The habit that actually gets people hacked
It is almost never a sophisticated attack. It is one password used in two places.
Updated 2026-09-25
Almost nobody gets "hacked" in the way films suggest. What actually happens is duller.
A company you signed up to years ago gets breached. The stolen list — email addresses and passwords — gets traded. Software then tries every one of those combinations against hundreds of other sites. If you used the same password anywhere else, that account opens. No skill, no targeting, no sophistication. Just patience and a list.
This is called credential stuffing, and it is the single most common way ordinary accounts are lost.
Why "but it is a strong password" misses the point
Strength stops guessing. It does nothing about a password that has already been copied out of a database. A 20-character password used in two places is worth less than a mediocre one used in one.
Uniqueness matters more than complexity.
What to do, in order of value
1. Make your email account unique and protected. Everything else resets through it. If someone holds your email, they hold every account attached to it. Give it a password used nowhere else and turn on two-factor authentication today.
2. Use a password manager. Your browser has one built in and it is free. You stop needing to remember or invent anything, and every site gets something different.
3. Turn on two-factor authentication where it matters. Email, banking, and anywhere your money or identity lives. An app code or a passkey beats an SMS code, but SMS is far better than nothing.
4. Check what has already leaked. Our password checker tells you whether a password appears in known breach data — the check happens in your browser, and the password is never sent to us or anyone else.
What not to bother with
Changing all your passwords every 90 days. It makes people pick weaker, more predictable variations — Summer2026! becoming Autumn2026! — and the official advice moved away from it years ago. Change a password when there is a reason to: a breach, a suspicion, or a password you know you reused.
Check a password Free, and it needs no account.