One password for everything: how to protect accounts after a data breach
August 17, 2026 08:02 Society Mail, messengers, social networks, marketplaces, "Gosuslugi", banking apps - today a significant part of our lives is concentrated in gadgets and dozens of online accounts. However, many still use the same password for different services. As a result, attackers do not even have to hack anything - it is enough to use data that has ended up in another leak. About the common mistakes users make and what measures really help protect accounts, NIA "Nizhny Novgorod" spoke with Dmitry Galov, head of Kaspersky GReAT (Global Research and Analysis Team of Kaspersky Lab) in Russia. The danger of repeated passwords Personal data leaks occur regularly, but they do not always mean the loss of an account. The main problem arises when a person constantly uses one password. "If a user uses the same password across several services, and that data ends up in a leak, attackers can use the obtained combination of username and password to attempt to log into the person's accounts on various platforms," explained Dmitry Galov. This approach allows fraudsters to mass-check stolen usernames and passwords on dozens of popular platforms. In 2026, the company's specialists studied 231 million unique passwords that ended up in major global leaks from 2023 to 2026. The results were alarming: 48% of passwords can be cracked in less than a minute; 60% - in less than an hour. According to the expert, many users still choose predictable combinations that are easy to guess. Rules for a strong password "If the data of one service is compromised, attackers may try to use the same combination of username and password to log into other accounts of the user. Therefore, it is recommended to use a unique password for each account," emphasized Galov. The expert advises against obvious choices like: 123456; qwerty; names; birth dates; popular words and other information that can be found in the public domain. "In general, the more complex the password, the better," noted the specialist. It is not necessary to create such combinations manually. Nowadays, password managers can take on this task, generating complex passwords and storing them in a secure vault. When to change your password Changing your password daily or monthly is not necessary. However, there are situations when it cannot be postponed. It should be done as soon as possible if there has been a data leak, signs of hacking appear, or there is suspicion that the password has become known to outsiders. "At the same time, the new password must be unique and not just a variation of the previous one with minimal changes," the specialist notes. Where to store dozens of passwords Remembering many long combinations is not easy. Writing them down in regular notes or text files is also not the best idea. "The optimal option is to use a password manager. It allows you to generate complex unique combinations and store them in an encrypted vault, and the user only needs to remember one master password," advises the expert. If the master password needs to be written down, it should be stored in a reliable place, inaccessible to outsiders. It is also important to protect the device itself: use screen locks, install updates in a timely manner, and use security software. Not just a password Today, one password is not enough. The expert recommends enabling two-factor authentication wherever it is available. Even if the password falls into the hands of attackers, they will need additional confirmation to log in. As a second factor, you can use: an authenticator app with one-time codes; a passkey that verifies identity through a fingerprint or facial recognition; a hardware security key. It is also worth enabling notifications for new logins, regularly checking active sessions, and the list of connected devices. What to do if your account is at risk If you become aware of a data leak or suspect account compromise, it is best to act immediately: Change your password (if there is suspicion of device infection - do this from another device). Replace this password in all services where it was used. End all active sessions. Check connected devices. Enable two-factor authentication. Ensure that the phone number, email, and other recovery methods have not been changed. Check the device for malware. NIA "Nizhny Novgorod" has channels on Telegram and MAX. Subscribe to stay informed about major events, exclusive materials, and timely information. Copyright © 1999—2025 NIA "Nizhny Novgorod". When reprinting, a hyperlink to NIA "Nizhny Novgorod" is mandatory. This resource may contain materials 18+
Другие Новости Нижнего (Н-Н-152)
One password for everything: how to protect accounts after a data breach
News of Nizhny Novgorod
