Hackers Are Logging In, Not Breaking In
Attackers rarely force their way in anymore. They sign in with a real password. How passwords get stolen, and the one setting that stops most of it.

Picture a burglar who doesn't pick the lock because he found the key under the doormat. That's how most break-ins at businesses work now. Attackers rarely force their way in. They sign in with a real username and password, and from then on they look like an employee.
In Verizon's 2025 breach report, stolen or abused credentials were the most common way in, at 22% of breaches. Among ransomware victims, 54% had company passwords exposed in "infostealer" logs before the attack. When I look at how break-ins actually start, it's almost always a password, not a hack.
How passwords get stolen
- Phishing pages that copy the Microsoft 365 or bank sign-in screen.
- Infostealer malware, often picked up from a fake download on a personal computer, that quietly collects every password saved in the browser.
- Reused passwords. When any website you use is breached, criminals try that email and password everywhere else. Verizon found these "credential stuffing" attempts make up a meaningful share of all sign-in traffic, even at small businesses.
- Guessing. Short or common passwords still fall to automated guessing.
The one setting that stops most of it
Multi-factor sign-in, sometimes called two-step verification, means a password alone is no longer enough. The attacker also needs your phone or a security key. It is the single most effective security control a small business can turn on, and it is already included in Microsoft 365 and Google Workspace.
Not all versions are equal:
- Best: a security key or a passkey, which can't be phished.
- Good: an authenticator app with number matching, where you type the number shown on screen.
- Better than nothing: a code by text message. It can be intercepted by a SIM swap, so move off it where you can.
Make passwords harder to steal and less useful
- Use a password manager so every account gets its own long, random password. Then a breach somewhere else can't unlock your email.
- Don't save work passwords in the browser on a personal computer.
- Turn on alerts for sign-ins from new countries or devices, and block sign-ins from places your business never operates.
- Remove accounts the day someone leaves, and review who has admin access every quarter.
What to do today
Check that multi-factor sign-in is on for every email account, every remote access tool and every admin login. Not "available", actually on and enforced. If you're not sure whether multi-factor sign-in is on for everyone, call us. It takes us minutes to check.
Not sure where your business stands on this?
We’ll walk through how you handle it today and tell you straight whether it needs attention.