If you use the same password on multiple accounts, you think you're choosing convenience, but in reality you're choosing risk. "When one site is compromised, cybercriminals don't stop there," explains Christian Ali Bravo from the team at cybersecurity firm ESET. "They take the stolen credentials and automatically try them on thousands of other sites. That's the credential stuffing».
This attack is particularly dangerous because it doesn’t require attackers to “crack” each password individually. Instead, cybercriminals steal lists of usernames and passwords from a compromised site and automatically try them on many others – email, social media, banks and e-shops. If the password works even once, they have gained access to a real account.




