One was based on a car make and a year. It probably seemed reasonably unique to its owner. But passwords like Toyota2026, and endless variations with a year or an exclamation mark, are exactly the sort of combinations attackers try first. Huge password dictionaries already contain common car brands, sports teams, suburbs, pet names, children’s names and predictable number patterns. If someone can see on Facebook, Marketplace or Instagram what you drive, the password becomes less of a mystery. And if you think you are being smart by replacing the letter O with a 0, hackers now that trick too.
Another customer had a 4-digit number in her email address. Unfortunately, that same number had also become her phone PIN, laptop PIN and part of most of her passwords. That is understandable. People use familiar details because they have far too many accounts to remember. The problem is that once a pattern appears in one place, it gives a scammer a useful clue everywhere else.
The important lesson is not that you need to invent a password that looks like somebody dropped a keyboard down the stairs. It is that passwords should not be based on your life. Your date of birth, children’s names, car registration, favourite football team, street name, pet’s name and the number in your email address may feel private enough. In reality, bits of that information can be found through social media, old data breaches, public records, online shopping accounts, or simply guessed from common patterns. A password does not need to be fully exposed to be vulnerable. It only needs to be predictable enough.
One Leaked Password Can Open More Doors Than You Think
The other problem we see constantly is the same password being used on multiple accounts. Maybe you used it years ago on an online shop, a forum, a streaming service, a competition entry or some website you barely remember joining. That smaller business gets breached, or its customer database is sold, and your email address and password end up in a list online.
Criminals then try that same combination on bigger targets: Gmail, Outlook, Facebook, Microsoft, Amazon, MyGov, telcos and banking-related services. This is mostly automated. Nobody needs to sit there manually entering your password into hundreds of websites. Software can test thousands of leaked combinations very quickly and report back when one works.
That is why a password that is merely “good enough” is no longer good enough if you use it everywhere. Your email account deserves special attention because it is usually the master key to everything else. If someone gets into your email, they can request password resets for other accounts, intercept those reset links, and sometimes delete the warning emails before you see them. A Facebook account can be annoying to lose. An email account can become the route into almost everything connected to you.
At an absolute minimum, the passwords for your emails should be unique. The same goes for banking, MyGov, your mobile provider, social media and any account that stores payment details or personal documents.
The Bigger Problem: Your Data is Already Scattered Everywhere
Weak or reused passwords are still one of the easiest ways into an account. But they are only one part of the privacy problem Australians now deal with. Every time a business asks for your driver licence, passport, Medicare details, address, date of birth, phone number and email address, it is trying to verify who you are. Fair enough. The problem is that each time those details are copied into another database, they become another potential target.
Australians have had plenty of public reminders of this: Optus, Medibank, Latitude and many others. Smaller breaches at real estate agencies, medical providers, retailers and service businesses often do not make national news, but may still expose enough information to make somebody’s life difficult. A password can be changed. Your date of birth cannot. Neither can your former addresses, driver licence number, Medicare number or the answers to old-fashioned security questions.
Once enough pieces are out there, a criminal can build a fairly believable version of you. They may try to open an account, apply for credit, make a scam call sound convincing, or convince a telco to move your phone number to another SIM card. That last one is particularly nasty: if they control your number, they may receive text-message verification codes intended for you.
A breach also does not always lead to fraud immediately. Stolen data can be collected, copied, sold and kept for years. It may only become useful later, when a criminal combines it with information from another breach or finds a new way to exploit it. So when a company says, “We take your privacy seriously,” that should mean more than sending an apologetic email after something goes wrong.
The Failure of Australian Oversight Bodies
Dr Andy Schmulow argues that Australia has more publicly leaked personal data per person on the dark web than any other country. In this Unemployable Media podcast, he is scathing about corporate negligence and political inaction around data privacy. It is unapologetically political, and some of his views will be controversial, but it is well worth watching with an open mind.
Despite high-profile incidents, Australian regulators have been criticized for:
- Inaction on data breaches and privacy violations.
- Protecting large corporations instead of consumers.
- Refusing to publicly reveal findings that might “embarrass” companies like American Express.
- Being overwhelmed or excessively deferential to industries they regulate.
This is a textbook case of regulatory capture, where agencies like the Office of the Australian Information Commissioner (OAIC) and ASIC prioritize industry interests due to political or financial pressure, rather than enforcing laws protecting citizens.
Businesses Need to Do Better Too
There is only so much that ordinary people can do when they are required to hand over sensitive documents to access everyday services. Businesses should be collecting only the information they genuinely need, protecting it properly, and deleting or de-identifying it once they no longer have a proper reason to retain it. Instead, customer records can linger in old systems, cloud backups, accounting software, shared inboxes and databases maintained by third-party providers.
That creates an unfair arrangement. Companies get the convenience of collecting customer data, while customers carry much of the damage if it is lost. After a breach, the business may offer an apology, a call centre and perhaps a credit-monitoring subscription. The customer may spend months replacing documents, watching bank accounts, dealing with suspicious calls and trying to prove that a fraudulent transaction was not theirs.
Australia has privacy rules, including obligations around protecting personal information and disposing of it when it is no longer needed. But rules only work when they are properly enforced. Cybersecurity is still too often treated as an expense to minimise rather than basic business hygiene. “Sorry, it was a sophisticated attack” is not much comfort when your identity documents are now circulating somewhere they should not be.
Today’s story about a couple who lost $250,000 in a property-settlement scam is a sobering reminder that even careful people can be caught. The fraudulent payment instructions came from their solicitor’s genuine, hacked email account, and the transfer was made in person at a bank branch. The lesson is uncomfortable: banks will investigate, but they are primarily there to protect the bank, and the customer can still be left carrying much of the loss. We have become too comfortable assuming that a company, a bank or the government will automatically catch a problem and make it right. They might help, but the final responsibility for checking unexpected payment details – especially for a large transfer – still sits with us.
What You Can Actually Do
You cannot personally force every company to handle data properly. You can, however, make yourself a far less convenient target.
The best practical step is using a password manager. It creates a long, different password for every website and remembers them for you. Rather than trying to remember twenty variations of the same password, you only need to protect the password manager itself. It sounds like another thing to learn, but it is usually much easier than the current system of forgotten passwords, reset emails and notes hidden somewhere near the computer. We can help set one up if you would rather not tackle it alone.
Also, check your email addresses at Have I Been Pwned – it will show where your data was exposed. Finding your email there does not automatically mean someone is currently inside your accounts. Almost everyone who has been online long enough will find at least one old breach. It does mean you should change any password you have reused and be especially careful with suspicious emails that appear to know something about you.
Two-factor authentication is still worthwhile, particularly on email and financial accounts, but it is not a substitute for a strong, unique password. It will, however, stop attackers who know your passwords from trying to login to your accounts.
The goal is not to become paranoid or make every login painful. It is simply to stop using information that describes you as the lock on your digital life. Because a car model, a familiar number or an old favourite password might feel memorable to you. To someone trying to get into your accounts, it may be the first thing they try.