How to Get Breached, Step 2: Use the Same Password Everywhere. It’s Easier to Remember!
One password for email, payroll, the bank, and that forum you joined in 2014. What could go wrong?
When one password opens email, banking, and payroll, a single breach on any website can unlock your entire business.
Welcome back to our guide to getting breached. This week’s tip is a real time-saver: pick one good password and use it for everything. Email, payroll, the bank, the vendor portal, the site where you ordered the office chairs. You will never click Forgot Password again, and neither will the criminal who bought your login in a leaked list last year.
If you would rather keep your business out of the breach column, read on.
Why password reuse is a business problem
Attackers rarely guess passwords anymore. They collect them. When a website is breached, the usernames and passwords stored there get traded and sold. Automated tools then try those same combinations against thousands of other services: Microsoft 365, banks, payroll providers, accounting software. This is called credential stuffing, and it only works because people reuse passwords.
That means your security depends on the weakest website any employee has ever signed up for with a work password.
A hypothetical example
Picture a made-up 15-person distributor. The office manager uses one password for her work email and for a home decor site she shopped at years ago. The retailer is breached. Months later, an automated tool tries her email address and that password against Microsoft 365, and it works. The attacker reads her inbox quietly for two weeks, learns how invoices get approved, then emails a customer from her real account with new bank details for the next payment.
There was no malware and no alarm. The only thing the attacker needed was one reused password.
Action steps for you and your IT team
Roll out a business password manager. Every employee gets an account, and every login gets a long, unique, generated password. Staff remember one strong passphrase.
Turn on multi-factor authentication (MFA). Start with email, banking, payroll, and remote access. MFA does not make reuse safe, but it keeps many stolen passwords from being enough.
Check for breached passwords. Have IT screen new passwords against lists of known compromised ones, which current NIST guidance calls for, and monitor for company credentials in new leaks. A free service such as Have I Been Pwned shows whether an email address appears in known breaches.
Change passwords on evidence, not on a calendar. Forced 90-day changes produce Spring2026! followed by Summer2026!. Favor length over odd symbols.
Separate work from personal. Work email addresses and work passwords stay out of shopping, streaming, and social accounts.
Retire shared logins where you can. If a shared account is unavoidable, keep it in the password manager’s shared vault, protect it with MFA, and change it whenever someone leaves.
Put it in writing. A one-page password policy gives you something to train on and enforce.
Questions your customers may ask you
Q: How do you protect the accounts that hold our information? A: Every employee uses a unique password for each system, stored in a password manager, with MFA on anything that touches customer data.
Q: What happens if an employee’s password shows up in a breach? A: We monitor for exposed credentials. When one appears, the password is changed right away and we review the account for unusual sign-ins.
Q: Isn’t a password manager putting all your eggs in one basket? A: It is one well-guarded basket instead of dozens of weak ones. The vault is encrypted and protected by a strong passphrase plus MFA.
Q: Do your staff share logins? A: Each person signs in as themselves wherever the system allows, so we can see who did what and remove access the day someone leaves.
How Farmhouse Networking can help
Farmhouse Networking helps small and mid-sized businesses replace password habits with a system. We help you choose and roll out a business password manager, then train your staff so it gets used. Our dark web monitoring alerts us when your company’s credentials appear in a leak. In Microsoft 365, we configure banned-password protection, multi-factor authentication, and Conditional Access so a stolen password alone will not open the door. Our staff is 100% U.S.-based, and a live person answers the phone.
Is one reused password all that stands between you and a breach?
Email support@farmhousenetworking.com to request a free breach-readiness review. We will look at how your business handles passwords, MFA, and exposed credentials, then give you a plain-language list of what to fix first.
Next week: How to Get Breached, Step 3: Click Every Link. What’s the Worst That Could Happen?
And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say, “They share freely and give generously to the poor. Their good deeds will be remembered forever.” For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.