Three different attacks this month had the same outcome: someone logged in using a password that didn’t belong to them. A basic password policy and two-factor authentication fit on a single page, cost almost nothing, and stop most of these attempts—even when the password has already fallen into someone else’s hands.
Here’s what happened, in a nutshell: FortiBleed leaked the administrator passwords of approximately 86,000 FortiGate firewalls, and 63% of the leaked accounts were default “admin” accounts that had never been renamed. A separate campaign stole Microsoft 365 accounts via hijacked hotel Wi-Fi using fake login pages. And AI-powered voice cloning phone scams have risen to the top of the list of frauds in Romania, accounting for 42% of incidents reported to the DNSC in the first half of 2026.
The minimum policy consists of four points, listed in the order in which they should be addressed:
- Unique passwords for each account, generated and stored in a password manager. Reusing passwords is the number one problem: a single old leak can compromise ten accounts. Bitwarden, 1Password, or the password managers from Microsoft or Google get the job done, with automatically generated 12- to 14-character passwords.
- Two-factor authentication for everything that matters: email, Microsoft 365, banking, accounting, and admin dashboards. It’s the only measure that stops an attack even after a password has been stolen. Enable it for all users and on all login channels.
- Use passkeys instead of SMS codes. An SMS code can be bypassed by a phishing page that asks for it along with your password; a passkey—linked to your fingerprint, face, or device PIN—withstands such attacks.
- Clean up default “admin” accounts and shared accounts. Rename the “admin” account, give each person their own account, and revoke access for former employees.
Then write the rule in a single paragraph and add it to the company’s security policy: unique passwords managed by a password manager; mandatory two-factor authentication via email and on any system containing customer data; passkeys wherever possible; no payments based on a simple phone call. You don’t have to do everything today—implementing a password manager and two-factor authentication for email this week will take your company out of the “easy targets” category. If you want to see where your company stands, the free assessment takes 5 minutes: https://xdn-cs.ro/instrument-nis2.html
This article was generated with AI assistance.