Login credentials are a valuable currency in the dark corners of the internet. Hackers trade users’ login data in forums, sell it for profit, or use it for their own schemes. But how do they end up with such large amounts of passwords in the first place? Let’s talk about how hackers get thousands of passwords at once using techniques like social engineering, brute-force attacks, and OAuth phishing, how you can tell if your credentials have been stolen, and what you can do to protect your accounts.
Contents:
Key takeaways
Hackers can get passwords through data breaches, phishing, credential stuffing, brute-force attacks, password spraying, social engineering, man-in-the-middle attacks, insecure password sharing, shadow forwarding, and OAuth phishing. Each method exploits a different weakness in how people create, store, or share their credentials.
To catch potentially compromised passwords, watch for signs like unexpected account lockouts, unfamiliar login alerts, and unrequested password reset emails.
To protect your passwords, you should use a password manager, enable two-factor authentication, and monitor data breaches. Ensure all passwords are unique and share credentials only through encrypted channels. If possible, consider switching to passkey authentication.
How hackers gain access to your passwords
The economy of stolen passwords is as intricate as trade routes. Cybercriminals have developed systems for data theft, from using malware and scouring unsecured databases to obtain the passwords to listing and selling them on the dark web and cybercrime forums.
In recent years, criminals have favored the quality of stolen data over the quantity. According to research into data leak trends, the overall number of breaches has gone down, but the datasets themselves are larger, favoring stealthier attacks with more valuable credentials. The methods of data theft are also evolving — although phishing remains a highly effective social engineering tactic to steal passwords directly from unsuspecting users, AI-powered tools are gaining traction too.
Data breaches
Data breaches are incidents caused by attacks against companies that hold and manage user data. Cybercriminals compromise the company’s systems and gain access to sensitive information, including passwords, email addresses, home addresses, and Social Security numbers. Hackers can get millions of passwords at a time and compile them into bigger datasets. They then put these up for sale on the dark web or even list them for free for others to exploit.
Tip: If a service you use lets you know it had a data breach, update your password immediately and turn on two-factor authentication (2FA) for a little extra peace of mind. You can also use NordPass’s Data Breach Scanner to learn if your credentials have been compromised.
Phishing
Phishing is one of the most common and most successful cyberattacks, typically targeting large numbers of users at once. For instance, hackers might take email addresses they found in a data breach of a bank, contact all clients pretending to be that bank, and send emails asking to “confirm their passwords” or “verify their accounts.” The targets open the link and enter their details, unaware that they’ve just handed over the keys to their accounts.
To create more convincing phishing scams, criminals might use deepfakes and AI-generated images. These visuals can be used to create more compelling fake websites or, if it’s a spear phishing attack, to imitate people the target knows.
Criminals might also use phishing to steal more data than just passwords — session cookies are just as valuable. Session cookies hold unique session identifiers that let criminals bypass authentication altogether. Instead, the identifier lets them access an active login session without ever entering a password or completing multi-factor authentication. More complex threats, like reverse-proxy phishing and browser-in-the-middle (BitM) attacks, let hackers intercept credentials and steal session cookies in real time using malicious extensions and proxy scripts.
Tip: Learn to identify the telltale signs of a phishing email. If your gut is telling you something’s off, don’t click any links or share your information with the sender. Double-check the sender’s details, and if you’re unsure, go straight to the source to confirm its validity.
Credential stuffing
Many users tend to reuse the same password across multiple accounts. They might insert some variations, like an uppercase letter or an extra punctuation mark, if a website demands it. However, research into the top 1,000 most visited websites revealed that most don’t even set strict password requirements, letting users reuse the same password everywhere.
Cybercriminals are aware of this tendency and have found ways to utilize users’ laziness with credential stuffing attacks. For these attacks, hackers take credentials they’ve already stolen or taken from data breaches and use them to log in to numerous platforms and apps, hoping they find a match and can steal the account. The more times you reuse the same credential combination, the more success criminals can find by stuffing it in various sites.
Tip: Make all your passwords unique and complex — preferably at least 15 characters long and composed of uppercase and lowercase letters, numbers, and symbols. A reliable password manager with autofill and autosave can help keep things tidy if you’ve got a lot of accounts, so you don’t need to worry about accidentally forgetting your new login details.
Brute-force attacks
While credential stuffing attacks rely on passwords that hackers already have, brute-force attacks are designed to guess those passwords in the first place. Criminals use specialized software that rapidly tries different character combinations until it finds a match. The simpler your password is, the easier it is to brute-force it.
Tip: Avoid the easy stuff like “password123” or your last name. Any word that can be found in a dictionary is easy for criminals to guess — even if you replace an “A” with a “4.” Go for something longer and more random — a password generator can help you out.
Password spraying
Password spraying attacks are similar to credential stuffing. However, instead of taking a bunch of compromised passwords, criminals try a few very common combinations, like “password” or “qwerty.” Password spraying takes advantage of users who reuse the same weak passwords. With “123456” being the most common password in the world, it’s no wonder that criminals have an easy time using password spraying attacks successfully.
Tip: Avoid weak or commonly used passwords. Instead, choose longer, less predictable combinations. Consider adding two-factor authentication (2FA) to your accounts. You can use NordPass Authenticator to generate one-time codes for login authentication.
Social engineering
Social engineering attacks are a range of cyber threats that play into users’ psyches to steal their credentials. Phishing, which we’ve already discussed, is one type of social engineering. Usually, these attacks see hackers playing the long game.
Sometimes they talk to users casually, building up trust until they can feel like they can pry more and more information. In other cases, they play into the sense of urgency and pressure users into giving up their data. For instance, social engineering scammers might pretend to represent tech support and warn users that if they don’t update their credentials using a specific link right now, their account will be taken down.
Social engineering attacks are effective because they rely on human error. People tend to scrutinize less when they’re under pressure, so they’re more likely to give up their passwords themselves. By the time they realize what happened, the account is no longer in their control.
Tip: Don’t overshare online or when talking to strangers on the phone. If someone asks for your personal info out of the blue, be cautious — it’s okay to be a little skeptical. Most major services, including NordPass, will not ask you to reveal any sensitive information, like your password or credit card details, over a phone call or an email.
Man-in-the-middle attacks
A man-in-the-middle attack is a type of attack where the hacker intercepts the communication between you and the website you’re trying to log in to. These attacks usually take place on unsecured public Wi-Fi networks, like in cafés or malls. Once you connect your device to this network, the cybercriminal can capture everything you transmit over it, including your passwords and credit card numbers, without you even realizing it.
Tip: Always connect to a virtual private network (VPN) if you need to use a public Wi-Fi network. Save the more sensitive stuff, like logging in to your banking account, for later when you can connect to a secure network. Keep an eye on the “https” marker in website URLs — it usually means you’re on a secure site.
Insecure password sharing
Most people would never leave their house keys behind in the door lock or under the doormat, yet they can be careless with their digital keys. They might quickly share a password via a text message, a social media DM, an email, or send an unencrypted text file to their friend. However, by doing this, they expose their accounts to danger.
Many messaging, social media, and email services keep chats and messages unencrypted unless you choose to use an encryption feature. That means if your messages got compromised, criminals wouldn’t break a sweat finding the passwords you’ve shared. Likewise, keeping an unencrypted plaintext file labeled “Passwords” on the desktop invites danger in.
Tip: Don’t leave your passwords lying around on your device or share them over a text message. Use the NordPass secure sharing feature to keep your credentials safe even if you lend them to a friend. You can also learn to encrypt an email to keep its content private.
Shadow forwarding rules
Shadow forwarding rules are email-based attacks where cybercriminals first gain access to the victim’s email account and then, instead of locking them out completely, stealthily lurk in the inbox. They can create hidden inbox rules to copy the emails, forward them to the criminal’s inbox, and automatically delete all forwarded emails from the “Sent” folder. That way, criminals can request an account reset on a website. Although the user deletes the password reset email from their own inbox, criminals can still use the link and change the login details.
Shadow forwarding rules are difficult to identify because the user doesn’t see any interference with their account unless they check the “Sent” folder before the criminals have the chance to delete the evidence.
OAuth consent phishing
Applications can use OAuth (an authorization framework, often paired with OpenID Connect) to enable single sign-on (SSO). For instance, if you select to log in to a random website using your Google account, the process is authorized using an access token. The OAuth provider issues the token that lets the app act on your behalf without ever revealing your password.
Criminals can register apps under names that mimic legitimate services, such as file managers or email tools. These apps often have little or no real functionality — their purpose is only to capture the access token once it’s granted.
The user receives a phishing link related to the attacker-controlled app that takes them to the genuine provider’s — like Google or Microsoft — OAuth consent screen. They select “Allow” to authorize, and the access token then goes into the criminal’s servers. The access token lets hackers reach the victim’s data and services on the OAuth provider — such as their inbox or file storage — within the permissions the victim granted.
How to tell your passwords have been stolen
Hackers usually prefer to keep a low profile, so don’t expect a flashing “You got hacked” pop-up to appear on your screen, unless it’s a spoofed ad on a dodgy website. However, if your passwords have been stolen, you might notice some strange behavior related to your accounts.
Data breach notifications
The EU’s GDPR and the SEC’s cybersecurity disclosure requirements state that companies must disclose a data breach. That means if your data has been compromised, you must be told in a matter of days. This notification is your cue to update credentials immediately and reinforce your account security. If you’re worried about breaches slipping past you, you can set up NordPass’s Data Breach Scanner to monitor your passwords, email addresses, and credit card details on the dark web.
Locked out despite correct password
If you keep trying to log in to your account with the password you know is correct but are getting denied, someone might have changed it. Hackers often change passwords as soon as they gain access to the account to lock out the original owner. If you see a “Forgot password?” option, try following the platform’s account recovery steps.
Unusual login alerts
You might start receiving alerts asking you to confirm unusual login attempts or notice active sessions running on devices you don’t own. This suspicious activity lets you know that someone is trying to or has managed to access your account without your approval. The good news is that many platforms now have a built-in security feature that requires you to manually verify a new login attempt. Simply select “This isn’t me” to stop cybercriminals from reaching your account.
Unwanted password resets or security alerts
After a few failed login attempts, cybercriminals might try to reset your password. If you receive password reset emails or security alerts you didn’t request, don’t interact with any links. This lets criminals know that they have the right email address, and they might try to access your other accounts using it.
How can you protect your passwords?
Password breaches happen every single day, and you’ve likely lost at least one set of credentials to hackers over the years. To keep your current passwords safe from everyday cyber threats, you can follow a few key steps.
Monitor data breaches
Monitoring breaches is like checking the weather forecast for your online life. By staying on top of data breach updates, you can quickly know when your accounts are at risk and be ready to change your password before hackers make their move. NordPass’s Data Breach Scanner checks if your passwords, email addresses, or credit card information have been compromised in a breach. It sends an alert to your device as soon as your data is found on the dark web.
Don’t reuse passwords
Reusing passwords might seem convenient, but it poses a sizable security risk to your accounts. If one account gets compromised, the rest are at risk of being found and breached as well. Instead of using one password for everything, create unique passwords for each account you own. It might seem overwhelming at first, but with a password manager like NordPass, you can have them all sorted and easily accessible on all your devices — while remaining protected from unauthorized access.
Store your passwords securely
Don’t jot down your passwords on sticky notes, store them in plaintext files on your desktop, or, worse, send yourself DMs as reminders of your most important credentials. Make sure you use encrypted password storage to keep them safe. NordPass uses XChaCha20 encryption to offer a high level of security to all your sensitive data and requires your Master Password or biometrics to unlock your vault.
Don’t share passwords without encryption
Avoid sending a quick text to a friend just to let them access a joint account. Instead, use encrypted sharing methods. NordPass lets you control how much information you want to share by letting you set the permissions to autofill only, view, or edit.
Use strong passwords
These days, a password like “123456” or “p455w0rd” simply doesn’t cut it. Strong passwords are unique and tough to guess. Think of your password as a mini puzzle — the harder it is, the better it locks down your account. And if you want to get creative, you can come up with a passphrase — a combination of words in a sequence only you know. Since spaces and dashes both count as special characters, adding them between a few words increases the passphrase's strength while keeping it easy for you to remember. Most websites let your passwords be up to 64 characters long, so you have plenty of room to try different combinations.
Resolve your credential weak links
It takes one vulnerable password to cause a lot of damage. If you’re worried that your current passwords might not be resilient, you can check them with NordPass’s Password Health. It checks all credentials stored in your vault and detects weak, reused, and exposed passwords. As soon as you spot the weak link, you can update it to strengthen your account protection.
Use two-factor authentication
Two-factor authentication is an extra line of defense for your accounts. Even if cybercriminals manage to get your password and try to log in to an account, 2FA can stop them before they gain access — they must enter a verification code that only you have. You can store your two-factor authentication keys alongside your passwords using NordPass. Any time you need to log in, you’ll have to use biometrics to access the one-time code, keeping criminals out of your accounts.
Switch to passkeys
A password isn’t the only way to protect your account. Passkeys are a passwordless authentication method that combines biometrics with a pair of cryptographic keys to unlock your accounts. With passkeys set up, you don’t need to worry about forgetting your passwords. Instead, you can simply add and manage passkeys on NordPass, and a prompt will let you easily log in any time you need to.