Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
RESEARCH 30 JAN 2026 · 3 MIN

Two people, one password, and a very bad Tuesday

A short account of how a single shared login cost a five-person firm nine days of work. Nobody did anything reckless. The setup did the damage on its own.

SARA MITCHELL · RESEARCH
SHARE LinkedIn X Email
RESEARCH cover image

This is one case, told with the details changed, because the shape of it is so common it is worth walking through. A five-person firm shared one login for the email account that everything ran through: orders, the accountant, the bank's password resets. Sharing it felt efficient. Two people needed it, then it was easier to leave it as it was, and the password had not changed in a couple of years.

The Tuesday started when one of those two people reused that same password on a supplier's website, which was later breached. Attackers took the leaked email-and-password pair and tried it against the firm's mailbox, because people reuse passwords and criminals know it. There was no second factor to stop them. They were in, and because it was the shared account, nobody noticed a stranger among the usual comings and goings.

From inside the mailbox they did the patient thing. They read the threads with the firm's biggest customer, learned the tone, and then emailed new bank details for an invoice already in flight. It was paid, because it came from the right address in the right thread at the right moment. The firm only realised when the genuine supplier chased for money that had gone elsewhere.

The nine days were not the fraud itself. They were the aftermath: proving what had happened, resetting every account the shared login touched, working out which emails had been read, telling the customer, and reporting it. Because the login was shared, none of it could be pinned to a person, which turned every question into a longer investigation. A shared account has no story to tell you about who did what.

The fix costs nothing and is almost boring. One account per person, second factor on the mailbox, and a password manager so nobody has to reuse or share. Any one of those three would have broken the chain on that Tuesday. Having all three would have made the whole day impossible.

WHAT TO DO
  • ✓Give every person their own login and stop sharing any account.
  • ✓Turn on second factor for the mailbox that handles resets and money.
  • ✓Use a password manager so nobody reuses or shares a password.
  • ✓Set a rule that new bank details are always confirmed on a known phone number.