Skip to content

How a password actually gets stolen

In short

There are three routes, and guessing is not one of them. Either they already have it, because it leaked from a service you used and they try it elsewhere. Or you type it in yourself, on a page imitating a site you know. Or software installed on your machine collects it. A password's length protects against none of the three — only its uniqueness does.

Why this works

The image of a hacker “cracking” a password character by character misdescribes what happens, for a mechanical reason: services limit attempts and lock the account after a few tries, which makes that route impractical however much computing power is involved. The three routes below get around the problem instead of tackling it — they don't need to guess. That is why useful advice is about uniqueness and a second factor rather than complexity: complexity only defends against the route nobody takes.

Step by step

  1. A breach elsewhere, then reuse

    A site is compromised, its credentials circulate in batches, and an attacker automatically tries them on dozens of other services. Nothing is guessed: your password is known, and it opens everything that shares it. This route costs the attacker almost nothing — no flaw to find, no victim to convince — and the only remedy is a different password for each service.

  2. Typing it into a fake page

    A page imitating a legitimate service collects what you type into it. No flaw is exploited: you type it in willingly, which makes the attack independent of how strong the password is.

  3. Software installed on your device

    A program collects the passwords saved in the browser, session cookies and keystrokes. It had to be installed, which takes an action on your part: a file opened, a fake update accepted, an app taken from somewhere other than an official store. That is what makes it avoidable.

  4. Getting around the second factor

    When a password is no longer enough, the attacker asks for the code — on the phone, the second after it is sent — or floods the victim with approval requests. Receiving a code you didn't ask for means one thing only: someone already knows your password.

The most common mistakes

  • Aiming for complexity rather than uniqueness: a very long password is still useless once it has leaked and is reused.
  • Neglecting an old account of no value: it often carries a password still used elsewhere.
  • Changing the password of the one account that raised an alert, and leaving the others that share it.
  • Thinking a password manager is risky: the risk it removes — reuse — is the one behind most account takeovers.
  • Relying on text messages alone as a second factor, when the number itself can be hijacked.

The attacks this defeats

Official sources

Other guides · Last updated: 2026-09-02.