Monday, August 10, 2026

Top 5 This Week

- Advertisement -
spot_img

Related Posts

- Advertisement -

Why Weak Passwords Are Still the Easiest Way Into a Small Business


Cybersecurity, hacker – artistic impression. Image credit: John Tekeridis via Pexels, free license

A regional accounting firm with eleven employees did not get hacked in any cinematic sense. An attacker simply signed in. The login came from an old marketing account whose password matched the one an employee also used for email, payroll, and the client portal. By the time anyone noticed the strange forwarding rules, invoices were already being rerouted. No malware, no zero-day, no genius on the other end. Just one password doing the work of five.

That is the uncomfortable truth for most small and medium-sized businesses (SMBs). The cheapest and most common way in is a credential someone already handed over, often without realizing it.

The breach usually starts with a login, not a hack

Stolen and reused credentials are not a side story in breach data. They are the headline. The use of compromised credentials was an initial access vector in 22% of breaches studied in the Verizon 2025 Data Breach Investigations Report, and 88% of basic web application attacks involved stolen credentials. Attackers are not always breaking locks. Often they are walking through doors that were left keyed to a password floating around the internet.

The damage rarely stops at one account. Verizon also found that 54% of ransomware victims had their credentials show up in infostealer logs before the attack, which is how a single leaked login becomes a full network compromise. The financial tail is long. Business email compromise alone drove $2.77 billion in reported 2024 losses, according to the FBI Internet Crime Complaint Center (IC3), and that scam almost always begins with one account an attacker can quietly read. Recent reporting on a global credential hacking campaign made the same point in blunt terms: attackers logged in using passwords victims never bothered to change.

For a small business, the bill is concrete. Hiscox put the median cost of a cyberattack on a US small business at roughly $8,300, and that figure does not capture the days of downtime, the awkward calls to clients, or the lost trust that follows.

Reuse is the quiet multiplier

One weak password is a problem. The same weak password on six accounts is a breach waiting for a trigger. Reuse is what turns a minor leak at some forgotten vendor into access to your bank portal, and employees do it constantly. Nearly half of workers, 48% in one survey, admitted to reusing passwords across workplace accounts, a Bitwarden World Password Day poll found.

Here is the mechanism that makes that dangerous. When a password leaks anywhere, attackers feed it into automated tools that try it against thousands of other sites, a technique called credential stuffing. If your office manager reused one password, a leak at an unrelated shopping site can hand someone the keys to your accounting software within minutes. The failure mode is speed and scale, not skill. Sound access control strategies start by making sure no two of those doors share a key.

A password manager closes the gap

The fix is not “tell people to try harder.” Humans cannot memorize forty unique sixteen-character passwords, so they reuse a handful and hope. The practical answer is to remove memory from the equation entirely by giving every employee a password manager that generates and stores a different strong credential for each account. The Cybersecurity and Infrastructure Security Agency (CISA) makes the same recommendation in its strong-password guidance, noting that this approach makes people far more likely to use a long, random, unique password on every site.

What does that actually change? Every account gets its own high-entropy password that no person ever types from memory. Reuse drops to zero, which means a leak at one vendor stays contained to one login instead of cascading across your business. Credential stuffing has nothing to feed on, because there is no shared password to try elsewhere.

Pair the manager with multi-factor authentication (MFA), which requires a second proof of identity beyond the password, and you cover the gap for the rare case where a single credential still slips out. The right cybersecurity tools work in layers, and these two are the layers that block the cheapest attacks first.

Rolling it out without slowing the team down

Adoption fails when it feels like a tax on getting work done, so make the secure path the easy path. A few steps cover most of the risk:

● Deploy the manager company-wide, not just to the IT person, so every employee account is protected.

● Move team logins into a shared vault. That kills the spreadsheet of passwords and the credentials pasted into chat, which are among the easiest things for an attacker to find.

● Turn on MFA everywhere it is offered, starting with email, banking, and payroll.

● Audit existing passwords for reuse and weak entries, then let the manager regenerate them.

● Revoke vault access the day someone leaves, so old employees do not keep live keys.

None of this requires a security team. It requires a decision and an afternoon.

The lowest-cost control you can ship this quarter

Most SMB defenses fail at the login, which is also the cheapest place to fix them. A password manager plus MFA does not chase the most exotic threat in the headlines. It shuts down the one that actually shows up: a reused password sold cheap and tried everywhere. Pick a manager, roll it out this week, and turn the easiest way into your business into a dead end.




Source link

- Advertisement -
Newsdesk
Newsdeskhttps://www.european.express
European Express News aims to cover news that matter to increase the awareness of citizens all around geographical Europe.

Popular Articles