What would happen if someone got hold of one of your employees’ passwords from years ago.

Not a password they are using today.

Not one they even remember.

Just an old one that was never changed.

Because that is exactly how a recent data theft campaign worked.

Sensitive business data from organisations around the world was quietly accessed and later put up for sale.

Different industries. Different sizes of business.

But one thing kept coming up.

Every affected organisation allowed access using nothing more than a username and password.

No second step.

No extra check.

Just type your password and you are in.

Why passwords are no longer enough

This is where multi factor authentication comes in.

MFA simply means using more than one way to prove it is really you.

Usually that is your password plus something else, like a code on your phone, an app approval, or a fingerprint.

So even if someone has your password, they still cannot get in.

In these cases, MFA was not enforced.

And that made all the difference.

How the attackers got in

The attackers did not guess passwords.

They used infostealing malware.

This is a type of malicious software that can sit on a device without the user realising.

Once it is there, it quietly collects saved passwords, login details, and other sensitive information, then sends it back to criminals.

This can happen on:

Office machines

Home devices

Personal laptops

Any device that has ever been used to log into work systems.

What makes this more dangerous is that the stolen data is not always used straight away.

Some of the passwords used in this campaign were years old.

Why this is a real business risk

This highlights two common issues.

Passwords are not changed often enough.

Old access is still trusted long after it should have been removed.

That means something that happened years ago can still cause a problem today.

A device that was infected in the past can become a risk again without warning.

This is why relying on passwords alone is no longer enough.

If you are unsure whether your systems are properly protected, it is worth reviewing how access is currently managed. Our managed IT support services help businesses put the right controls in place without adding complexity.

One simple step that stops it

In these cases, MFA would have stopped the attack.

The attackers had the passwords.

But they did not have the second factor.

No phone.

No approval.

No access.

That extra step would have turned a successful breach into a failed attempt.

Why MFA is worth it

One of the most common reactions to MFA is that it is inconvenient.

And yes, it adds an extra step.

But compare that to the impact of a breach.

A forgotten password being used years later.

Confidential data being accessed without anyone noticing.

MFA turns a stolen password into something useless.

It is no longer optional.

It is a basic security measure every business should have in place.

Taking action now

Old passwords do not expire on their own.

And threats do not go away just because time has passed.

If you want help reviewing your current setup or enforcing MFA across your systems, you can get in touch here and we will guide you through it.

Stoic sysadmin plotting a midnight patch — CETSAT-approved glare ready to block malware

Chat with Dave