The Hacker Did Not Guess the Password. He Already Knew It
Last week, we worked with a customer whose Microsoft 365 account had been compromised.
We immediately revoked all active sessions and reset the account password. That should have removed the attacker and stopped any unauthorized access.
There was one major problem: multifactor authentication was not enabled.
We recommended turning it on, but the customer initially refused because he felt it would be a hassle. Like many people, he saw the additional verification step as an inconvenience rather than an important layer of protection.
The next day, we checked the account again.
Someone had successfully logged in from the same foreign country as the original suspicious activity.
At that point, we asked the customer a simple question: “Is the new password similar to another password you commonly use?”
His answer was yes.
The attacker had not broken through some advanced security system. They had tried another password the customer regularly used, and it worked.
We helped the customer create a new, longer, and unique password. We also convinced him to enable multifactor authentication. After those changes were made, the suspicious login activity stopped.
The Real Problem Was Password Reuse
Further investigation revealed that the customer’s information had appeared in multiple previous data breaches.
The attacker likely already had access to one or more older passwords connected to the customer’s email address. They tested those passwords against the Microsoft 365 account.
This technique is known as credential stuffing.
Attackers take stolen usernames and passwords from one breach and try them on other websites and services. They know many people reuse the same two or three passwords across their email, banking, shopping, social media, and business accounts.
In this case, the attacker got lucky twice because the customer repeatedly used a small collection of common passwords.
The attacker did not need to be a technical genius. The customer’s password habits did most of the work for them.
MFA Is Less Hassle Than an Incident
Multifactor authentication may add a few seconds to the login process, but recovering from a compromised account can take hours or days.
A stolen Microsoft 365 account can expose email conversations, customer information, invoices, cloud files, contacts, and internal business communications. Attackers may also use the legitimate account to send fraudulent payment requests or phishing messages to employees and customers.
That is far more inconvenient than approving a notification on your phone.
A password should be long, unique, and used for only one account. A password manager can create and securely store different passwords so users do not have to remember them all.
MFA should also be treated as a basic requirement, not an optional feature.
The Lesson
The customer believed changing the password would solve the problem. It did not, because the replacement password was still part of the same reused password pattern.
The suspicious activity stopped only after the customer used a truly unique password and enabled MFA.
Cybercriminals do not always have to hack their way into an account. Sometimes, they reuse information that has already been stolen.
Using the same password everywhere may feel convenient, right up until an attacker finds it.




