Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

One account, one password

Protect important accounts with unique passwords you do not have to memorise.

Users of online and financial servicesAbout 5 minutes of reading + 3 questions
Start with the example Need help now?

What you will learn

  • Use a long, unique password for every account.
  • Protect email and payment accounts first.
  • Know what to change when a password is exposed.

Practice example

One password is exposed. How many accounts are at risk?

A shop where you have an account reports a data breach. You use the same password for shopping, email and a social network.

  1. 01A reused password
  2. 02Email connects accounts
Fictional training scenario.
Show the example explanation
A reused password
An attacker may try the same credentials on other services.
Email connects accounts
Email often controls password resets elsewhere, so it deserves particular attention.

Why email takes priority

Email often receives links for changing passwords on other accounts. Someone with access may read messages, impersonate you and attempt to take over connected services. Your email password therefore needs to be separate, even if you already use an extra sign-in check.

Make passwords you can maintain

  1. Give every account a long, unique password. Names, dates and small variations on one password are poor patterns.
  2. Use a password manager to generate and store passwords. On a work device, use a solution approved by your organisation.
  3. Protect the manager with a strong master password and an additional factor where supported. Check how to regain access if you lose your device.
  4. Do not save passwords in the browser on a public computer or someone else’s device.

If a service offers a passkey, consider that option using its official instructions. For accounts that use passwords, a unique password and 2FA remain important.

If a password has already been exposed

From a trusted device, open the service’s official app or website. Change the affected password and every account where it was reused, prioritising email and financial services. Review active sign-ins and remove unfamiliar sessions according to the provider’s instructions.

If you cannot sign in or notice unfamiliar changes, follow the account recovery guide. If banking information is exposed or you see a suspicious transaction, contact your bank immediately through an official channel. Do not include passwords or one-time codes in an incident report.

One change to make today

Cannot find the password control? Open the steps for your Google, Microsoft, Apple or other supported account.

Check that your email has a separate password and a second factor enabled. Then work through your other important accounts one at a time.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A shop password has been exposed. You also use it for email. What should you do?

Why does this matter? Reusing a password links the security of multiple accounts: a shop breach can also endanger email. Email access may then provide password-reset routes for other services.

  1. Change it only at the shop.

    The same password could still unlock other accounts. Changing it on one website does not change copies of the same password that remain valid elsewhere.

  2. Use a trusted device to change it everywhere it was reused, prioritising email.Correct answer

    This limits connected harm. Give each account its own password. Prioritising email reduces the risk of its access being used to take over connected accounts as well.

  3. Wait for an unfamiliar sign-in.

    An unfamiliar sign-in may mean harm has already occurred. Waiting for a visible sign does not change the fact that someone may already have the detail needed to attempt a sign-in.

How can you maintain many different passwords?

Why does this matter? When many passwords are hard to remember, reusing them or making predictable variations is tempting. A manager helps keep them different, but its access and recovery also need protection.

  1. Use a password manager, protect access to it and check its recovery options.Correct answer

    A manager can generate and store a separate password for each service. This reduces the need for reuse, while protecting the manager limits access to the whole collection.

  2. Add each website name to the same password.

    Predictable variations make related passwords easier to guess. Someone who sees one such password may recognise the pattern and try its variation for another service.

  3. Save passwords in the browser on a public computer.

    Other people may gain access to information saved on a public computer. The stored password remains on a device you do not control, so its exposure also depends on other users of that computer.

You have enabled 2FA for email. Should you now reuse its password elsewhere?

Why does this matter? A unique password and 2FA address different problems. The first limits the consequences of another site’s breach; the second adds a barrier when a password nevertheless becomes known.

  1. Yes, the second factor addresses every risk.

    2FA cannot stop every form of attack. Some phishing targets sign-in approval too, so there is no reason to remove the protection provided by a distinct password.

  2. Yes, if the password is long.

    Length does not prevent the reuse of an already exposed password. A long exposed password is still known in full; using many characters does not make it secret on another site.

  3. No, keep both a unique password and a second factor.Correct answer

    These measures complement each other and reduce different risks. Keeping both measures avoids relying on the assumption that any one control will never fail.

No registration. Your answers are not sent; the result is just for you.

Remember

Use a long, unique password for every account.

Add a second sign-in factor

References

Sources and further reading

Unique-password and email-protection recommendations follow the Serbian National CERT publication on compromised email. Password-manager guidance is supplemented by the UK NCSC recommendations; no particular product is recommended or guaranteed.

Content last reviewed