Cyber Smart Week is a reminder that cyber security is everyone's responsibility.

As part of Cyber Smart Week 2026, we're sharing a series of articles from CyberCX, Enable's cyber security partner, covering practical ways to stay safer online. This article was provided by CyberCX and offers expert insights into an important cyber security topic.

Back in 2011, a guy we’ll call Mike signed up to a car forum. He picked a password he liked, something memorable, something he could reuse, and didn’t think about it again. Over the next decade he used that same password, or a small variation of it, for his email, his online shopping, and eventually his banking. Why not? It was a good password. Easy to remember, hard to guess.

In 2019, that car forum got hacked. Mike never even heard about it. The forum was long dead, the breach barely made the news, and his details, his email address and that password, ended up in a giant list traded among criminals. That’s where the trouble started, years after he’d forgotten the forum existed.

Here’s how it unraveled. Attackers don’t sit there typing passwords. They take leaked email-and-password pairs and feed them automatically into hundreds of popular sites, betting that people reuse passwords. They were right about Mike. The combination unlocked his personal email. Once they were in his email, they owned everything, because email is the master key to your whole online life.

Once attackers have your email, everything changes

From his inbox they searched for “welcome” and “reset password” emails to see what accounts he had. They found his Trade Me, requested a password reset, clicked the link that arrived in the email they now controlled, and took it over. Then they went for his bank. The bank’s account recovery process sent a verification link to, you guessed it, his email. By the time Mike noticed anything was wrong, money was gone and he was locked out of his own accounts.

Mike didn’t do anything obviously stupid. He didn’t fall for a dodgy link or hand his details to a stranger. His only mistake was using one password in more than one place. That single decision, made years earlier, was enough. 

The good news: the fix is simple

The fix is genuinely simple, and it removes most of this risk in an afternoon. First, check whether your details are already floating around: the free site haveibeenpwned.com lets you type in your email and tells you which breaches it’s appeared in. It’s run by a well-respected security researcher and it doesn’t store what you type. Most people are shocked at how many breaches they’re already in. Second, get a password manager, there are reputable free and paid ones, and let it create a long, random, different password for every site. You only have to remember one master password, it remembers the rest. A unique password per site means that even when a site gets breached, the damage stops at that one site. 

And this is exactly why it matters at work too. Reused and previously-breached passwords are one of the most common ways attackers get their first foothold inside an organisation. They aren’t hammering at the front door, they’re quietly trying passwords that leaked from somewhere else and hoping someone reused theirs. Using a unique password for your work accounts, and never reusing a work password on a personal site, or the other way around, is one of the highest-value habits you have. A clever password you reuse everywhere is far weaker than a boring random one you only use once. 

What to actually do ✅

  • Use a password manager so every account gets its own long, random password. 

  • Never reuse a password, especially not across personal and work accounts. 

  • Unique-per-site beats clever-but-reused every single time.

We'll be sharing more expert insights from CyberCX and other cyber security topics throughout the year, so check back regularly for new articles.