The leak happens on someone else's server
The phrase "my password was hacked" suggests someone was guessing letters for your email. In reality, it's almost always the service that gets hacked: a store, forum, or delivery service. The whole database is taken - millions of rows at once - and your password is just one of them.
A careful service doesn't store your password. It stores a hash - an irreversible fingerprint with a random salt added, unique to each user, computed with an intentionally slow algorithm: that makes extracting passwords from a stolen database expensive. But not everyone did this. Some stored passwords in plain text; others used a fast hash that a graphics card can test billions of possibilities per second.
Why one leak unlocks several accounts
After that, it's not hacking but arithmetic. Your username is almost always the same - your email address. If your password is reused too, an "email + password" pair from a stolen database can work for your inbox, marketplace, and game account.
About 2 out of 3 adults use one password across multiple sites - Google survey, 2019
That's why a leak has a second life. Ready-made lists of pairs are run by bots across hundreds of sites in a row - this is called credential stuffing. It works rarely, for a fraction of a percent of attempts, but when there are millions of pairs, that means tens of thousands of other people's accounts. Only a second factor breaks the chain: a code or key that wasn't in the database.
A complex password doesn't protect you from this
That leads to an annoying conclusion: length and special characters barely affect whether a password leaks - only how long it takes to recover it from a hash. What protects you from a leak isn't complexity, but uniqueness. There's also the habit of changing passwords every 3 months: evidence that it reduces risk never materialized, while it is clear that people change them predictably, adding a digit to the old password. In 2017, the US standards institute NIST removed the requirement to change passwords on a schedule from its recommendations.
Changing passwords on a schedule reduces leak risk
A leak has a long shelf life: a database can circulate for years before appearing in a public archive - the full LinkedIn haul was published 4 years after the hack. That's why an email saying "your data was in a leak" can be about a service you forgot about long ago.
Your first reaction to that email may be to rush to change everything and give up halfway through. It's more useful to go in order: first your email, then services using the same password.
While your password manager opens: inhale - exhale
Why can one leak unlock several of your accounts?
What's best to do after a leak notification?
Sources
- NIST SP 800-63B "Digital Identity Guidelines" (2017)
- public analyses of the RockYou (2009), LinkedIn (2012, full dataset published in 2016), and Adobe (2013) leaks
- on password reuse - Google and Harris Poll survey, 2019
Next in the “Cybercrime” series
2 articles in full on the site, 3 more in the app
