Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

How One Breach Becomes A Login Somewhere Else

Stolen credentials are valuable mainly because people reuse them, and the automated process of testing them across unrelated sites is cheap and quiet.

Individual using a VPN application on a laptop at a desk in a modern office setting.
Photograph by Dan Nelson via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

A leaked list of passwords from an obscure site causes trouble at banks and email providers that were never breached. The connection is made by attackers, not by the sites.

The stolen list is a starting point

Breached databases contain email addresses and passwords, often stored badly enough that the passwords can be recovered.

Those pairs are aggregated across many breaches into large collections, deduplicated and traded. The original source stops mattering quickly.

The value lies in the assumption that some fraction of those people used the same password on services worth attacking.

Testing is automated and deliberately slow

Software attempts each pair against a target service, using large pools of addresses so that no single source produces a suspicious volume.

Attempts are spread over time and across many accounts rather than concentrated on one, which avoids lockout rules designed around repeated failures on a single login.

Success rates are low in percentage terms and large in absolute numbers, which is the whole economics of the activity.

The defence looks like an unfamiliar login

Services respond by scoring each attempt on context: the network it came from, the device characteristics, the time and how the request was made.

An attempt that succeeds but looks unusual triggers an additional check rather than an outright refusal, since blocking legitimate users is also a failure.

This is why a correct password sometimes produces a verification prompt. The system accepted the credential and doubted the circumstances.

Password rules addressed the wrong problem

Complexity requirements were designed against guessing attacks, where an attacker tries likely passwords without knowing any.

Against a known correct password from another site, complexity is irrelevant. A long and complicated password reused twice fails exactly as fast as a simple one.

Guidance shifted accordingly towards length, uniqueness and checking new passwords against known breached lists rather than enforcing character categories.

The second factor is what actually stops it

An attacker holding the correct password still cannot proceed without the additional factor, which is why this attack collapses against accounts that have one.

Not all second factors resist equally. Those bound to the specific site cannot be relayed by an attacker who has tricked the user into supplying a code.

The practical implication is narrow and clear. Uniqueness prevents the credential travelling, and a second factor prevents it working if it does.

Questions readers ask

What happens if I lose my phone?

If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.

Is a passkey the same as biometric login?

No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.

Data & Privacysecurityauthenticationcryptographyaccounts
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas