Zombie credentials: why old password dumps still fuel account takeovers
LinkedIn was breached in 2012. Adobe followed in 2013, Yahoo soon after. Yet accounts are still being hijacked every day with passwords stolen in those long-forgotten incidents, because a reused password does not expire when the news cycle moves on.
Old breaches never really close
When a company is hacked, its stolen data rarely fades away. It gets traded on underground forums, merged into ever-larger collections and reposted for years. Researchers have a name for this material, previously compromised data, and it behaves less like an archive than a live weapon. The scale is hard to overstate. Have I Been Pwned recently indexed roughly two billion email addresses and 1.3 billion unique passwords pulled largely from credential-stuffing lists, most of it aggregated from breaches that were years old, as Troy Hunt documented when the data went into the service (https://www.troyhunt.com/2-billion-email-addresses-were-exposed-and-we-indexed-them-all-in-have-i-been-pwned/).From dump to combolist
Criminal aggregators deduplicate these dumps, normalize the formats and merge them into so-called combolists: files of email and password pairs built specifically for automated attacks. Landmark collections such as Anti Public, Collection #1-5 and the 3.2-billion-record COMB database were assembled exactly this way, stitching together dozens of unrelated breaches into a single searchable arsenal. Age matters, but less than you would hope. Analysts at Breachsense note that only around 0.2 to 2 percent of credentials from old breach compilations still work, yet with lists containing billions of pairs, even that sliver translates into hundreds of thousands of working logins (https://www.breachsense.com/blog/dark-web-combo-list/).Stuffing at industrial scale
Credential stuffing is the monetization step: bots feed a combolist into login pages across the web, betting that victims reused their passwords. The bet pays off constantly. Akamai recorded nearly 30 billion stuffing attempts in 2018 alone, then 193 billion in 2020, a 360 percent jump in a single year (https://www.csoonline.com/article/567905/credential-stuffing-explained-how-to-prevent-detect-and-defend-against-it.html)."Weak passwords and password reuse are the bane of account security. If a password is weak or reused across multiple accounts, it will eventually be compromised." - Akamai, State of the Internet reportCloudflare's own network data makes the human side uncomfortably clear. Roughly 41 percent of successful logins by real people across sites it protects involved leaked credentials, and 52 percent of all authentication traffic contained passwords found in its 15-billion-record breach database (https://blog.cloudflare.com/password-reuse-rampant-half-user-logins-compromised/). Most of that automated traffic comes from bots testing stolen pairs at speed. Only about 5 percent of leaked-password login attempts get denied outright, which tells you how thin many sites' defenses remain.
One password, compounding costs
The arithmetic of reuse is brutal. One password shared between a cat forum, an email account and a shopping site means one old dump unlocks all three. Attackers typically start with low-value accounts, mine them for personal details, then pivot toward email and financial services where the real money sits. The downstream damage compounds too. A single takeover can trigger identity fraud, business email compromise or, in corporate settings, ransomware entry. Akamai has cited cases where one financial firm suffered more than 8,000 account takeovers per month, driving six-figure daily fraud losses before bot defenses were deployed. And the threat keeps refreshing itself. Infostealer malware now harvests plaintext passwords directly from infected browsers, feeding newer, deadlier combolists whose hit rates reach 30 to 60 percent. Your decade-old forum password may be stale; your current one is worth more.Breaking the cycle
The defense is unglamorous and effective. Every account needs its own credential, so one breach stays contained. Practical steps:- Use a password manager and generate a unique password for every service.
- Audit your email address at Have I Been Pwned, then change anything exposed and reused.
- Turn on multi-factor authentication wherever it is offered, especially for email.
- Never tweak old passwords with small variations, such as adding an exclamation mark, since cracking tools predict this.