Password Recycling: The Most Expensive Habit in Your Company

BACS dedicated a weekly review in late April to password reuse, with the message that anyone who uses the same password across multiple services risks having a single data theft compromise all their accounts. Sounds obvious, but when you look at the numbers you realise that most organisations still have not got the memo.

Credential stuffing, meaning the automated abuse of stolen credentials, is not some exotic threat but one of the most common attack vectors out there, and one that a surprising number of companies continue to shrug off.

Scale of the problem

Akamai recorded roughly 193 billion credential stuffing attempts worldwide last year. These are not targeted attacks by individual hackers sitting at their keyboards guessing passwords, but fully automated scripts hammering stolen username-password combinations against thousands of websites around the clock, seven days a week.

The data comes from a pool of over 24 billion stolen credential sets currently floating around the dark web. Every major leak of the past decade has fed that pool (LinkedIn, Adobe, Dropbox, Yahoo and dozens more), and the uncomfortable part is that this data does not expire but gets traded, merged, enriched and loaded into attack tools that anyone can buy.

Verizon pegs credential stuffing at 22 percent of all data breaches, which means nearly one in four breaches starts with someone reusing a password. IBM puts the average cost of such an incident at 4.67 million dollars.

Why the password problem persists

Most people know they should not reuse passwords, but they do it anyway. Studies show over 60 percent of users have at least one password doing double duty across services, and for personal accounts the rate is even higher.

But can you really blame them? The average professional juggles over 100 online accounts, and keeping a unique strong password for every single one while actually remembering them is flat out unrealistic without tools. That is where the real problem lies: it is not a knowledge gap but a tools-and-process gap.

Credential stuffing and SMEs

Here is a scenario we see with clients more often than we would like: an employee uses their personal email password for the company login too. Their personal provider gets breached. Within hours those credentials are in a database that attackers test against corporate logins; VPN, Microsoft 365, CRM, whatever uses the same username and password is compromised.

Large enterprises with dedicated security teams and identity management systems can handle this. But an SME with 30 staff where the IT person also does the bookkeeping faces a very different situation, because there is no SIEM catching unusual logins and often not even a consistent password policy.

Three measures

First, and this is the big one: roll out a password manager for every employee. Bitwarden, 1Password, KeePass, honestly the specific tool is secondary. What matters is making it mandatory, not optional. The cost is a few francs per person per month, and the alternative costs orders of magnitude more when things go wrong.

Second: multi-factor authentication (MFA) on everything that supports it. Microsoft 365, VPN, banking, cloud services. MFA makes stolen passwords largely worthless; bypass methods do exist and attackers use them, but it raises the bar dramatically. Setup takes minutes per service.

Third: check whether your company email addresses already appear in known data leaks. Have I Been Pwned is free and gives you answers instantly. If you show up there, change every affected password right away and this time make it unique.

The structural problem

Password reuse is not really a user problem at its core but an organisational one. As long as a company does not provide password managers, does not mandate MFA and does not run regular checks, password recycling will remain the default. Blaming employees is convenient but solves nothing.

The BACS warning is justified, but warnings alone do not change behaviour unless they are translated into concrete action. The good news is that the three measures above cost less than half a consulting day combined, yet they close an attack vector responsible for nearly a quarter of all data breaches…

We help SMEs roll out password management and MFA, including staff training so it actually sticks in daily work. And in our penetration tests we routinely check whether credential stuffing would succeed against your systems. Get in touch if you want to know where you stand.

Sources: BACS Weekly Review KW 16, Verizon Data Breach Investigations Report 2025, Have I Been Pwned, Akamai State of the Internet Report