Kevin is an operations coordinator who keeps his work life and personal life separate. Different laptops for work and personal use. Different phone apps. He is careful, or so he thinks.
One evening, Kevin gets an email to his Gmail account. It says his Google account was accessed from an unfamiliar device. He clicks the link to review his account activity. The page looks right. He logs in, confirms everything looks fine and moves on.
What Kevin doesn't realize is that the login page was fake. His Gmail password is now in someone else's hands.
That same night, the attacker tries Kevin's Gmail password on his work account. It works. Kevin used the same password for both.
By morning, the attacker has read three weeks of internal emails and accessed two shared project folders.
Kevin's personal email was attacked using a fake security alert. The attacker used his personal password to get into his work account, because both passwords were the same. One compromised account became the key to the other.
Your personal email often holds password reset links for dozens of accounts, including work tools. If someone gets into your personal email, they can request a reset for almost anything connected to it. When personal and work passwords match, a single attack can cause damage in two places at once.
Use a different password for every account. Your work password must never match your personal email password.
Treat any security alert email with suspicion. Go directly to the website or app to check your account. Do not click the link in the email.
Turn on multi-factor authentication (MFA) for your personal email. Gmail, Outlook and Yahoo all support it at no cost.
Check which accounts are connected to your personal email address. Those accounts can all be reset by anyone who gets into that inbox.
If your personal email is ever compromised, tell IT immediately. They need to know so they can protect your work account.
Open your personal email account and turn on two-step verification or MFA right now. It takes less than two minutes and closes one of the most common entry points attackers use..
My work password is unique. I don't use it anywhere else.
My personal email has MFA turned on.
I know which accounts are linked to my personal email address.
I go directly to websites to check alerts. I don't click links in security emails.
I know to report to IT if my personal email is ever compromised.
Never use the same password for your personal email and your work account. If one falls, the other should stay standing.