puts multiple accounts at risk
Current statistics
Last week's reports by category:
