Ir al contenido

1. Why a Password Is No Longer Enough

LESSON 1 OF 6 · 5 MIN

Why a Password Is No Longer Enough

Let us start with something that actually happened to a company very much like yours.

A sales manager at a distribution company received an email titled "Action Needed: Please Update Your Email Password". It looked ordinary. He entered his password. A few weeks later a second message arrived — a document to sign, apparently through a well-known e-signature service. He signed in again.

Nothing appeared to happen. No warning, no alert, nothing broken. That was the problem.

What the attacker did next

Over the following days somebody logged into his mailbox from commercial data centres in another country. They did not delete anything and they did not send spam — that would have been noticed. They simply read his mail for three days, learning who pays the invoices, how colleagues write to each other, and what a normal request looks like.

Then, late one evening, they sent a message from his real account to the company bookkeeper, written to look as if it came from another employee. The goal was a payment redirected to their own bank account.

The point of this lesson

The password was correct. That is why the mail server let them in — it had no reason to refuse. Nothing was hacked, nothing was broken. Someone simply knew the password.

Two-factor authentication would have stopped this on day one, because the attacker had the password but not the phone.

Why this matters to you personally

You may think your mailbox is not interesting. But your mailbox is the place where your bank, your payroll system and every other service sends its "reset your password" link. Whoever controls your email can eventually control almost everything else.

That is why we start here.

No se permite comentar en este curso.