The four ways your account gets cracked
When you picture a cracked account, you probably see someone typing furiously who says 'I'm in' after a tense minute. That is almost never how it goes. In practice an account is taken over in one of four ways, and in three of them nobody involved knows anything about you personally.
Those four routes are the whole problem. Once you know them, you immediately understand why the measures in this course are what they are — and why a few things you may always have done, such as that one password with a digit on the end, do not protect you.
1. Reuse: one password, ten doors
This is by far the biggest one. You use the same password in several places. Somewhere it leaks — at a web shop where you ordered something once, at a forum you have long forgotten. The fraudster then tries that combination of email address and password automatically at hundreds of other services: your email, your bank, your social accounts, your work system.
Trying costs him nothing. It runs automatically, millions of combinations at a time. He is not looking for you; he is simply seeing where something opens. However strong that password was on its own, the moment it exists in two places it is only as strong as the weaker of the two.
2. Guessing: predictable is nearly as good as known
People choose passwords in surprisingly predictable ways. A name with a birth year. The word 'welcome' with an exclamation mark. The season plus the year, because you had to change it every three months. Attackers hold lists of the millions of most-used passwords and of the tricks people use to vary them — replacing an 'a' with an '@' has been on those lists for a very long time.
So guessing does not work the way it does in films, character by character, but with ready-made lists that are worked through in seconds. What stops that is not how complicated your password is, but how unpredictable it is.
3. Data breaches: it goes wrong at the service, not at you
Sometimes you do everything right and the service itself gets hacked. Then the details of every customer are out in the open, yours included. There was nothing you could have done, and you usually do not even notice: companies report these things late, vaguely, or not at all.
What you can do is make sure the damage stays limited to that one service. That is exactly where route 1 goes wrong. In the next lesson we look at what is actually taken in a breach like that.
4. Phishing: you hand it over yourself
The fourth route is that somebody simply asks you for your details, wrapped in a believable story: a copied login page, an urgent message from 'your bank', a colleague asking for a code. Here no password is strong enough, because the problem is not that it gets guessed — you type it in yourself.
Phishing has a course of its own. One thing matters here: this is the only one of the four routes where two-step verification makes the difference between 'they have my password' and 'they are in'.
Two measures cover all four
Line the four up and you notice how small the solution really is. A unique password per service removes route 1 entirely and limits route 3 to that one service. A long, unpredictable password removes route 2. And two-step verification catches whatever still slips through via route 4.
That is this whole course in two sentences. The rest is about making that workable across dozens of accounts, without having to memorise anything and without locking yourself out.
- Write down the five accounts you would miss most if you lost them. Think of your email, your bank, your phone account, your bookkeeping, your work system.
- Next to each one, note whether you use a password there that you also use somewhere else. Be honest: 'almost the same, but with a different digit on the end' counts as reuse.
- Underline your email account. In module 5 you will see why that is the most important one on the list.
- Keep this list. You will be working from it for the whole course.
Stuck?
- I have nothing to hide, so why would anyone want my account? Because nobody is looking for you. Accounts are taken over in bulk and then used to defraud other people in your name, or resold. You do not have to be interesting to be useful.
- My password has capitals, digits and a symbol — is that not strong enough? Against guessing, perhaps. Against reuse and data breaches, no. Once the password is known from a leaked service, how it was built no longer matters.
- I change my password every quarter, does that help? Surprisingly little. People then make variations (Summer2026, Autumn2026) and those are exactly the predictable ones. Better to choose one unique, long password and only replace it when there is a reason.
- Is writing passwords down not dangerous? A note in your desk drawer is safer than the same password on ten sites. Module 3 shows a better way, but writing it down is not the worst mistake you can make.
- Which of the four routes is most common, and why does it cost the attacker almost no effort?
- Why is a complicated password that you use everywhere still weak?
- In which of the four routes is nothing your fault — and what can you still do about it?
- Which two measures together cover all four routes?