ByDavey Winder,

Senior Contributor.

You might well assume that your passwords are safe and secure. After all, you don’t share them between different sites and services, you like to think you are savvy enough to steer clear of even the most advanced of phishing attacks. But, remember, assume makes an ass out of u and me. What if your password is weak enough to be broken in the blink of an eye by attackers using an automated password hacking machine? What if infostealer malware has already compromised it? What if your password is on this newly published, and easily searchable, list of credentials that are already being used by hackers in ongoing account takeovers? If your password is on the list, they are getting in. It’s as simple as that. Here’s what you need to know and do, right now.

If you read my article here, you will already know that compromised password lists are not only a thing, but they are a prolific thing. Complied from lists of already leaked credentials following successful data breaches, the logs of infostealers that have exfiltrated them from under your very nose, and other sources. The list I am talking about today, however, is not one of these but is, in many ways, even more dangerous. Why so? Because millions of people are using the passwords it contains, without realizing the risk that doing so opens them, their accounts and often their businesses up to.