Skip to content
Tech News
← Back to articles

My 140 reused passwords finally came back to bite me. Here’s how I fixed it

read original more articles
Why This Matters

This article highlights the ongoing risks of password reuse and the importance of adopting modern password management practices. It underscores how past habits can have long-term security implications, even years later, emphasizing the need for robust digital security measures for both consumers and the industry. The story serves as a cautionary tale encouraging better password hygiene and the adoption of password managers to prevent breaches.

Key Takeaways

Mishaal Rahman / Android Authority

It’s famous online security lore that you shouldn’t reuse the same password across multiple accounts. But once upon a time, I was a naïve student who liberally ignored this rule, placing far too much trust in the companies that held my data.

Fast forward to 2026, and those bad habits have come back to bite an older and wiser version of myself. While I have long since stopped reusing passwords, the Ghost of Passwords Past decided to visit me when I was notified that my data had been exposed in a breach. And it ended up affecting a lot more than I expected.

Do you ever reuse your passwords for more than one account? 18 votes Yes, I've done it a lot. 50 % Only occasionally. 22 % No. 28 %

How did I even reuse the same password 140 times?

Megan Ellis / Android Authority

While I was aware that I’d used the password many times in the past, I hadn’t realized just how much. It was somewhat of a holy grail at the time: a secure password with random letters and characters — as well as one that I actually remembered.

At the time, password managers weren’t as ubiquitous as they are now. Chrome only introduced a built-in password manager around 2015, and it only started generating passwords in 2018. I had started using this password in 2009. These were the days of adding every game and quiz you could on Facebook (not realizing they were harvesting data), while e-commerce and online services were growing quickly. By the time Chrome’s password manager came around, I had already signed up for dozens of sites using the same password.

I eventually set up a few safeguards as well, including signing up for Have I Been Pwned updates and keeping an eye on Google Password Manager’s notifications for leaked passwords. I did eventually stop using the password because password managers allowed me to generate much more complex credentials without needing to remember them. I could also easily store and access passwords from my phone or my browser, meaning that these secure credentials applied to new app sign-ups as well.

Over the years, I also started changing some of my most important accounts, as well as the ones I was most concerned about when it came to leaks. My Facebook password has long-since changed, along with my primary Google account. At the same time, though, I didn’t realize how much of a trail of reused passwords I had left behind. These were mostly sites I no longer used, so they fell to the back of my mind.

... continue reading