惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
The GitHub Blog
The GitHub Blog
月光博客
月光博客
T
Tailwind CSS Blog
小众软件
小众软件
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
B
Blog RSS Feed
博客园 - 司徒正美
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
博客园 - Franky
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Azure Blog
Microsoft Azure Blog
T
The Blog of Author Tim Ferriss
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
My Password Has Been Stolen—What Happens Next?
Davey Winder · 2026-05-08 · via Forbes - Innovation
Human hand holding an asterisk from the password.

What happens when your password is stolen?

getty

Now that World Password Day has been and gone, credential theft will continue as before. Infostealers will continue stealing, hackers will continue compromising, and accounts will be raided for whatever value they contain. But have you ever stopped to think what actually happens after your password gets stolen? The security boffins at Comparitech, after analyzing more than 447,000 credential “leaks, dumps, and breach threads” across four cybercriminal forums containing a total of 1.1 million stolen user records dating from 2013 to 2026, have revealed the answer.

ForbesMicrosoft Says Edge Password Security Vulnerability Is ‘By Design’—Is It Time To Switch To Chrome?By Davey Winder

My Password Has Been Compromised—Now What Happens?

If you have ever found yourself in the nightmare scenario where the password to one of your accounts has been compromised, you will know all too well the sense of panic and hopelessness that immediately washes over you. And, sad to say, the chances are pretty high that you have. I recently reported that password theft had surged across 2025 with 2.8 billion credentials found to be compromised. With newly published warnings that Microsoft Edge loads your passwords in plain text in the browser process memory, and Amazon being weaponized with the use of stolen credentials, the new Comparitech analysis could not have come at a better time. Taking the format of a statistical analysis of the dark web’s credential pipeline, the report answers the question: Where do leaked passwords end up?

According to Paul Bischoff, author of the report write-up for Comparitech, the researchers, including Mantas Sasnauskas, analyzed databases from four major cybercrime forums to uncover just how stolen passwords are “accessed, traded, and aggregated before being utilized in credential-stuffing campaigns, ransomware attacks, business email compromise, and so on.”

Although a five-stage password supply chain was composed as a result of the analysis, the first stage, origin, is a moot point, as it involves things that have already happened before the credentials arrive on a cybercrime forum. What we do know is that infostealer malware and data breaches are the primary sources of compromise.As, indeed, is the last: end use details what the credentials will be used for in the future, such as breaches, ransomware and so on. The remaining middle stages, defined as wholesale, trade and aggregation, provide the heart of the analysis.

MORE FOR YOU

Wholesale is where the stolen passwords are brokered, perfectly demonstrating the supply side of the password economy. One Russian-language cybercrime forum, RAMP, for example, was selling pre-authenticated initial access to corporate networks using stolen credentials.

Next up is trade, where, unsurprisingly, “compromised data is posted, sold, traded, and reposted across hacker forums, both as free downloads and inside paid marketplaces,” Bischoff said.

Then comes aggregation with compromised passwords and other credentials being fed into so-called combolists, the most valuable of which have been deduplicated across the breaches concerned, which hold value for attackers. The reason? Because they can be used to leverage credential-stuffing threat campaigns.

ForbesCritical New Google Security Update—127 Chrome Security Vulnerabilities ConfirmedBy Davey Winder

How To Protect Your Password From Compromise

With the Comparitech analysis providing the answers to what happens after your password has been compromised, one question remains hanging in the cyber wind: how can you protect it from being stolen in the first place? The simple answer is by not using one to start with. Switch to passkeys wherever possible, as these are way more secure and much, much harder to compromise. Apart from that, never share your password between sites and services, as this leaves them all vulnerable if just one is breached. Use a password manager for your password and passkey needs. This will allow you to use strong and unique passwords without needing to remember them all. Also, always employ two-factor authentication where available, as this adds another layer between your account and anyone in possession of your stolen password.