How could my bank password be in a data breach without me being hacked?
#1
I just got a notification that my password was in a data breach, but it’s a strong, unique one I only use for my bank. I’m trying to understand how that could happen if I wasn’t directly compromised. Could it be from some third-party service the bank uses that got hit?
Reply
#2
That can happen even with a password you never reuse. A bank vendor or partner who stores credentials or access logs could get compromised and your info ends up in someone’s dump.
Reply
#3
I got one of those alerts too, and they said a third party used by the bank was compromised; my password was unique to banking, but the dump included my email and a hash that matched when a cracker tried something.
Reply
#4
I spent a weekend worrying about it, then wondered if maybe malware on my device was reading keystrokes; I didn’t re-use the password anywhere else, but I still rotated it.
Reply
#5
Could the real issue be something else entirely like a phishing prompt or credential stuffing from somewhere you don’t even remember?
Reply


[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Forum Jump: