CIO Brief: Credential Breaches at Other Companies Are Your Problem Too
Retrospective: this article looks back at events from December 2016, written in 2026 with the benefit of hindsight.
The short version: When a big company like Yahoo loses billions of passwords, your company is also at risk. Your employees reuse passwords, and attackers try leaked passwords against your email and cloud apps.
Why another company's breach is your problem
Criminals collect leaked username and password pairs into enormous lists and try them automatically against popular services such as Microsoft 365. This is called credential stuffing. It costs them almost nothing and works often enough to be profitable. A single successful login to an executive's or finance employee's email can lead to invoice fraud, data theft or ransomware.
The business impact
- Fraud: business email compromise is one of the costliest cybercrimes reported to the FBI every year.
- Data exposure: a mailbox holds contracts, customer data and credentials for other systems.
- Disruption: account takeover is a common first step toward ransomware.
Questions to ask your team
- Is multi-factor authentication enforced for every account, including executives and service accounts?
- Have we blocked older sign-in methods that cannot use MFA?
- Would we know if someone signed in with a stolen password today?
- How does our help desk verify someone before resetting their password or MFA?
What good looks like
Every account requires a second factor, administrators use phishing-resistant methods, legacy sign-in protocols are blocked, and suspicious sign-ins raise alerts someone reviews.
The decision
If the answer to the first question is anything but "yes, everyone," make it the top identity priority this quarter. It is inexpensive, well understood, and stops most of these attacks.
- Yahoo's Billion-Account Breach Disclosure (Dec 2016): The Case for MFA Everywhere Incident Teardowns
- How to Roll Out MFA to Every Microsoft 365 User Without a Help Desk Meltdown How-To & Hardening
- Detecting Credential Stuffing Attacks: Entra Sign-In Logs and Sentinel KQL Detection & Response