Before You Reuse
The risk of reused passwords
Using the same password across multiple websites is convenient, but it creates a dangerous domino effect: a single breach on one minor account can compromise them all.
If a data breach exposes your email address and password, someone may try that same combination on other websites. A password taken from a shopping, gaming, streaming, or social media account could then be used to access your email, financial information, or another account that matters to you.
A password can be long and difficult to guess and still put you at risk if you reuse it. The best way to limit the damage from a breach is to use a different password for every account. That does not mean you have to remember them all.
How to Stop the Domino Effect
Protecting every account doesn't mean you have to memorize dozens of complex passwords:
-
Use a unique password for each account. If you have reused a password, start by replacing it on your email, financial, work, school, and social media accounts.
-
Let a password manager remember them for you. A password manager can create and store a different strong password for each account. Protect the password manager itself with a strong, unique password and multifactor authentication. For an additional layer of protection, some people store only part of each password in the manager and add something known only to them when signing in. If you use this approach, make sure the complete password is still unique to each account and that you will not lose access if you forget the missing portion.
-
Choose a passkey when one is available. A passkey lets you sign in using your fingerprint, face, device PIN, or screen lock instead of a password. Because each passkey is connected to a specific website or app, it cannot be reused on another site and is designed to resist phishing. Passkeys can be stored on your device, on a security key, or in some password managers. These options offer different levels of security and convenience.
-
Turn on multifactor authentication. For accounts that still use passwords, multifactor authentication adds another step before someone can sign in. It can help protect an account even if its password is exposed.
If you learn that one of your passwords was exposed, do not panic. Change it on the affected account and anywhere else you reused it. Then review those accounts for activity you do not recognize.
Celebrate Cybersecurity Awareness Month with Us
Share This Information
Forward this email to a friend and encourage them to follow us at IT Security - DoIT Cybersecurity Assurance and Digital Trust on myumbc. Learn about recent cybersecurity attacks and articles about threats, scams, and attacks.
Join Us
Want to see whether your email address has appeared in a known data breach? Visit us in the Commons Breezeway during the following two events. We can help you check, answer questions, and decide what to do next.
-
10/7/26 from 12 pm-1 pm Celebrate Cybersecurity Awareness Month (Commons Breezeway
-
10/28/26 from 12 pm-1 pm Celebrate Cybersecurity Awareness Month (Commons Breezeway
Follow along throughout Cybersecurity Awareness Month for more ways to protect your accounts and information.
The first draft of the above announcement was generated using AI and edited by the Division of Information Technology Communications and IT teams.