← Back to News List

Before You Reuse

The risk of reused passwords

Using the same password across multiple websites is convenient, but it creates a dangerous domino effect: a single breach on one minor account can compromise them all. 

If a data breach exposes your email address and password, someone may try that same combination on other websites. A password taken from a shopping, gaming, streaming, or social media account could then be used to access your email, financial information, or another account that matters to you.

A password can be long and difficult to guess and still put you at risk if you reuse it. The best way to limit the damage from a breach is to use a different password for every account. That does not mean you have to remember them all.

A line of black dominoes on a wooden surface, showing them in the act of falling in a cascading chain reaction. Several of the angled and fallen dominoes feature white text that reads, from left to right: GAMING SITE, EMAIL, BANKING, SOCIAL MEDIA, and BREACH.

How to Stop the Domino Effect 

Protecting every account doesn't mean you have to memorize dozens of complex passwords:

  1. Use a unique password for each account. If you have reused a password, start by replacing it on your email, financial, work, school, and social media accounts.

  2. Let a password manager remember them for you. A password manager can create and store a different strong password for each account. Protect the password manager itself with a strong, unique password and multifactor authentication. For an additional layer of protection, some people store only part of each password in the manager and add something known only to them when signing in. If you use this approach, make sure the complete password is still unique to each account and that you will not lose access if you forget the missing portion.

  3. Choose a passkey when one is available. A passkey lets you sign in using your fingerprint, face, device PIN, or screen lock instead of a password. Because each passkey is connected to a specific website or app, it cannot be reused on another site and is designed to resist phishing. Passkeys can be stored on your device, on a security key, or in some password managers. These options offer different levels of security and convenience.

  4. Turn on multifactor authentication. For accounts that still use passwords, multifactor authentication adds another step before someone can sign in. It can help protect an account even if its password is exposed.

If you learn that one of your passwords was exposed, do not panic. Change it on the affected account and anywhere else you reused it. Then review those accounts for activity you do not recognize.

Celebrate Cybersecurity Awareness Month with Us

Share This Information

Forward this email to a friend and encourage them to follow us at IT Security - DoIT Cybersecurity Assurance and Digital Trust on myumbc. Learn about recent cybersecurity attacks and articles about threats, scams, and attacks. 

Join Us

Want to see whether your email address has appeared in a known data breach? Visit us in the Commons Breezeway during the following two events. We can help you check, answer questions, and decide what to do next.

Follow along throughout Cybersecurity Awareness Month for more ways to protect your accounts and information.

The first draft of the above announcement was generated using AI and edited by the Division of Information Technology Communications and IT teams.

Posted: October 6, 2026, 1:00 PM

Cybersecurity Awareness Month 2026 graphic with the text “Before You Reuse” and a password icon with a repeat symbols. UMBC Division of Information Technology logo is present.