Maybe you got one of those "we've had a security incident" emails from a site you'd half forgotten about. Maybe Microsoft or Google warned you about a sign-in from a country you've never been to. Or maybe nothing has happened yet, and you're wondering whether a password you used years ago is still out there.
It probably is. Passwords stolen in old breaches get bundled into huge lists and sold, and criminals run those lists through software that tries each email-and-password pair against Microsoft 365, Google, banks and online shops, thousands of attempts a minute. It's called credential stuffing, and it only works when someone has used the same password in more than one place. Here's how to find out whether you're exposed and how to shut it down.
The quick version
- Check your email addresses on Have I Been Pwned.
- Change any password that has been in a breach, and every account that shares it, starting with email.
- Use a password manager so every account gets its own password.
- Turn on MFA everywhere, and move to passkeys for email and banking.
- Look at recent sign-ins to your Microsoft 365 or Google Workspace accounts for anything you don't recognize.
How it works, briefly
When a company is breached, the stolen usernames and passwords end up on criminal marketplaces as "combo lists." They don't expire. Adobe's 2013 breach exposed about 153 million accounts, and that data still circulates more than a decade later.
The attacker doesn't guess. They take a password that worked on some other site and try it on yours, using automated tools that spread the attempts across thousands of home internet connections so the traffic doesn't look like one attacker. If you reused the password, they're in.
The prize for most small businesses is the email account. From inside a mailbox, an attacker can read invoices and banking details, send messages as you, reset passwords on anything tied to that address, and set up hidden forwarding rules to keep watching after you change your password. That's the usual first step of business email compromise. Verizon's 2024 Data Breach Investigations Report found stolen credentials involved in about a third of breaches over the past ten years.
Check yours
Have your email addresses been in a breach?
- Go to haveibeenpwned.com and enter your business email address.
- Repeat for your personal address, and for each employee's work address (or ask them to do it).
- For every breach listed, note the site and what was exposed.
If a breach included passwords, assume that password is known, even if you changed it on that site at the time. Then ask: did I use it, or something close to it, anywhere else?
Are any of your saved passwords already exposed?
If you save passwords in Chrome or your Google account, run Google's Password Checkup: in Chrome, open the More menu, then Passwords and autofill > Google Password Manager > Checkup, or go to passwords.google.com and choose Go to Password Checkup. It flags passwords that are compromised, reused or weak. Most password managers (Bitwarden, 1Password and others) have a similar breach and reuse report.
Has anyone signed in who shouldn't have?
Microsoft 365. In the Microsoft Entra admin center (what used to be the Azure Active Directory portal), go to Entra ID > Monitoring & health > Sign-in logs (Microsoft's guide). How far back you can look depends on your plan: seven days on Business Basic and Standard, 30 days on Business Premium. There's also a Risky sign-ins report under ID Protection, but without a Microsoft Entra ID P2 license it only shows limited information, with no risk level or detail. For a small business, the plain sign-in log is the one to read.
Google Workspace. In the Google Admin console, go to Reporting > Audit and investigation > User log events (Google's guide). It shows the last seven days by default, and you can filter for sign-ins Google marked as suspicious.
Each person can also check their own account: mysignins.microsoft.com for Microsoft 365, or the Security page of a Google Account under recent security activity.
What to look for:
- Sign-ins from countries or cities where nobody on your team works or travels.
- A string of failed sign-ins followed by a successful one.
- Sign-ins at hours nobody was working.
- A successful sign-in followed soon after by a new inbox rule that forwards or moves mail.
If you find any of these, change the password, sign the account out of all sessions, remove any inbox rules you didn't create, and get help if you're not sure what was accessed.
Fix it
Get a password manager
A password manager is the only practical way to give every account a different password. It creates long random passwords, stores them encrypted and fills them in for you, so you only remember one strong master password. Bitwarden has a good free tier and inexpensive business plans with shared vaults; 1Password is another solid choice.
Change reused passwords, most important first
Use the manager to replace any password that appeared in a breach or is shared between accounts. Start with:
- Business email (Microsoft 365 or Google Workspace), because it can reset everything else.
- Online banking and payment accounts.
- Your website, domain registrar and online shop admin logins.
- Cloud storage and any software holding client data.
Longer beats clever. NIST's current password guidance favors length over complexity rules, and a random 16-to-20 character password from a manager is far stronger than "Summer2026!".
Turn on MFA, then move to passkeys
MFA (multi-factor authentication) means a stolen password alone isn't enough. CISA puts it near the top of its list for good reason. Turn it on for email first, then banking, then everything else that offers it.
Prefer an authenticator app over text-message codes, which can be stolen through a SIM swap. Better still, use passkeys where you can. A passkey replaces the password with a cryptographic key that stays on your phone or laptop and unlocks with your fingerprint, face or PIN. With no password to reuse, there's nothing for a combo list to stuff. Microsoft 365 and Google Workspace both support them, and Microsoft has been moving SMS and voice users onto passkeys since September 2026. One caution: an attacker who has your password will try to wear you down with repeated sign-in prompts instead, so read our guide to MFA fatigue attacks and passkeys for how to set them up so that doesn't work.
Keep it from happening again
- One rule for the team: every work account gets its own password, stored in the company password manager. Never reuse a work password on a personal site.
- Turn on sign-in alerts where your services offer them, and send them somewhere the account owner will actually see.
- Block the old sign-in methods attackers use to skip MFA. In Microsoft 365, Security Defaults or a Conditional Access policy does this; our Microsoft 365 security settings guide covers it.
- Re-check Have I Been Pwned now and then, or sign up for its free notifications so you hear about new breaches involving your addresses.
When to call someone
- You found a sign-in you can't explain, especially one followed by new inbox rules.
- Someone outside the business received an email "from" you that you didn't send.
- You need to roll out a password manager and MFA to a team and don't know where to start.
If you'd like help with any of that, our cybersecurity service covers it.




