FILE No.EN-17 · ONLINE

One Password to Lose Them All

ARCHIVED
2026-10-01 · source: rewritten from a credential-stuffing breach report

The Act

Millions of people used the same email-and-password combo across dozens of sites. When breach dumps from old forums and apps leaked those combos, attackers loaded them into automated tools and tried them against major brands — including a fast-food chain's loyalty app.

The Price

Tens of thousands of loyalty accounts were compromised in a single wave: stored payment methods exposed, gift card balances drained, personal details harvested. The company had to force logouts, reset passwords, and restore balances. The victims' only mistake was reusing one password from a forgotten forum account.

The Lesson

Every breach of any site you've ever joined is a breach of you — everywhere that password works. Use a password manager with unique passwords, and turn on two-factor authentication for anything holding money. Your 2019 forum password should not be guarding your wallet.

FAFO Index

8/10 — one lazy habit, every account at risk.

Bottom Line

Reuse a password and you're only as secure as the weakest site you've ever joined.

Seen something like this?

Report it anonymously — submissions are rewritten and anonymized before publishing.

Report incident

MORE FAFO STORIES

The $390,000 'Antivirus Refund

phone scam mistakes to avoid

The AWS Key Committed to GitHub

AWS key leaked mistakes to avoid

The 'Dream Job' That Asked for a Deposit

online job scam mistakes to avoid