Even a long, complex password does not guarantee that an account is safe from hackers, Full Stack engineer and application architect Denis Sinyukov has warned. Sinyukov, who specializes in corporate IT systems, fintech development and business process automation, explained to Lenta.ru, one of Russia's most-read online news outlets, how scammers break into accounts despite seemingly strong protection.
The idea that hackers guess passwords by hand is long outdated, Sinyukov said.
He said criminals now rely on automated tools that check logins and passwords already known to have been compromised against a wide range of websites. That means risk exists even for people who once created a long and complex combination, he said. Security researchers call this technique credential stuffing: automated software feeds huge lists of previously leaked usernames and passwords into login pages across the internet, hoping some victims reused the same combination elsewhere.
How scammers steal passwords
According to Sinyukov, stolen passwords most often reach scammers through several channels. One of the most common is phishing websites built to imitate the pages of banks, email providers, online marketplaces or social networks. Users type their real login details into these fake pages believing they are on the genuine site, handing their credentials straight to the criminals behind them. Phishing remains one of the most common entry points for cybercriminals worldwide because it targets people rather than software, tricking them into willingly handing over their own credentials.
Another channel is database leaks. If a service failed to properly protect user information, that data can end up publicly available or for sale on underground online marketplaces, Sinyukov told Lenta.ru. Large corporate data breaches have repeatedly exposed the login details of millions of users in recent years, and the resulting databases often circulate for sale on underground forums long after the original breach is discovered.

Infected devices pose a separate threat, he said. Malicious software installed on a device can log keystrokes, intercept data typed into a browser or gain direct access to accounts already saved on that device. Keyloggers and similar malware are a well-documented tool used by cybercriminals to silently capture everything a victim types, including passwords entered on legitimate websites.
Reusing passwords called the riskiest habit
Sinyukov named reusing the same password across multiple services as the most dangerous habit of all. If credentials leak from an unimportant or poorly protected site, he explained, attackers can automatically test that same login-and-password pair against email accounts, banks, cloud storage services and other personal accounts.
How to protect an account
Sinyukov said the safest approach is to use a unique password for every service, generated by a password manager. Such tools create and store randomly generated passwords for each account, so a breach at one service does not leave others exposed. Password managers are widely recommended by cybersecurity professionals because they remove the need for users to remember dozens of complex passwords, reducing the temptation to reuse the same one across multiple accounts.
He also recommended enabling two-factor authentication on at least email, banking services, marketplace accounts and social networks. Two-factor authentication requires a second verification step, typically a one-time code sent by text message or generated in an app, so a stolen password alone is not enough to get into an account.
Sinyukov's further advice included regularly updating operating systems and applications, avoiding suspicious links, never storing passwords in notes or messaging apps, and not entering login details on websites whose web address looks questionable.
Earlier advice on strong passwords
Roman Alabin, head of the information security group at InfoWatch, a Russian information security company known for developing software that helps organizations prevent data leaks, previously gave Russians three tips for creating reliable passwords.
