Sunday, June 21, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » The Threat of Compromised Passwords

SBN

The Threat of Compromised Passwords

by Enzoic on June 9, 2020

Over time passwords have become a ubiquitous part of our digital activities. They’re something we expect to create and manage for all of our accounts, and yet with all of our online accounts, having unique passwords can be difficult. Despite this, they remain the most common way of locking unauthorized persons out of our systems and away from our sensitive data. The data held in our digital accounts is of great value to threat actors everywhere. This is why attackers are perfecting their techniques and using sophisticated tactics to conduct account takeover attacks using compromised passwords.

Compromised passwords pose a significant threat to the security of organizations and individuals and as time ticks on, the list of exposed passwords continues to grow at an alarming rate. In fact, according to the Verizon Data Breach report, 81% of hacking-related breaches leveraged either stolen and/or weak passwords.

The Impact of Compromised Passwords

We’re currently experiencing a data breach epidemic. According to the 2019 MidYear QuickView Data Breach Report, 4.1 million records were compromised in the first six months of 2019. According to Help Net Security, in 2019, a total of 7,098 reported breaches exposed 15.1 billion records.

Compromised passwords are a crucial part of the data breach epidemic. One study found that 90% of respondents have experienced the effects of a data breach resulting from a compromised password. Compromised passwords impact both individuals and organizations, so in this section, we’ll be focusing on both to get a full picture of the true impact.

Reputation and Financial Loss

Threat Actors can potentially gain access to and the organization’s IT systems and steal sensitive data by utilizing compromised passwords. Even if they don’t use a compromised password to gain access to the system, they can often come away with many thousands or millions of these passwords after a successful data breach. This can have a significant impact on a company’s reputation and result in major financial loss, both in terms of fixing the damage and in the loss of future revenue.

The financial impact of a data breach due to compromised passwords can devastate companies of all sizes but can be particularly severe for small and medium-sized businesses (SMEs). SMEs are often less likely to have robust cybersecurity policies that protect against the use of already compromised passwords and they are also less likely to believe their company will be on the radar for Threat Actors. According to the IBM Cost of a Data Breach Report, the average total cost of a data breach globally is USD 3.92 million. However, the US is the most expensive country to have a data breach, where the average cost rises to USD 8.19 million.

Loss of Data

According to the same IBM report, 25,575 records on average are lost in a data breach. Once this data is out there it’s incredibly difficult (if not impossible) to regain control of it.

Recent Examples of Prominent Data Breaches Involving Exposed Passwords

  • In February 2018 Under Armour’s popular fitness app MyFitnessPal was breached, resulting in 150 million usernames, email addresses, and passwords being exposed.
  • In October 2016 the FriendFinder Network, a network dedicated to adult content and communication services was targeted by Threat Actors. In the attack, more than 412.2 million accounts were exposed and names, email addresses, and passwords were put in the hands of Threat Actors. The exposed passwords were protected using the notoriously weak SHA-1 hashing algorithm which meant that the vast majority of passwords were cracked in very little time.
  • In 2016, Uber was hit with a data breach that exposed over 57 million user and driver records. Threat Actors were able to gain access to these records by gaining access to Uber’s GitHub account, where they then found the username and password for Uber’s AWS account. So, in this case, according to CSO Online, a compromised password directly led to millions of user records being exposed.

The Growing Threat and Looking to The Future

While passwords remain a popular way of securing data, they are far from perfect.

“The password is by far the weakest link in cybersecurity today.” Michael Chertoff, former head of Homeland Security

This has led some security professionals to suggest other ways of securing our data, some of which are gaining traction. Fingerprint, Iris, or other biometric readers are becoming more common, as are persona-based authentication methods (relying on your online behavior and geographical location), and authentication keys. However, none of these options have managed to replace the traditional password and each comes with their own pros and cons.

Organizations cannot move away from the password anytime soon because of all the new authentication methods, the password is still the back-up factor and there is not a ubiquitously trusted alternative yet. This means we’re forced to come up with new and creative ways to defend our data while using passwords. Exposed password screening and compromised credential screening is starting to become more widely used due to its ability to alert users when their password has been exposed and is therefore no longer safe to use.

The post The Threat of Compromised Passwords appeared first on Enzoic.


Recent Articles By Author
  • The Login Was the Breach
  • Summer Is Prime Time for Account Takeover
  • The 2026 Verizon DBIR
More from Enzoic

*** This is a Security Bloggers Network syndicated blog from Enzoic authored by Enzoic. Read the original post at: https://www.enzoic.com/the-threat-of-compromised-passwords/

June 9, 2020June 9, 2020 Enzoic account takeover, Compromised Password Screening, credential screening, exposed passwords
  • ← COVID-19 Is Breeding More Cyberattacks: Here’s How to Contain Them
  • Web scammers are using the COVID-19 crisis to attack your customers with Magecart and other client-side exploits →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

3 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

4 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

4 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
France to Stop Certifying Products Without Quantum-Safe Encryption in 2027
Trying to Control AI is Like Holding Sand
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
Kodak Confirms Data Breach Claimed by ShinyHunters Extortion Gang
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
973 MCP Packages, 71% Single-Maintainer: A Practitioner’s Guide to AI Developer Security
Novo Nordisk Reports Cybersecurity Breach Affecting Clinical Trial Patients

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | 3 days ago 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 2 days ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | 3 days ago 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 4 days ago 0

Security Humor

Fortinet® Follies

Fortinet® Follies

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The Dangers of Open Source Software and Best Practices for Securing Code
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.