{"id":21734,"date":"2025-06-19T07:26:32","date_gmt":"2025-06-19T05:26:32","guid":{"rendered":"https:\/\/www.curiaweb.ch\/?p=21734"},"modified":"2026-08-23T09:54:09","modified_gmt":"2026-08-23T07:54:09","slug":"milliarden-passwoerter-im-umlauf-was-jetzt-tun","status":"publish","type":"post","link":"https:\/\/www.curiaweb.ch\/en\/milliarden-passwoerter-im-umlauf-was-jetzt-tun\/","title":{"rendered":"Billions of compromised passwords in circulation \u2013 what now?"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Billions of compromised credentials are circulating on the internet. They originate from data leaks, phishing attacks, infostealer malware, and other attacks, and are sometimes combined into massive data collections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2025, a particular amount of attention was received by a collection of around <strong>16 billion login records<\/strong>. However, this was neither a single new attack nor 16 billion different affected individuals. The data came from various sources and also contained duplicates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For users and companies, the exact number is secondary anyway. The decisive factor is: <strong>Stolen credentials can still be used for attacks \u2013 especially when passwords are reused.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where do the compromised credentials originate?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Such collections of passwords and credentials usually do not come from a single major hacker attack. Instead, data from various sources is collected and later combined.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Typical sources are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data leaks at online services and companies<\/li>\n\n\n\n<li>Phishing attacks on users<\/li>\n\n\n\n<li>Infostealer malware on computers and other end devices<\/li>\n\n\n\n<li>stolen browser and login credentials<\/li>\n\n\n\n<li>older password collections and databases<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Particularly problematic are so-called <strong>Infostealer<\/strong>. Among other things, these malicious programs attempt to read access credentials stored in the browser or on the device and transmit them to attackers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why reused passwords are so dangerous<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A stolen password does not only have to be dangerous for the service originally affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Anyone who uses the same password for multiple accounts may turn a single data breach into a problem for numerous other logins.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers can automatically try known combinations of email address, username, and password on other services. This attack method is called <strong>Credential Stuffing<\/strong> referred to as.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If, for example, the same password works for the online shop, the cloud service, and the email account, a single compromised access point can have far-reaching consequences.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why the email account should be particularly protected<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The email account is one of the most important digital access points of all. It is used to reset passwords, send confirmations, and exchange both business and personal information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A compromised email account can, among other things:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>enable access to additional user accounts,<\/li>\n\n\n\n<li>disclose confidential messages and documents,<\/li>\n\n\n\n<li>used for phishing and identity theft,<\/li>\n\n\n\n<li>send fake messages on behalf of the affected person.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Particularly for companies, this can quickly become a significant security problem. In addition to secure access data, spam, phishing, and malware protection therefore also play an important role. You can find out more about this at our <a href=\"\/en\/email-services\/\"><strong>Email security solutions<\/strong><\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What you should do now, specifically<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You don't have to wait for the next report of a major data breach. With a few basic measures, the risk of compromised accounts can be significantly reduced.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Use a separate password for each service<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Never use the same password for multiple important accounts. Email, hosting, cloud services, payment providers, and administrative access in particular should each have their own strong password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can create a strong password, for example, with our free <a href=\"\/en\/password-generator\/\"><strong>Password generator<\/strong><\/a> create.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Use password manager<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A password manager can generate long and unique passwords and manage them securely. This means you do not have to remember a complex password for every service.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Enable two-factor authentication<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable two-factor or multi-factor authentication if possible. In addition to the password, another factor is then required for login.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because of this, a stolen password alone is often no longer enough for an attacker to gain access to the account.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Check if your own email address appears in a data leak<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The service <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Have I Been Pwned<\/strong><\/a> enables checking whether an email address was found in known data breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A match does not automatically mean that a current password is known. However, it is a clear reason to check the affected accounts and access credentials.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Use passkeys when they are offered<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">More and more services are supporting so-called <strong>Passkeys<\/strong>. In the process, the traditional password-based login is replaced by a cryptographic authentication method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Passkeys are significantly more robust, particularly against classic phishing attacks, and avoid problems such as weak or reused passwords.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Also secure hosting and administration access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For companies, not only personal user accounts are relevant. Access to WordPress, hosting control panels, domain management, FTP\/SFTP, and business email accounts should also be given special protection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Administrator accounts should only be given to individuals who actually need them. Use individual credentials, enable available multi-factor authentication, and remove user accounts that are no longer needed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: A password alone is no longer enough today<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Billions of compromised access credentials show how important a well-thought-out security concept has become. The crucial factor is not so much the spectacular number of a single data discovery as the proper handling of one's own access credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Unique passwords, a password manager, multi-factor authentication, and modern methods such as passkeys<\/strong> significantly complicate the misuse of stolen credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For companies, an additional layer comes into play: hosting, websites, and email systems must also be properly secured and continuously maintained. Security is therefore not a one-time setup, but an ongoing process.<\/p>","protected":false},"excerpt":{"rendered":"<p>Billions of compromised credentials are circulating on the internet. Learn how to better protect passwords, email accounts, and corporate access from abuse with simple measures.<\/p>","protected":false},"author":1,"featured_media":21739,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[67],"tags":[],"class_list":["post-21734","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-sicherheit"],"_links":{"self":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/posts\/21734","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/comments?post=21734"}],"version-history":[{"count":2,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/posts\/21734\/revisions"}],"predecessor-version":[{"id":21738,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/posts\/21734\/revisions\/21738"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/media\/21739"}],"wp:attachment":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/media?parent=21734"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/categories?post=21734"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/tags?post=21734"}],"curies":[{"name":"WP","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}