Pathwise

Stay Safe Online · Lesson 1 of 12 · 12 min

How accounts really get taken

Most break-ins aren't clever hacking: they use a reused password, a fake login page or a code you were talked into sharing. Learn the main doors in, and which of your accounts to lock first.

NOT A MOVIE

Attackers take the easiest door

In films, a hacker types fast and breaks through a wall of code. In real life, most account takeovers come through a few boring doors: a password you reused somewhere that leaked, a fake login page you typed into, a code you were tricked into sharing, or a password simple enough to guess. None of these needs special skill, which is exactly why they're so common.

Someone who wants your Instagram doesn't attack Instagram's servers. It is far easier to try the password that leaked from a small shopping site you joined years ago.

Credential stuffing

NOUN · SECURITY

When a website is breached, lists of emails and passwords often end up for sale or shared online. Attackers then use software to try each email-and-password pair on many other sites automatically. If you used the same password in two places, the leak at one becomes a key to the other.

Your password leaked from a forum in 2021. You forgot the forum, but the same password also opens your email. A program tries it, and it works.

Check yourself

Reza uses one password for everything. A small online bookshop he used once was breached last year. This week someone logged into his email from another country. What most likely happened?

  1. Someone broke into his email provider's servers directly and stole his account
  2. His phone has a virus that recorded his typing
  3. The leaked bookshop password was tried on his email and it worked
  4. His email password expired, so the account unlocked itself
Show the answer

The leaked bookshop password was tried on his email and it worked

Right. That's credential stuffing. The bookshop leak handed out a password that also opened his email, because he used the same one.

DOOR TWO

You type it in yourself

Phishing means tricking you into handing over your password yourself. You get a message with a link to a page that looks exactly like your bank, email or Instagram login. Whatever you type goes straight to the attacker. A strong, unique password doesn't help here, because you gave it away.

"Unusual activity on your account. Log in within 24 hours or it will be closed." The link opens a perfect copy of the real login page. Module 2 of this course is all about spotting these.

DOOR THREE

The code you were asked to forward

Messaging apps like Telegram and WhatsApp log you in with a one-time code sent to your phone. If an attacker asks to log in with your number, that code arrives on your phone. All they need now is for you to tell them what it says. So they ask, often pretending to be a friend, a shop or support staff.

A message from a friend's account: "Sorry, I entered your number by mistake, a code just went to you, can you send it to me?" The friend's account was taken the same way, and now it's being used to take yours.

Check yourself

Leila's cousin messages her on Telegram asking for a login code that "came to her by mistake". Since the message really comes from her cousin's account, it's safe to send the code.

Show the answer

False

False. A message from a known account only proves the message came from that account, not that your cousin is typing it. Hijacked accounts are used exactly this way. A login code is for you alone: never forward it to anyone, however familiar they look.

THE MASTER KEY

Your email and phone number open everything else

Almost every service has a "forgot password" button, and it sends a reset link to your email or a code to your phone number. So whoever controls your email can reset the password on most of your other accounts. That makes your email, and the phone number linked to your messengers and bank, the most valuable things you own online.

An attacker who gets into Sam's email doesn't need his shopping or social media passwords. They click "forgot password" on each site and read the reset emails themselves.

The key to the key cupboard

Think of your accounts as rooms in a building, and your email as the cupboard where all the spare keys hang. A thief who picks one room's lock gets one room. A thief who opens the cupboard gets the whole building. Where the analogy breaks: in real life you'd notice the cupboard is empty, but online the attacker can copy the keys and leave everything looking normal, which is why you should check for warning emails about new logins.

Check yourself

Which door did each attack use?

  • Your password from a leaked forum also opens your email
  • You typed your password into a copy of your bank's login page
  • Your password was your birth year plus your name
  • You read a login code to a caller who said he was from support
  • You sent a "mistaken" code to a friend's account
  • The same password worked on four shopping sites
Show the answer

A reused or guessable password: Your password from a leaked forum also opens your email, Your password was your birth year plus your name, The same password worked on four shopping sites

You were tricked into handing it over: You typed your password into a copy of your bank's login page, You read a login code to a caller who said he was from support, You sent a "mistaken" code to a friend's account

Lock them in this order

  1. 1 · Your main email

    It resets everything else. Give it a strong, unique password and two-step login first.

  2. 2 · Your phone number and messengers

    Telegram, WhatsApp and similar apps carry your contacts' trust. Set their extra password or PIN (lesson 3).

  3. 3 · Bank and payment apps

    Use the app's own lock and never share card passwords or one-time codes.

  4. 4 · Social media and the rest

    Instagram, shopping sites, old forums. Unique passwords here stop a leak from spreading. Delete accounts you no longer use.

Check yourself

Maryam has one free hour tonight to improve her security. Her Instagram, Gmail, a food-delivery app and an old gaming forum all share one password. Where should she start?

  1. The old gaming forum, because old sites are the most likely to leak
  2. Instagram, because she has the most followers there
  3. The food-delivery app, because it has her card saved
  4. Gmail, because it can reset the password of every other account
Show the answer

Gmail, because it can reset the password of every other account

Yes. Her Gmail is the master key. Once it has a unique password and two-step login, a leak elsewhere can't be used to reset her other accounts.

Check yourself

Match each habit to the door it closes

Show the answer
  • A different password on every site → Credential stuffing after a leak
  • Never forwarding a login code → Messenger takeover by a "friend"
  • Opening your bank app yourself instead of a link → Fake login pages
  • Securing your email first → Password resets on all your other accounts

Lesson recap

  • Most accounts are taken through simple doors, not clever hacking.
  • A reused password turns one site's leak into a key for your other accounts.
  • Phishing pages and "send me the code" messages get you to hand things over yourself.
  • Your email and phone number reset everything else, so lock them first.

Keep it, don't just read it

Pathwise brings each idea back just before you'd forget it, with a quick question. Free on Android and on the web, in English and Persian.

Cafe Bazaar Myket Open the web app

All lessons in this course

  1. How accounts really get taken
  2. Strong passwords you don't have to remember
  3. Two-step login: a stolen password isn't enough
  4. Phishing: the message that wants you to hurry
  5. Fake pages, fake payment gates and fake apps
  6. SMS, call and messenger scams
  7. Pay without handing over your card
  8. Public Wi-Fi and your home network
  9. Share less, on purpose
  10. Stop pressing "later"
  11. Backups: the 3-2-1 rule
  12. If you get hacked: the first hour