How a password actually gets stolen
In short
There are three routes, and guessing is not one of them. Either they already have it, because it leaked from a service you used and they try it elsewhere. Or you type it in yourself, on a page imitating a site you know. Or software installed on your machine collects it. A password's length protects against none of the three — only its uniqueness does.
Why this works
The image of a hacker “cracking” a password character by character misdescribes what happens, for a mechanical reason: services limit attempts and lock the account after a few tries, which makes that route impractical however much computing power is involved. The three routes below get around the problem instead of tackling it — they don't need to guess. That is why useful advice is about uniqueness and a second factor rather than complexity: complexity only defends against the route nobody takes.
Step by step
A breach elsewhere, then reuse
A site is compromised, its credentials circulate in batches, and an attacker automatically tries them on dozens of other services. Nothing is guessed: your password is known, and it opens everything that shares it. This route costs the attacker almost nothing — no flaw to find, no victim to convince — and the only remedy is a different password for each service.
Typing it into a fake page
A page imitating a legitimate service collects what you type into it. No flaw is exploited: you type it in willingly, which makes the attack independent of how strong the password is.
Software installed on your device
A program collects the passwords saved in the browser, session cookies and keystrokes. It had to be installed, which takes an action on your part: a file opened, a fake update accepted, an app taken from somewhere other than an official store. That is what makes it avoidable.
Getting around the second factor
When a password is no longer enough, the attacker asks for the code — on the phone, the second after it is sent — or floods the victim with approval requests. Receiving a code you didn't ask for means one thing only: someone already knows your password.
The most common mistakes
- Aiming for complexity rather than uniqueness: a very long password is still useless once it has leaked and is reused.
- Neglecting an old account of no value: it often carries a password still used elsewhere.
- Changing the password of the one account that raised an alert, and leaving the others that share it.
- Thinking a password manager is risky: the risk it removes — reuse — is the one behind most account takeovers.
- Relying on text messages alone as a second factor, when the number itself can be hijacked.
The attacks this defeats
Official sources
Other guides · Last updated: 2026-09-02.