●  Melbourne-based · Local support you can actually reach
← All insights
Cyber security

Your old passwords are already on the dark web. Here's what that means

A password you set years ago, for some website you’ve probably forgotten you signed up to, is most likely sitting in a database that criminals can search right now. Not because you did anything careless. Because a company you trusted got breached, your details were in it, and that data doesn’t get deleted. It gets collected, traded, and reused.

This is one of the most misunderstood risks in cyber security, because it doesn’t feel like an attack. Nobody picks a lock. Someone just logs in as you, with a password you handed over to a different site years ago. Here’s how that works, and why it matters more than you’d think.

You don’t get hacked, you get logged into

When a big company suffers a breach, the email addresses and passwords from it end up in enormous collected lists. Attackers take those username and password pairs and try them, automatically, across hundreds of other services: email, banking, work logins. The technique even has a dull name, credential stuffing, and it works for one reason. People reuse passwords.

If the password from your old breached account is the same one you use for your work email, the attacker doesn’t need to be clever. They just walk in the front door with a key you already gave away. It’s cheap, it’s automated, and it runs constantly. The Australian Signals Directorate now fields a cybercrime report about every six minutes (ASD Annual Cyber Threat Report 2024 to 25), and a slice of those start exactly here.

Why this catches small businesses out

The weak point is usually the overlap between personal and work life. A staff member uses the same favourite password for a shopping site, a forum, and their work account. The shopping site gets breached three years ago, nobody notices, and the leaked password is still the one guarding your business email today. One old, unrelated leak quietly becomes a way into your company.

What actually fixes it

The good news is the fixes are simple and they stack. Do these and credential stuffing mostly stops working on you:

  • Stop reusing passwords. This is the whole game. A password manager makes it effortless, because it remembers a different, strong password for every account so you don’t have to. You learn one master password and it handles the rest.
  • Turn on multi-factor authentication everywhere it’s offered. Even if a password leaks, the attacker still hits a second locked door. This single step defeats most reused-password attacks outright.
  • Find out what’s already out there. You can check whether your email address appears in known breaches, and a proper dark-web check goes further. You can’t fix exposure you can’t see, and most people have more of it than they expect.
  • Use long passphrases, and drop the rotation theatre. A long, unique passphrase beats a short complicated one. And the old habit of forcing everyone to change passwords every 90 days is now considered counterproductive, because it just pushes people towards predictable patterns. Unique plus multi-factor beats frequent changes.

Why we check this for clients

Looking after a business’s security properly means watching for credentials that have already leaked, not just guarding the front door. If a staff member’s work email turns up in a fresh breach dump, that’s something you want to know about today, while you can still change the password, not after someone’s used it. You can’t act on exposure you never see, which is exactly why seeing it is part of the job.

The takeaway

Your old passwords being out there isn’t a sign you did something wrong, and it isn’t something you can undo. What you can do is make those leaked passwords useless: stop reusing them, turn on multi-factor authentication, and find out what’s already exposed. Do that, and the database with your old password in it becomes a piece of trivia instead of a way in.

Want to know what's already exposed?

Book a free, no-obligation security check. We'll show you whether your details are already circulating, and the simple changes that lock the door.

Actively managed IT

Want your protection this clear?

Every article here comes from how we look after Melbourne businesses every day. See where your business stands, and what “actively managed” really feels like.

Book a free assessment

Or explore cyber security in Melbourne.