Password Reuse - Attack Type

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 8, 2026
Last Seen
January 8, 2026

Password reuse is the practice of using the same credentials across multiple services, enabling attackers to leverage leaked passwords to gain unauthorized access (credential stuffing and account takeover).

Overview

Password reuse is the practice of using the same credentials across multiple services, enabling attackers to leverage leaked passwords to gain unauthorized access (credential stuffing and account takeover). This is significant in cybersecurity because high-value accounts, including admin consoles, are especially vulnerable. Microsoft’s MFA enforcement for the 365 admin center illustrates a defense-in-depth move to curb breaches stemming from reused credentials.

Related Threat Clusters

  • Microsoft Mandates MFA for Microsoft 365 Admin Center Access

    Microsoft is enforcing multi-factor authentication (MFA) for all users accessing the Microsoft 365 admin center, effective February 9, 2026. This policy follows a gradual rollout that began in February 2025, and…

    3 articles · Updated January 8, 2026

Recent Intelligence Reports

  • Microsoft to enforce MFA for Microsoft 365 admin center sign — Bleepingcomputer · January 8, 2026

CVSS v3.1 Breakdown