> For the complete documentation index, see [llms.txt](https://pnpt.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pnpt.adot8.com/external-pentest-playbook/common-pentest-findings/historical-account-compromises.md).

# Historical Account Compromises

## Overview

Company accounts found in breached databases fall under this category. Passwords are commonly reused or changed a just a little bit which can give an Attacker an easy foothold into the organization.

The **Likelihood** of this is **High** along with the **Impact** being **High** as well, for obvious reasons.

The company can create a blocklist of the compromised passwords.

## Example

<figure><img src="/files/R8dolNw3dx4jlVl2Ezpl" alt=""><figcaption><p>Finding</p></figcaption></figure>

<figure><img src="/files/Pk8NStsXBBDr2h30jy3s" alt=""><figcaption><p>Passwords should always be obfuscated in pictures. Usernames can be shown in credential dumps</p></figcaption></figure>

<figure><img src="/files/2q0BwwMi1VGIJPw6F90Z" alt=""><figcaption><p>Remediation</p></figcaption></figure>
