> Blog_

'Password123' Is Your Company's Worst Enemy

DarkStrata Security Team

The breach dumps are full of Company2024! and reused logins - which means your email security is set by the weakest website where a member of staff reused their password. A manager's guide to the three changes that actually fix it: NCSC-style passphrases, a properly deployed password manager, and MFA with honest expectations.

We index stolen credentials for a living, so we can tell you what's actually sitting in the breach dumps and stealer logs criminals trade: not millions of exotic hacks, but the same handful of human patterns repeated endlessly. Company2024!. Summer2025!. A pet's name with a birth year. A keyboard walk like qwerty123. And - the one that does the real damage - the same password, whatever it is, reused across a dozen services.

This is a guide for managers, not security engineers. No jargon, no fearmongering; just what the attack actually looks like, and the three changes that genuinely close it down.

Why One Reused Password Beats Your Firewall

Criminals almost never "crack" passwords against your systems these days. They don't need to. When any website is breached, the email-and-password pairs from it join the billions already circulating. Automated credential stuffing tools then replay those pairs against every other login page that matters - Microsoft 365, your VPN, your CRM, your customers' accounts.

So the security of your business email is not set by your IT department. It's set by the weakest website where any of your staff reused their work password. That's the whole problem in one sentence, and no amount of firewall spending changes it.

Its cousin, password spraying, comes from the other direction: rather than many passwords against one account, attackers try one likely password - Winter2025! meets most corporate complexity policies - against every account in your company. This is exactly why the complexity rules of the 2010s backfired: force people to include a capital, a number and a symbol, and they all converge on the same guessable formula.

What Actually Fixes It

1. Long Beats Clever

The NCSC's official advice is to build passwords from three random words - something like lamp-cactus-thirty. Length is what defeats guessing, and memorability is what defeats the sticky note. If your IT policy still demands a symbol, a capital and a 90-day reset, it's out of step with the UK's own national guidance: the NCSC explicitly recommends against routine password expiry, because it produces Password1, Password2, Password3.

2. A Password Manager, Deployed Properly

The realistic goal isn't staff memorising thirty strong passwords - it's staff memorising one (to the manager) and letting software generate and store the rest, unique per site. That kills credential stuffing outright: the leaked password from some hobby forum no longer opens anything else.

Two deployment details matter more than the brand you choose:

  • Pay for the business tier and roll it out centrally. A password manager adopted by 20% of staff protects 20% of your accounts. The per-seat cost is trivial next to one incident.
  • Turn off browser password saving via policy once the manager is in place. This one is close to home for us: when infostealer malware raids a device, the browser's saved-password store is the first thing it exports. Dedicated password managers, locked behind their own master password, are a far harder target than the browser vault. Getting passwords out of browsers materially shrinks what a stealer log contains.

3. Multi-Factor - With Honest Expectations

Turn on multi-factor authentication everywhere it's offered, prioritising email first (email resets everything else), then finance systems, then remote access. An authenticator app is good; phishing-resistant methods like hardware keys or passkeys are better, and they're what the NCSC's MFA guidance points towards for accounts that matter.

But be honest with your board about what MFA does and doesn't stop. It defeats a criminal who has only a password. It does not defeat one who has stolen a session cookie - the logged-in token infostealer malware lifts from a device alongside the passwords, which lets an attacker resume a session with no login prompt at all. MFA is necessary; it is not sufficient. (More on that in our anatomy of a stealer log.)

The Piece Most Businesses Skip: Knowing When It's Already Happened

Here's the blind spot. Every measure above reduces the odds of the next theft. None of them tells you about credentials that are already circulating - the ex-employee's login in a 2023 breach dump, the sales manager's password harvested from a home laptop last month.

That visibility is a solved problem. Domain monitoring alerts you when credentials for your company appear in stealer logs or breach dumps, so you rotate them before they're used rather than after. If you run customer logins, credential screening at sign-in quietly blocks known-compromised passwords without adding friction for anyone else. And when a specific employee's credentials do turn up, Lens lets them see and fix their own exposure privately - which gets far better cooperation than a summons from IT.

A Rollout Plan That Fits in a Quarter

  1. This week: check whether your domain already appears in breach data - a free DarkStrata trial answers that in minutes. Rotate anything it finds.
  2. This month: switch on MFA for email, finance and remote access. Update your password policy to NCSC guidance: three random words, no routine expiry.
  3. This quarter: roll out a business password manager, then disable browser password saving by policy. Put domain monitoring in place so exposure becomes an alert, not a surprise.

None of this requires a security team. It requires a decision, a modest budget line, and someone to own the rollout. Compared with explaining to your customers - or the ICO - how a reused password became a data breach, it's the cheapest work your business will do this year.


Sources

Reading Progress
0% complete
Tags
password-securitycybersecuritypassword-managerstwo-factor-authenticationbusiness-securitymanager-resources
Share This Post