The real risk of using the same passwords

Deliveroo have encountered a common security problem for over a month, where customers have had their accounts broken into, with orders for huge quantities of food sent to seemingly random addresses. This is due to a cyberattack known as ‘credential stuffing’.
Credential Stuffing automates the logins for thousands to millions of accounts. This involves hackers obtaining usernames and passwords from previous data hacks and testing the details garnered from this against a user’s other online accounts. This is made possible by people reusing passwords for different accounts. “Sadly cyber criminals rely on the fact that people reuse the same passwords on multiple online services and use data breaches elsewhere to try gain access to other accounts on the web,” a spokesperson for Deliveroo said.
It is common for people to regularly use the same passwords across the web. Credential stuffing can be a straightforward way for hackers to gain access to your online t services and accounts. It’s not something that is unique to Deliveroo, there has been a huge surge in attacks using this method recently.
In January, the world’s biggest database of compromised email addresses and associated passwords was found circulating online. Dubbed Collection #1 and Collection #2-5, these vast collections contain more than two billion accounts totalling 845 Gb of data.
Reddit has also warned about an increase in credential stuffing attacks this month. Reddit admins said they saw “unusual” activity and locked people out of their accounts. “The most common explanation for this is the use of very simple passwords or the reuse of credentials across multiple websites or services,” admins wrote in a blog post, “If another site is compromised and those lists of usernames and passwords become available, it’s very likely that they will be tried against other popular sites”.
There is little services and companies can do to prevent credential stuffing. To be secure and protect yourself against a credential stuffing attack, you should never use the same passwords across different accounts – at least not those which are important and contain payment details, such as your email, banking, shopping, etc.
You can use the following tools to see if you details have been previously compromised: haveibeenpwned? and Info Leak Checker.