After a password breach: how stolen logins get used
Leaked passwords are tried automatically on thousands of sites within hours. Here is how credential stuffing works and the exact steps that stop it.
How one leak becomes many break-ins
Breaches rarely stay contained. Stolen email-and-password pairs are bundled into combination lists and fed to automated tools that try them on banking, email, shopping and social sites — thousands of attempts per minute.
Reuse is what makes this work. A password leaked from a forum in 2019 can open an inbox in 2026 if it was never changed. Attackers count on it.
What to do right now
Treat any breach notice as a prompt to act on every account that shared the password, not just the breached one. Speed matters more than perfection here.
- Change the breached password and every account that reused it
- Turn on two-factor authentication, starting with email
- Watch for phishing that references the breach to look legitimate
- Remove accounts you no longer use instead of leaving them exposed
Stop the next breach hurting
Unique passwords plus a second factor turn a future leak from account takeover into a minor incident. A password manager makes uniqueness effortless; a hardware key or authenticator app makes the second factor phishing-resistant.
The password-manager and two-factor-auth tutorials below walk through both setups step by step.