Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

How to Steal a Password

How to Steal a Password

Passwords are what separate you from someone else’s private information, their money, their subscriptions, their personal data, their business, and even their livelihood. If you were able to easily crack a password, you’d have access to the wealth and identity of another person. In this blog, we’re going to show you just how to do that.

How to Steal Almost Anyone’s Password for Almost Any Type of Account (Bank, Netflix, Email Inboxes, and More!)

Need a few extra grand to get yourself through the weekend? How about access to your neighbor’s Netflix account so you don’t have to pay for yours? Maybe you just want to hack into your former employer and cause a little chaos.

It’s incredibly easy to do.

Unfortunately, we’re not going to show you exactly how to do that. That would be, well, immoral. 

But we got your attention, so there’s that.

It’s worth understanding just how easy it is for hackers and bad guys to infiltrate your work, your network, your online accounts, and just about everything else you do. 

And hey, if you got this far in here because of the title of the blog, we don’t necessarily think you are one of the bad guys. It’s actually really interesting how this stuff works, and understanding it can help you become a whole lot safer online.

Step One - Know a Thing or Two About Your Victim

We’re going to use Homer J. Simpson as our example. No, not that Homer J. Simpson. As it turns out, the 1940 American census has one single Homer J. Simpson on it, and he was born in 1914. We’re pretty sure there haven’t been a lot of babies born with the name Homer J. Simpson ever since the 90s, so this is a pretty safe bet for our fictional victim. Everything from here on out, we’re just going to make up.

So let’s say we really don’t like Homer, and want to make his life miserable. Actually, scratch that. Let’s say we don’t know a gosh darn thing about him.

You see, Homer had a MyFitnessPal account back in 2018. Homer was using it to track his calorie intake and his daily steps. In February of 2018 (this is true), MyFitnessPal suffered a data breach that exposed 144 million unique accounts, including their emails and passwords. 144 million accounts getting stolen is small potatoes in the world of data breaches, but these types of data breaches happen all the time, and it means that the data you entrust to a business or online service could get you more exposure than you were counting on. Literally thousands of online entities have been breached over the last few years, from Sony to Wendy’s to Yahoo to Facebook to Experian to Doordash, and the list goes on.

Well, Homer’s MyFitnessPal account and his old password are floating around the dark web, and it’s available for me to scoop up. You might ask, how much value could I get from a MyFitnessPal account, especially years later, and long after the service forced Homer to reset his password?

Well, I know Homer’s name, his email, and a password he likes to use.

I can make my way over to Google.com and start looking up Homer on social media. I can find his date of birth, the town he grew up in, and his mother’s maiden name. I can pull up his LinkedIn and find out where he works, who he networks with, and what his job title is.

In 10 or 15 minutes, I can get a pretty decent snapshot of who Homer J. Simpson is, especially if he uses social media. I can learn the name of his kids, his dog, his wife, and the type of car he drives. I can easily find his address.

So how does all of this help me determine his password?

Most people use information about themselves in their passwords. It’s a really dumb idea, but it’s true. So many people put in birthdates, or birth years into their passwords, and then use their pet’s name. It might take you a little time, but if you are clever, you might be able to extrapolate a password based on their personal information. When in doubt, if their dog’s name is Woofy, replace the O’s with zeroes.

Step Two - Just Use Software to Crack the Password

Don’t have a lot of time and just want to ruin someone’s day? There is software available on the dark web that makes it easy to crack sophisticated passwords. As long as the user’s password isn’t too complex (if it’s 9 or 10 characters, or a few more but without special characters) most cracking tools can usually get right in within a few minutes to maybe a day or two. Of course, if the user has a longer password that is truly random, and doesn’t contain any obvious terms like their favorite sports teams, their car make and model, or the word “password,” then it might start to take longer.

Complex passwords are harder for the software to crack, but fortunately, most of these tools will try the most common permutations first, so if your victim is lazy about their password generation, you should be able to get in.

Step Three - Just Trick Them Into Giving It To You

This is probably the step you should have started with because it’s the most effective way to steal a password. In fact, this is the number one way cybercriminals get access to things they shouldn’t. 

It’s true. Around 95% of modern cyber breaches these days start with a phishing attack. It has such a high success rate that it’s a no-brainer to use if you want to get into someone’s account.

Here’s how it works.

You send them an email saying you are, let’s say, their bank.

You tell them that something is wrong with their account. If you are pretending to be a bank, you have lots of options, because people get a strong emotional reaction when something happens to their money. Tell them that a payment has been authorized for $2500 for something. Be specific, be creative! The goal is to throw them off guard!

Now here’s the trick… Instead of sending them to their actual bank, send them to a webpage that you built, that looks an awful lot like their bank. The catch is when they try to log in, they give you their username and password.

It’s that easy!

This happens all the time. It’s very illegal, and you shouldn’t do it, but it’s also very difficult to catch cybercriminals who are doing this sort of thing.

Don’t Be a Victim of Cybercrime

It’s more important than ever to keep yourself and your business secure. Always use strong, complex passwords, and never use the same password twice. Set up Multi-factor authentication (MFA) everywhere you can, and be extremely skeptical of random unsolicited emails. If something doesn’t seem right, scrutinize it!

We can help your business become more secure. To get started today, give us a call at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Monday, 30 March 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips Internet IT Services Malware IT Support Workplace Tips Privacy Computer Phishing Google Email Workplace Strategy Hosted Solutions Collaboration Small Business Users Backup Ransomware Managed Service Mobile Device Productivity Microsoft Passwords Quick Tips AI Saving Money Communication Cybersecurity Smartphone Data Backup Data Recovery Disaster Recovery Android Upgrade VoIP Business Management Smartphones Mobile Devices communications Windows Social Media Browser Managed IT Services Microsoft Office Network Current Events Tech Term Remote Internet of Things Information Miscellaneous Artificial Intelligence Holiday Facebook Automation Gadgets Compliance Cloud Computing Covid-19 Training Outsourced IT Server Managed Service Provider Remote Work IT Support Encryption Spam Employee/Employer Relationship Office Windows 10 Government Business Continuity Data Management Virtualization Wi-Fi Blockchain Bandwidth Windows 10 Business Technology Managed Services Apps Two-factor Authentication Data Security Mobile Office Vendor Tip of the week App Voice over Internet Protocol Employer-Employee Relationship Networking Chrome BYOD Mobile Device Management Budget Gmail Apple WiFi Conferencing Computing Information Technology Managed IT Services How To Hacker BDR Avoiding Downtime Office 365 Marketing HIPAA Physical Security Applications Access Control Big Data Retail Operating System Healthcare Risk Management Computers Analytics Office Tips Website Augmented Reality Router Storage Virtual Private Network Password Bring Your Own Device Health 2FA Help Desk Excel Social Going Green Document Management Remote Workers Managed IT Service Telephone Cybercrime Scam Data loss Customer Service Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 Remote Monitoring Vulnerability End of Support Vendor Management Solutions Firewall Display Printer Paperless Office Windows 11 Infrastructure Monitoring The Internet of Things Video Conferencing Machine Learning Managed Services Provider Saving Time Virtual Machines Professional Services Settings Wireless Printing Content Filtering Maintenance Antivirus Downloads Customer Relationship Management YouTube iPhone Licensing Cryptocurrency Hacking Entertainment Vulnerabilities Data Privacy Presentation Virtual Desktop Images 101 Data storage LiFi Wireless Technology Telephone System Multi-Factor Authentication Robot Mobility Cost Management Outlook Money Humor IT Management Word VPN Employees Meetings Integration User Tip Modem Sports Computer Repair Mobile Security Processor Mouse Safety Holidays Administration Data Storage Smart Technology Supply Chain IT solutions Electronic Medical Records Language Employer/Employee Relationships Outsourcing SharePoint Legal Addiction Management PCI DSS Business Growth Chatbots Navigation Application Lenovo Gig Economy Screen Reader Writing Distributed Denial of Service Workplace Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Cortana Service Level Agreement Internet Service Provider Server Management Regulations Compliance Alt Codes Private Cloud Identity Evernote Paperless IBM Superfish Bookmark Identity Theft Smart Tech Memes Downtime Co-managed IT Hosted Solution Twitter Alerts SQL Server Technology Care Download Net Neutrality Financial Data Typing Error History Business Communications Browsers Smartwatch Connectivity IT Social Engineering Break Fix Scams Remote Computing Azure Hybrid Work Knowledge Competition Google Drive Upload Procurement Social Network Telework Cyber security Multi-Factor Security Tech Human Resources 5G CES Tablet IoT Communitications Dark Web Cables Google Docs Trends Supply Chain Management Unified Communications Alert Experience User Managed IT Customer Resource management FinTech Bitcoin File Sharing Regulations Running Cable Dark Data Google Calendar Term Google Apps How To Microsoft Excel IT Maintenance Data Analysis Google Wallet Star Wars IT Assessment Gamification Flexibility Notifications Staff Value Business Intelligence Organization Windows 8 Travel Social Networking Laptop Legislation Shortcuts IP Address Ransmoware Techology Fileless Malware Digital Security Cameras Drones Google Maps Smart Devices Content Remote Working Wearable Technology Memory Vendors Recovery Health IT Unified Threat Management Motherboard Data Breach Halloween Comparison Google Play Be Proactive Permissions Workforce Hard Drives Unified Threat Management Directions Videos Assessment Electronic Health Records Wasting Time Threats Domains Hacks Trend Micro Scary Stories Network Congestion Specifications Security Cameras Workplace Strategies Fraud Meta Fun Refrigeration User Error Microchip Internet Exlporer Software as a Service Username Deep Learning Managing Costs Amazon Public Speaking Lithium-ion battery Point of Sale eCommerce Black Friday SSID Education Virtual Assistant Outsource IT Entrepreneur Database Surveillance Network Management Tech Support IT Technicians Virtual Machine Environment Media Proxy Server Reviews Mobile Computing Cookies Monitors Cyber Monday Medical IT Hotspot Transportation Small Businesses Search Undo Tactics Development Best Practice Websites Mirgation Hypervisor Displays Shopping Nanotechnology Optimization Buisness PowerPoint

Blog Archive