{"id":24808,"date":"2018-12-04T03:42:34","date_gmt":"2018-12-04T08:42:34","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=24808"},"modified":"2021-09-24T07:34:52","modified_gmt":"2021-09-24T11:34:52","slug":"never-reuse-passwords-story","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/never-reuse-passwords-story\/24808\/","title":{"rendered":"Why you should never reuse passwords"},"content":{"rendered":"<p>Using one password for everything is convenient, but it\u2019s also dangerously insecure. We examine the case of Mark, a young designer.<\/p>\n<p>Mark is a regular guy. He has e-mail, Facebook, Instagram, Amazon, eBay, Steam, and Battle.net accounts, not to mention ones for another dozen online stores and a forum dedicated to his favorite video game. The accounts are all linked to his e-mail.<\/p>\n<p>One day, the customer database of one of the online stores Mark has an account at suffers a leak (apparently it was kept unencrypted on an open-access server). No credit card information is stolen, but e-mail addresses, names, and passwords are. At first glance, there seems no particular reason to worry. Such leaks happen, and this is just a small online store \u2014 can you blame a humble shopkeeper for not being a cybersecurity expert?<\/p>\n<p>But the cybercriminals who ransacked the database decide to try their luck \u2014 maybe someone on the list uses the same password for their e-mail account? They strike gold: Mark uses the same password everywhere, handing the cybercriminals access to his e-mail on a platter. There, they find not only photos that Mark sent to Lucy, but messages from Amazon, eBay, and other companies. Surely Mark doesn\u2019t use the same password for these accounts too? They try logging in to his Amazon account, and presto: same password again.<\/p>\n<p>Finding a credit card already linked to the Amazon account, the cybercriminals quickly snag a couple of iPhone Xs. Next up is Facebook, where the attackers ask Mark\u2019s friends for money: \u201cGuys, I really need to borrow some cash. I get paid tomorrow, so I\u2019ll pay you right back, promise.\u201d Some of the people who get the message really are Mark\u2019s friends, and send money\u00a0\u2014 to the cybercriminals\u2019 account, of course.<\/p>\n<p>But they haven\u2019t finished yet. The intruders now change the passwords for every account they can access, which in Mark\u2019s case means all of them.<\/p>\n<p>One of the Facebook friends smells a rat and decides to phone Mark to check if it\u2019s really him asking for a loan. Horrified, Mark rushes to his computer to change his Facebook password. But it\u2019s already been changed by the cybercriminals, and Mark is locked out. He tries to recover the password and asks Facebook to send him a password reset link by e-mail\u00a0\u2014 but he can\u2019t access that either, for the same reason.<\/p>\n<p>Mark realizes that he\u2019s been well and truly hacked. He calls his bank, freezes credit cards, tries desperately to change the passwords for the few services that haven\u2019t been snatched yet, and phones his friends to explain that it\u2019s not him asking for money. He apologizes to those who have already transferred funds to the scammers, and vows to pay it all back.<\/p>\n<p>And finally, Mark solemnly swears that he shall never use the same password for different services ever again for as long as he lives, and he\u2019ll enable <a href=\"https:\/\/www.kaspersky.com\/blog\/what_is_two_factor_authentication\/5036\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">two-factor authentication<\/a> wherever possible.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kpm-download\">\n","protected":false},"excerpt":{"rendered":"<p>Designer Mark used the same password for all of his accounts\u00a0\u2014 and lived to regret it. Here\u2019s his story.<\/p>\n","protected":false},"author":675,"featured_media":42037,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[1218,4230,405,187,3092,131,3099],"class_list":{"0":"post-24808","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips","8":"tag-2fa","9":"tag-international-day-for-universal-access-to-information","10":"tag-password-manager","11":"tag-passwords","12":"tag-story","13":"tag-tips","14":"tag-vasya"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/never-reuse-passwords-story\/24808\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/never-reuse-passwords-story\/14742\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/never-reuse-passwords-story\/12348\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/never-reuse-passwords-story\/6104\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/never-reuse-passwords-story\/16660\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/never-reuse-passwords-story\/14850\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/never-reuse-passwords-story\/13833\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/never-reuse-passwords-story\/17467\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/never-reuse-passwords-story\/16666\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/never-reuse-passwords-story\/21823\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/never-reuse-passwords-story\/5502\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/never-reuse-passwords-story\/11225\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/never-reuse-passwords-story\/10115\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/never-reuse-passwords-story\/18188\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/never-reuse-passwords-story\/22110\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/never-reuse-passwords-story\/23741\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/never-reuse-passwords-story\/17712\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/never-reuse-passwords-story\/21592\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/never-reuse-passwords-story\/21591\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/passwords\/","name":"passwords"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24808","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/675"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=24808"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24808\/revisions"}],"predecessor-version":[{"id":34481,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24808\/revisions\/34481"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/42037"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=24808"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=24808"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=24808"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}