When people talk about the risks of password reuse, the most common reaction is “who would even care about my accounts?” It’s a fair question, and it has a precise answer: nobody is interested in you in particular. Lists of stolen credentials — the username-and-password pairs you use to sign in — are tried in bulk, automatically, against everyone.
The more useful question is a different one: if that password worked, what would be touched?
This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that the damage is never of just one kind.
It expands on the recommendation a unique password for every account.
Three questions to measure an impact
Before getting into the details, it’s worth having the right questions at hand. For any account — and not only when something goes wrong — they are these:
- What could someone who got in here read? — this is the confidentiality question.
- What could they change or send in my name? — this is the integrity question.
- What would I no longer be able to do if I lost access? — this is the availability question.
Applied to your main email account, these three questions almost always produce the same answer: a lot. Applied to an old forum account, they produce a modest answer — until you discover that its password is the same as your email’s. That is exactly where reuse changes the maths: the impact is no longer measured on the account that gets hit, but on the most important of all the accounts that share the same key.
1. Confidentiality: information stays with the people entitled to see it
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. A reused password weakens it because it extends the same permission to read across several services.
A practical example
The password for your email account is the same one you used to sign up for an online store back in 2019. That store suffers a data breach. Whoever gets hold of the list doesn’t need to attack your email provider: they simply try the same email-and-password pair and read your inbox.
What the incident looks like
Your inbox holds payment confirmations, attached documents, work messages, medical reports, contracts and private conversations. Nothing even needs to be changed: simply reading is already a harm, and it is often the one that goes most unnoticed.
What to watch for
- sign-ins from places or devices you don’t recognise in the account’s activity history;
- messages marked as “read” that you never opened;
- sign-in notifications from an app or email client you didn’t set up;
- automatic forwarding rules you didn’t create (a forwarding rule quietly sends a copy of your incoming mail to another address).
What to do
Replace your email password with one used only there, turn on multi-factor authentication (a second check, such as a code on your phone, on top of the password), and review your forwarding rules. Treat your email as the most critical account you have, because it is the one used to recover all the others.
2. Integrity: information stays correct
Integrity is the guarantee that data isn’t altered by anyone without the right to do so. Here, password reuse weighs in a different way: it’s no longer about what someone can see, but about what they can change in your name.
A practical example
With access to your profile on a payment service, someone changes the linked bank account details or the shipping address. The service isn’t being attacked: it is carrying out an instruction that looks like it came from you.
What the incident looks like
The most frequent changes involve exactly the details you need to regain control: the recovery email address, the phone number, the security questions. Once those are changed, the road to recovery gets much longer. At the same time, messages may start going out in your name to your contacts, with requests that seem believable precisely because they come from you.
What to watch for
- confirmation emails for changes you didn’t request;
- contacts telling you about strange messages sent from your account;
- security settings that are different from how you remember them;
- apps connected to your account that you never authorised.
What to do
Check your recovery details and connected apps from time to time (connected apps are third-party services you once allowed to access your account). If you receive a confirmation for a change you didn’t request, don’t use the links in the message: go to the service through its official address and check from there.
3. Availability: you can get in when you need to
Availability is the guarantee of being able to use your data and your services at the moment you need them. It’s the easiest impact to recognise, because it shows up as a locked door.
A practical example
You try to sign in to your cloud storage account and the password no longer works. You start the recovery process, but the recovery email address has been changed.
What the incident looks like
The lockout rarely involves just one service. If the password was shared, the same situation can come up on several accounts around the same time. For anyone who works with online tools, that means coming to a stop: documents out of reach, invoices not sent, communications cut off.
What to watch for
- the correct password is rejected on a service you used normally;
- the account appears suspended or locked with no explanation;
- password recovery breaks down because the contact details linked to the account are no longer yours;
- the same problem appears on several services within a short time.
What to do
Always keep a second recovery channel up to date and separate from the first. Store your MFA recovery codes — the one-time backup codes that let you in if you lose your second factor — somewhere safe and reachable even without your phone. If you lose access, always start by recovering your main email: it’s the root.
| Aspect | What someone who gets in can do | Why it matters |
|---|---|---|
| Confidentiality | Reads emails, documents, messages and personal data | The harm happens even without leaving obvious traces |
| Integrity | Changes settings, sends messages in your name, alters recovery details | Undermines trust and makes recovery take longer |
| Availability | Changes the password and contact details, locks you out of the account | Stops personal and work activities, sometimes permanently |
One scenario that brings them together
In 2018 you signed up for a forum to ask a technical question. Password: the same one as your email at the time, which you still use today.
That forum shuts down in 2021, but its user database keeps circulating. An automated system tries that pair on a list of common services. It works on your email.
From there, in sequence: your mail is read and the services you’ve signed up for are identified (confidentiality); the recovery phone number is changed on two of them (integrity); the password for your cloud storage is changed (availability). Three different impacts, a single cause: a password that stayed the same for years on a service you had forgotten about.
The impacts that show up later
Not every effect appears right away. Some develop over time, which is why “nothing has happened” isn’t a reliable check.
- Silent reading. Someone who signs in only to read leaves no obvious traces. The first sign may come months later, when that information is used somewhere else.
- Access that stays open. An active session (the “stay signed in” state on a device or browser) or a connected app keeps working even after a password change, unless it is explicitly revoked.
- Data used to make another request believable. Information gathered from an inbox — supplier names, amounts, habits — is used to build messages that look legitimate, sent to you or to your contacts.
- Credentials put back into circulation. An exposed password can reappear in combined lists years after the original breach, and be tried again.
This isn’t a reason to live on high alert. It’s the reason protection has to be preventive: a unique password and a second factor reduce all four of these effects, including the ones you’ll never see.
Not all accounts weigh the same
The impact depends on what an account holds and on what it lets someone reach.
| Type of account | Main impact | Why |
|---|---|---|
| Main email | All three, with a multiplier effect | It’s the recovery key for every other service |
| Online banking and payments | Integrity and availability | Changes to personal and bank details, transactions blocked |
| Cloud storage and document archives | Confidentiality and availability | Holds years of documents, often other people’s too |
| Work accounts | All three, with effects on others | Involves clients, colleagues and suppliers |
| Social media | Confidentiality and integrity | Messages in your name, private conversations exposed |
| Online shopping | Integrity and financial | Saved addresses and payment methods |
| Secondary services and old accounts | Low on their own, high if they share the password | They’re the most common way in |
The last row is the one that counts: the highest risk almost never comes from the account you consider important.
Why similar passwords matter too
A tiny variation doesn’t reduce the impact, because it doesn’t reduce predictability.
| Password | Why it’s still risky |
|---|---|
Luna2023!, Luna2024!, Luna2025! | Only the year changes: the pattern is obvious |
LunaEmail!, LunaBank!, LunaSocial! | Putting the service in the password makes the rule instantly clear |
Chicago1980! | Combines a place and a date: information that is often easy to find |
Password123! | One of the most commonly tried combinations of all |
If the first one is exposed, the others don’t need to be guessed: they can be worked out.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that a single event produces impacts on different levels |
| Skills | Being able to read confidentiality, integrity and availability as three concrete questions |
| Secure Behaviour | Regularly checking sign-ins, recovery details and connected apps |
Reference level: FL2 — Beginner. This is the level at which you move from “I know I should use different passwords” to “I understand what happens if I don’t.” Awareness of the impacts is what keeps the behaviour steady over time.
Summary
- Confidentiality is about what gets read: emails, documents, personal data.
- Integrity is about what gets changed: settings, messages sent in your name, recovery details.
- Availability is about what you can no longer use: locked accounts, interrupted recovery, work brought to a halt.
A reused password doesn’t produce just one impact: it opens the door to all three, on the same account and on the ones linked to it.
One thing to do today. Open the security settings of your main email account and check three things: recent sign-ins, the recovery address, and any forwarding rules. It takes about five minutes, and it covers all three impacts at once.
Related content
- A unique password for every account — the recommendation this expands on
- Consequences of a stolen password — from technical impacts to concrete effects on work, money and reputation
- How to tell if your account was hacked — how to notice that one of these impacts is already under way
- What to do after reusing passwords — what to do, in order of priority
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



