logo

Exploiting Password Reuse on Personal Accounts: How to Gain Access to Domain Credentials Without Being on a Target’s Network: Part 1

ID: 1a9b3960-054a-5239-b810-1e9f6241dd55

STIX ID: report--1a9b3960-054a-5239-b810-1e9f6241dd55

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2016-02-15

Date Updated: 2026-04-27

Author: BHIS

...
...

This article documents a practical attack methodology for obtaining domain user credentials without network access by leveraging breached personal account credentials of an organization’s customers. The author describes collecting ~50,000 leaked customer credentials via PwnedList, correlating personal emails to employees using Pipl, converting names to the corporate email schema, and attempting logins against external services (e.g., OWA) to identify reused passwords and gain domain access, with recommendations to use password managers to reduce reuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.