Skip to content

How to manage passkeys for your Google Account

Passkeys are digital keys that combine cryptography and biometrics to create a more secure and convenient way to authenticate online identity. Instead of remembering and typing a password, you can use a fingerprint reader or Face ID to verify your identity and gain access to your online accounts.

 

What are Google’s requirements for passkeys to work?

To use passkeys for your Google Account, your authentication device must meet the following requirements:

  • An Android device that runs at least Android 9.

  • An iOS device that runs at least iOS 17.

  • A macOS device that runs at least Ventura.

  • A Windows computer that runs at least Windows 10.

  • If you use a hardware key for passkey authentication, check whether it supports the FIDO2 protocol.

  • If you use NordPass for passkey management, make sure you have the app or extension installed on your device.

 

How to set up a passkey for your personal Google Account

Google Account settings follow a similar layout on different devices, so you can follow the setup instructions to your convenience:

  1. In your Google Account settings, select the “Security” tab.

  2. Under “How you sign in to Google,” select “Passkeys and security keys.” You may be asked to verify your identity.

  3. Select “Use passkeys” to switch on passkey authentication. Then, select “Create a passkey.” You will be prompted to unlock your device.

  4. That’s it! You can now use a passkey to access your Google Account.

If you use your Google Account on multiple devices, you can set up unique passkeys for each one.

In the same Google Security settings, you can choose to use passkeys as your primary login method:

  1. Under “How you sign in to Google,” select “Skip password when possible.”

  2. Toggle on “Skip password when possible” and return to settings.

 

How to set up passkeys for Google Workspace

If your organization uses Google Workspace, you may be able to set up a passkey as the primary or secondary authentication method. First, your organization administrator has to switch on passwordless authentication for all Workspace accounts.

For admins:

  1. Log in to your Google Workspace account.

  2. In the Admin Panel, go to the “Security” tab.

  3. Under “Authentication,” select “Passwordless.”

  4. Select “Skip passwords.” For more granular controls, you can adjust this setting for specific departments in your organization.

  5. Optionally, check the “Allow users to skip their password and authenticate with a passkey” box to make passkeys the primary authentication method.

  6. Select “Save.” All users in your organization will now be able to set up a passkey. If you completed step 5, the passkey set up will be mandatory.

For end users:

  1. In your Google Account settings, select the “Security” tab.

  2. Under “How you sign in to Google,” select “Passkeys and security keys.” You may be required to enter your account password to proceed.

  3. Select “Use passkeys.” Then, select “Create a passkey.”

  4. You will be prompted to unlock your device to create the passkey.

  5. You can now use a passkey as an authentication method.

Depending on your organization’s settings, the passkey will work either as a primary or secondary authentication step. If you use more than one device to access Google Workspace, you can create unique passkeys for each one.

 

How to save and manage passkeys for your Google Account in NordPass

Having a Google Account passkey tied to your device can pose some challenges. If you suddenly lose access to that device, you won’t be able to use the passkey to log in to your account. While you can resort to alternative login methods like entering your account password, a simpler solution is creating a passkey with a third-party provider like NordPass.

 

Saving, logging in, and managing your Google Account passkey in NordPass

To set up a passkey for your Google Account, you need to use the Nordpass browser extension.

  1. Log in to your NordPass account to keep it running in the background.

  2. In your Google Account settings, select the “Security” tab.

  3. Under “How you sign in to Google,” select “Passkeys and security keys.”

  4. Click “Use passkeys” to switch on passkey authentication.

  5. Click “Create a passkey.” You may be prompted to enter your account password.

  6. You will see a NordPass pop-up prompting you to create a passkey. Add a title to the passkey and select “Create.”

  7. In the Google Account screen, click “Done.”

That’s it! You’ve created a Google Account passkey with NordPass. Thanks to synchronization, you will be able to use it to log in to Google on any device that has NordPass installed.

To manage your passkey, go to your NordPass vault. In the “Passkeys” tab, locate your Google Account passkey. Click the three dots on the right side of this passkey and select “Edit.” You can add extra information using custom fields.

If you want to delete your NordPass passkey, you can do so in the Google Account security settings. Alternatively, you can switch off passkeys as the primary authentication method, as detailed in the instructions above.

  1. In the Security settings, select “Passkeys and security keys.”

  2. You will see a list of passkeys connected to your Google Account. Select the “X” next to the NordPass passkey.

  3. Confirm your selection. If you want to add a NordPass passkey to your Google Account in the future, follow the previous instructions.

Note that disconnecting NordPass from your Google Account passkey options doesn’t automatically remove the passkey from your vault. To remove it, click the three dots on the right side of the passkey in your vault and select “Move to trash.” 

 

Using Google to sign in to your Nord Account or Nord Business Account

It’s not recommended to store both your Google account password and passkey in NordPass if you use Google as an authentication service to sign in to NordPass. If you are using Google single sign-on (SSO), you need to log in to your Google account first before unlocking NordPass. For this reason, you should not depend solely on NordPass for accessing your Google account.

However, you can still use passkeys to access your Google account. There are two workarounds to use passkeys for the Google account used to log in to NordPass:

Google offers passkey authentication as an alternative to passwords, which means that you can use both a passkey and a password to log in to your Google account. A password can be used when signing in to NordPass, while a passkey stored in NordPass can be used to log in to your Google account in other cases.

Alternatively, you can create multiple passkeys for your Google account and use the one not provided by NordPass to log in to your NordPass account. Another passkey, provided by NordPass, can be used to log in to your Google account whenever it’s needed.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Can Slack admins read your DMs?

If you use Slack for work, chances are you’ve sent a message or two that you hoped only your teammate would get to see. It’s all right, we’ve all done it—expecting a bit of privacy in what feels like a one-on-one conversation. But is Slack privacy even a thing? Are your DMs just between you and the person you’re chatting with? Let’s find out.

Can your boss see your Slack messages?

It might not be what you want to hear, but yes—your manager could potentially read your private Slack messages. That said, it’s not as simple as them just opening up your chat history. Whether they can access your messages depends on the Slack plan your company is on, its Slack workspace settings, and the established internal privacy policies.

In other words, no one can just casually peek into your DMs. Your employer would either need your permission or have to go through a formal process—usually by submitting a request to Slack and providing a valid reason, like a legal or compliance investigation. So, they’d only be able to export messages from your private channels and DMs if Slack approved their request.

Should that ever happen, don’t bother editing or deleting your DMs—it won’t make any difference. Slack stores all the original versions of your messages on its servers. So, once you send something, it’s technically there for good.

Also worth noting: anything you post on public channels is automatically visible to everyone in the Slack workspace—no special permissions needed.

So, can Slack admins read user DMs?

As you can probably guess, the answer is still a “yes”—but with a few caveats.

Slack admins in your company are responsible for things like access permissions, legal compliance, and integrations. Basically, they’re the ones running the Slack show. This means that, in some situations, they can technically have access to your direct messages in Slack. But here’s the key part: they can’t do it by default. There are data privacy rules and Slack policies in place to prevent casual snooping. Access to private messages only happens under specific circumstances.

If your company uses Slack’s Enterprise Grid or Business+ plan, some admins—usually people working in IT, compliance, or HR—can be given the option to export data from Slack, including all private messages. It’s a feature mostly meant for large organizations that need to stay on top of compliance and legal requirements. But for this to happen, admins have to put in a request directly to Slack—and Slack won’t approve it unless they’ve got a really solid legal or compliance reason.

On Pro and Free plans, things are a lot more limited. Admins can only export messages from public channels. That said, in the case of a serious breach or legal investigation, even on these plans, a company can submit a formal request to Slack for access to private data. And if the situation is serious enough, Slack will likely grant it.

So, are your Slack messages private? Technically, yes—at least until something happens that prompts an investigation. If that day comes, Slack admins could gain access to your messages so they can be reviewed.

Types of data that can be exported from Slack

With all this talk about who can download what on which Slack plan, it’s totally fair if you’re feeling a bit dizzy and wondering what it means for the privacy of your messages. To help clear things up, check out the table below—it lays out exactly what kind of data admins can access, based on the company’s Slack plan.

 FreeProBusiness+Enterprise Grid
Exporting messages from public channelsYesYesYesyes
Exporting messages from public channels, private channels, and direct messages*  YesYes
Exporting messages by conversation type or member   Yes
Exporting a detailed list of channels*  YesYes
Export Slack data for a single user*   Yes

*Workspace owners and organization owners need to submit a request to enable these types of exports.

So if you’re still wondering, “Can Slack admins see private channels?”—the short answer is “technically, yes.” However, their access depends on which Slack plan the company is on, and whether Slack approves their request to check your private messages.

Is it similar with tools like Microsoft Teams?

Yes, very much so. Just like with Slack, your employer can get access to your messages on Microsoft Teams—provided they’re on the right subscription plan. The only difference (though it might feel like a big one) is that with MS Teams, admins do NOT need Microsoft’s approval to view private messages within the organization.

So, if your company is on the E3 or E5 Office 365 Enterprise plan, your admins can use features such as eDiscovery to search for and export data like:

  • One-on-one, group, and meeting chats

  • Private channel messages

  • Meeting chat logs

  • Recorded meetings and transcripts

  • Files that were shared as attachments

That said, it’s probably not like someone is sitting there reading your messages all day. These data monitoring tools are mainly in place for security, compliance, and legal reasons—for example, if there’s a data breach. In day-to-day operations, your messages are most likely just stored safely in the background.

But if you’re specifically asking: “Can Microsoft Teams be monitored by my boss?”, the answer is: “Yes, it sure can be.”

How to act responsibly on Slack

Since Slack is meant for work-related communication, it’s probably not the best place to overshare or drop sensitive info without a second thought. Here are a few handy tips to help you stay clear, professional, and safe while chatting with your team—without putting yourself (or anyone else) in a tough spot.

Be respectful—no matter who you’re chatting with

Everyone in your organization deserves to be treated with kindness and respect. As part of the team, you must always communicate in a professional manner—whether you are chatting in person or online. If someone’s giving you trouble, it’s best to talk to your supervisor about the situation, without letting your emotions take over and writing something on Slack that could negatively affect how others perceive you.

Be mindful about sharing personal stories

It’s perfectly normal for people to form friendships at the office—after all, many—if not most—of us spend more time with our coworkers than with our friends outside of work. That said, it doesn’t mean you should treat Slack like your personal messaging app and use it to have casual, buddy-buddy conversations with your teammates. Keep in mind you’re still at work, and some things are better saved for when you’re hanging out with the team outside of work hours.

Avoid sharing confidential business information

What’s really important is that you use Slack for things like collaborating with your team on your daily tasks, scheduling meetings, and sharing updates on marketing campaigns. This is to say that you should never put sensitive data—like client information, company secrets (such as proprietary designs), passwords to business accounts, or credit card details—in a post or message on Slack. If you need to share something sensitive, like corporate credentials or credit card information, it’s better to use a tool like NordPass, which keeps everything encrypted. And if you’re unsure about what’s safe to share on Slack, it’s a good idea to check with your IT department for guidance.

Stay informed about Slack’s privacy settings

Remember that your employer could potentially access your private messages and channels at any time. Right now, your messages are usually only reviewed by admins if there’s a serious investigation, like checking if you’ve crossed any lines or if your actions contributed to a legal issue or data breach. But these rules could change, so it’s a good idea to stay on top of any updates to your organization’s Slack privacy policy in the future.

Bottom line

If your company uses Slack, your employer might be able to see your messages in private chats and channels—but it depends on your company’s Slack plan and whether Slack agrees that your boss has a good reason to see your DMs.

That said, it’s always a good idea to keep things professional in your Slack messages and avoid sharing sensitive information like customer data or corporate passwords. If you do need to share business credentials with your teammate, make sure to do it using a secure password manager like NordPass to keep everything safe and sound.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Password rotation: A practical overview

All these numbers tell the same story: Passwords stay valuable to attackers because organizations resume them or don’t change them often or intelligently enough. Companies therefore need a way to control the lifespan of any password an attacker might obtain. And that control comes with password rotation.

What is password rotation?

In cybersecurity, password rotation is the practice of regularly replacing a password with a fresh one in order to limit its usable lifespan and the time a bad actor has to exploit it, if compromised. The basic idea is simple: Change passwords regularly to minimize credential-related risks.

The rotation interval can be measured in days, weeks, or months, depending on the sensitivity of the account and company policies. A domain admin credential securing production servers might rotate every week, whereas an internal account might rotate every other month. Rotation schedules are frequently set inside a password rotation policy that specifies cadence as well as complexity requirements.

Regulatory frameworks such as NIST (SP 800‑63B) no longer mandate a fixed 90‑day reset for every account, but they do require event‑driven changes whenever a compromise or leak is suspected.

For most businesses, the challenge with regard to password rotation is executing it at scale without negatively affecting productivity or introducing new risks due to poor implementation.

Why is password rotation important?

Today, bad actors don’t rely as much on zero-day exploits or similar security gaps. Instead, they rely on stolen credentials. A systemic rotation policy can help companies deal with these risks.

First, a password rotation policy shrinks the attacker’s window. If a contractor’s password changes every quarter, a breached database discovered six months later lands too late. Second, such a policy cleans up dormant access. For example, when an employee leaves, the next scheduled rotation automatically invalidates the login in case HR forgot to disable or remove it. Third, it showcases due diligence to auditors and regulators and can ease your compliance journey whether it’s for – PCI DSS, ISO 27001, NIST, or SOC 2.

Password rotation pitfalls

While well intentioned, a password rotation policy can backfire when not executed properly.

Excessive rotation

When change frequency is set to an unrealistic cadence – say every seven days – users resort to shortcuts like sticky notes or simple and quick changes (“PasswordMay01!” becomes “PasswordMay08!”).

Repetitive password usage

If policy enforces rotation but not history checks, employees circle through a small set: Qwerty2024!, Qwerty2025!, Qwerty2026!. Remember – attackers who know yesterday’s formula can guess tomorrow’s.

Pattern‑based passwords

Humans are predictable, especially when it comes to password changes: Adding the next number, changing capitalization, or swapping summer for winter or vice versa are all very obvious.. Automated password‑spray tools can exploit these patterns with minimal variation.

Avoiding these pitfalls requires thoughtful policy design and the right automation settings.

 

Is password rotation enough?

Password rotation yields the best results when it’s a part of a broader security framework that adheres to modern security requirements. The latest NIST SP 800‑63B guidance no longer recommends forcible resets for ordinary users who have not exhibited signs of a compromise. Instead, it prescribes event‑ or risk‑driven rotation for privileged, shared, and high‑value accounts. It also requires multi‑factor authentication (MFA) as an extra layer of security.

MFA blocks most automated account takeovers even when the password remains unchanged, yet it is not a cure-all. Mobile MFA fatigue attacks and prompt bombing show that multi-factor authentication can – in fact – be phished. Rotation therefore works in tandem with MFA, ensuring an attacker cannot get their hands on the same credential months later after social engineering the one-time password.

Least‑privilege design is the third part of the equation: An attacker who compromises login details of someone in marketing should not automatically gain access to production databases. To reduce such risks, apply frequent rotation to the logins that can do real damage: admin, root, and any shared service accounts. In this case, the policy protects what matters without adding unnecessary burden to low-risk users.

A pragmatic rotation policy

An effective rotation policy must bridge security requirements with day‑to‑day practicality. It should give administrators a clear, verifiable checklist while sparing low‑risk users unnecessary friction and hassle.

  1. Group passwords by impact. Rank each password according to the damage it could cause if stolen.

  2. Match cadence to risk. Rotate high‑impact passwords, say, every 30 days or immediately after any security incident. Medium‑impact passwords could change every 90 days. Low‑impact credentials may update only when a role changes, a compromise is detected, or a regulation requires it.

  3. Automate every change. Use APIs, scripts, or a privileged‑access‑management (PAM) platform so passwords can be renewed automatically.

  4. Record the evidence. Send detailed rotation logs to your SIEM system. In case of an audit, auditors need to see exactly what changed, when it changed, and which user or system triggered the action.

How NordPass can help

NordPass provides password rotation tools that remove guesswork without adding busywork. Every password is stored in a zero‑knowledge vault encrypted on the user’s device, so neither NordPass nor attackers can read any of the vault’s data in transit or at rest.

Through the Admin Panel, security teams can set company‑wide rotation rules: which groups must change passwords, how often, and what length or character mix each new password must meet.

NordPass then reminds users when a change is due and records the update. In an instance when HR disables an account through Azure AD, SCIM, or Google Workspace, NordPass locks the vault at the same moment, cutting off access to shared passwords before they can be reused or leaked.

Rotation is faster when the right password is only a click away. NordPass comes with a free password generator that creates strong, unique strings of characters on the spot, so users never recycle old favorites.

To see how these controls fit into a larger security stack, visit NordPass Business and explore features like SSO, breach monitoring, and policy templates that support compliance frameworks such as ISO 27001 and NIS 2.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to manage passkeys on Android

Wait… what are passkeys, again?

For those who don’t know, passkeys are a new authentication method designed specifically to allow users to log in to their online accounts securely—but without the need for passwords. The goal is to leverage technological innovation to improve both cybersecurity and user convenience. How does it work?

Each passkey uses a pair of cryptographic keys: one public key stored on the app or website’s server, and one private key that stays on your device. When you log in, the server sends a request with the public key to your device, which then responds with the private key. If both keys match, you’re granted access.

Since the private key is safely stored on your device and never leaves it, the risk of unauthorized access is much lower. That’s also because passkeys, unlike passwords, can’t be cracked, guessed, or easily stolen. And the cherry on top is that, with passkeys, you don’t have to remember or type in anything—you can just quickly and safely access your accounts.

Passkey requirements for Android

At this point, it’s worth noting that not all Android versions or devices fully support passkeys. So, if you’re thinking about going passwordless, you should keep that in mind, especially if you plan to use a third-party passkey provider like NordPass. Here’s a quick breakdown of which Android versions support passkeys—and how far that support goes.

Android versionPasskey support
Android 9 (Pie)Basic passkey support—works only with external security keys (e.g., YubiKey).
Passkeys are stored locally (no cross-device synchronization).
Android 10/11/12Improved integration with browsers and apps via WebAuthn.
Android 13Full native passkey support.
Integrated with Google Password Manager for syncing across devices.
Biometric or screen lock authentication.
Android 14Support for third-party passkey providers (e.g., NordPass).
Enhanced multi-device syncing and usability.
Android 15More seamless cross-platform passkey usage.
Improved user experience in apps and websites.

As for the other software and hardware requirements for running passkeys on Android, the good news is that most modern Android devices already meet them. This means that if you purchased your device in late 2023 (when Android 14 was launched) or later, it most likely has full support for third-party passkeys.

Still want more details? Here are the key technical requirements your Android device must meet to use passkeys:

  • Your device must have a trusted execution environment (TEE) or secure element (SE) component for storing cryptographic keys.

  • Biometric authentication or a screen lock must be enabled.

  • The Google Play Services app needs to be up to date.

  • You must have an internet connection to sync passkeys across devices.

How to create and save a passkey on your Android device

The process of setting up, creating, and storing passkeys on your Android device can be a bit different depending on a few factors—like which version of Android you have, the passkey provider you’re using (such as Google’s native option or a third-party service like NordPass), and the websites or services you want to use passkeys for. That said, creating passkeys usually involves the following steps:

  1. Enable the lock screen on your Android device (if you haven’t already).

  2. Go to a website or app that supports passkey logins.

  3. Choose to sign up with a passkey option. (If you already have an account, go to the account settings and find the passkey login option.)

  4. Follow the on-screen instructions to create a passkey.

  5. Confirm and save the passkey using your device’s built-in biometrics.

Once confirmed, your new passkey will be stored in your default passkey provider—if you have Android 14 or later, you can choose that to be either Google Password Manager or a third-party solution like NordPass.

How to log in with a passkey on Android

Logging in with a passkey to a website or app is super easy—way easier than using a password. Here’s how it goes:

  1. Go to the website or open the app where you’ve saved your passkey.

  2. Select the option to log in with a passkey (it’ll usually say something like “Use passkey” or “Sign in with passkey”).

  3. Authenticate by following the on-screen prompts (like using your device’s fingerprint scanner or Face ID).

That’s it! If the two cryptographic keys match, you’ll get instant access to your online account or app.

Using passkeys on Android with NordPass

While NordPass is best known as a password manager, it’s also fully equipped to support passkey technology across all major platforms and browsers—and it was one of the first to do so! This is because we believe passwordless authentication is the way forward, and we want you to experience it with top-tier security and ease.

Getting started with passkeys in NordPass is really simple. Just install the NordPass app on your device and set it as your primary passkey manager in your device’s “Passwords and Accounts” settings. Once that’s done, NordPass will prompt you every time you want to create or log in with a passkey, guiding you through the process.

Managing your passkeys in NordPass is also a breeze—they’re stored securely in your vault under a dedicated item category. There, you can easily see when each passkey was created, share them with trusted people without compromising your security, and even add secure notes to help you keep track of important details for any service or account.

For a step-by-step guide on using passkeys with NordPass, check out our Help Center article, where we cover everything from passkey setup to login.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

AI is now being used to guess your business passwords

When you think of a password manager, you probably think about its ability to generate unique and secure passwords for every account. While that’s true, password managers also protect against a range of technical threats you might not expect—threats that can devastate businesses, from phishing attacks using Punycode domains that trick employees into revealing corporate credentials to keyloggers and brute-force attacks on admin panels that expose sensitive systems. 

In 2025, with 74% of all data breaches involving some kind of human element or error and costing companies millions in downtime and fines, password managers like NordPass are far more powerful than just a password generator—they’re a business’s shield against financial and reputational ruin. In this article, we’ll break down 5 cyber threats and explain exactly how password managers defend against them.

1. Phishing

Phishing is a cyberattack in which attackers trick users into revealing sensitive information, like usernames and passwords, by creating fraudulent websites that mimic legitimate ones. This type of attack is a huge problem, especially for businesses losing data to fake login pages. In 2025 so far, phishing has accounted for over 36% of all data breaches, and about 3.4 billion phishing emails are sent every day. These numbers show how widespread and persistent phishing has become.

These attacks often rely on techniques like Punycode domains, hijacked subdomains, and typosquatting to deceive users. Phishing links are commonly distributed via email, SMS, or malicious ads, directing victims to fake login pages where their credentials are captured. 

For example, an attacker might create a domain like http://www.goоgle.com (using the Cyrillic “о” instead of the Latin “o”), which looks nearly identical to http://www.google.com but directs users to a malicious site. Alternatively, attackers might exploit a misconfigured DNS setting to hijack a subdomain, like secure.login.example.com, making the phishing site appear as if it belongs to the legitimate example.com. In typosquatting, domains like http://www.faceboook.com or http://www.pay-pal.com are registered to exploit common user typing errors.

asset2

Image: An example of an open-source phishing kit

Password managers protect against phishing by using exact domain matching when autofilling credentials. When a user visits a phishing site, even if the domain visually resembles the legitimate one, the password manager recognizes the mismatch and refuses to autofill credentials. 

For instance, if credentials are saved for http://www.paypal.com, they will not be provided on a phishing domain like http://www.paypa1.com. This prevents users from unknowingly submitting their passwords to fraudulent sites.

Another layer of protection comes from eliminating the need for manual password entry. Password managers use secure browser APIs or system-level frameworks like Android’s Autofill API or iOS’s AutoFill to inject credentials directly into login fields. This bypasses keyboard input entirely, preventing phishing websites from capturing credentials through keylogging or fake form fields.

2. Credential stuffing

Credential stuffing is a type of cyberattack in which attackers use large sets of stolen username and password combinations, often obtained from previous data breaches, to gain unauthorized access to user accounts on different platforms. 

For businesses, this is a huge threat—employees reusing personal passwords for work accounts can open the door to attackers who might use a breach of a random website to access corporate emails, CRM systems, or financial tools, costing companies millions in stolen data or ransomware payouts. The attack relies on the assumption that many people will reuse the same credentials across multiple websites and services. 

Automated tools are used to test these credential pairs across numerous sites at scale, often with the help of bots, enabling attackers to exploit any reused credentials efficiently.

asset5


Image: Cybercrime forum discussions focusing on credential-stuffing tools

For example, if an attacker acquires a leaked database from a breached e-commerce platform, they might use the stolen email-password pairs to attempt logins to banking, social media, or other sensitive services. Automated credential stuffing tools, like Sentry MBA or OpenBullet (as seen above), can test thousands of combinations per minute, often evading basic security measures like rate limiting or CAPTCHA using proxies.

Password managers provide a strong defense against credential stuffing by generating and storing unique, complex passwords for every account. Since credential stuffing depends on the reuse of credentials across multiple platforms, having a distinct password for each account renders the attack ineffective. Password managers make this feasible by securely storing and autofilling these unique passwords, so users don’t need to remember them.

NordPass offers a valuable feature called Password Health. This feature scans all passwords stored in your vault and checks how vulnerable they are, giving you a clear view of your password security. It alerts you about weak, reused, or compromised passwords, helping you take necessary actions to strengthen your online security. This is an effective way to ensure your passwords aren’t putting your accounts at risk.

3. Brute-force attacks

Brute-force attacks involve systematically guessing passwords by trying all possible combinations, often with the help of automated tools. While most modern consumer platforms include protection mechanisms like two-factor authentication (2FA), CAPTCHA, or account lockouts to prevent these attacks, there are edge cases where brute-force attacks remain viable. This is particularly true for public-facing admin portals or legacy systems that lack built-in protections by default.

For instance, if your business runs a WordPress site without security plugins, it may be leaving its admin panel (/wp-admin) exposed to brute-force attacks. Attackers might use tools like Hydra or WPScan to test thousands of password combinations, starting with weak or default credentials like admin with password123. Without additional configurations, some versions of these platforms remain vulnerable, as they typically don’t include features like rate limiting or CAPTCHA out of the box. Users must proactively install plugins to secure these areas.

asset4

Image: An example of WPScan brute-force functionality

Password managers provide an important layer of protection against brute-force attacks by encouraging the use of strong, complex passwords that are resistant to guessing. A password manager can generate a password like Tx8&@K1p!Rv2#, which is more difficult to crack, even with the most advanced brute-force tools. Furthermore, password managers ensure that users don’t rely on weak or default credentials and prevent the reuse of passwords across different systems, which attackers could exploit.

NordPass, in particular, not only generates strong, complex passwords but also stores them securely. Users have the flexibility to determine the complexity of their passwords, allowing them to create passwords that are both highly secure and tailored to their needs. Importantly, NordPass encourages the use of unique passwords for each account, ensuring that even if one set of credentials is exposed, it cannot be used to access other systems.

In addition to generating and securely storing strong passwords, NordPass also includes its built-in Authenticator feature, which can be used as an authenticator app. This adds an extra layer of security by enabling 2FA for your accounts, making it a lot harder for attackers to gain access, even if they manage to crack a password. The NordPass Authenticator is a convenient and secure option to further bolster your defenses against brute-force and other types of attacks.

With a password manager, the only password users need to remember is their master password—the key to unlocking their vault of securely stored credentials. Once this master password is entered, the manager handles the rest, automatically filling in passwords for all other accounts. This removes the burden of remembering each password individually, while still keeping your accounts protected with strong, unique passwords.

Although brute-force attacks are not a genuine risk for most consumers due to modern protections, they still pose a threat in specific scenarios, like unsecured admin portals or systems without rate limiting. By using a password manager to create and store strong, unique passwords, users add an extra layer of defense against this type of attack. In these edge cases, password managers provide protection, ensuring that even if other security layers are missing, accounts are protected with passwords that are resilient to brute-force attempts.

4. Keyloggers

Keyloggers are malicious tools designed to record every keystroke a user types, allowing attackers to steal sensitive information like usernames, passwords, and other private data. Companies can leak important information if keyloggers hit employee devices. They are often deployed as malware through phishing emails, malicious websites, or software downloads, but they can also exist as physical hardware devices installed between a keyboard and a computer.

Software-based keyloggers function by intercepting keyboard inputs at different stages within the operating system. They often utilize API hooks to monitor and record keystrokes as they are being processed. 

For example, a keylogger on a Windows system might use the SetWindowsHookEx function to intercept keystrokes in real time. This allows it to capture credentials and other private information as they are typed. Clipboard loggers, another variation, monitor copy-paste actions to steal sensitive data like passwords copied for use.

asset3

Image: Guides being shared on a cybercrime forum on how to write keyloggers

Password managers effectively counter these risks by eliminating the need for manual password entry. Instead of requiring users to type their passwords, password managers use secure autofill mechanisms to directly input credentials into login fields. On web browsers, they inject credentials through direct interaction with the DOM, while on mobile devices, they use system-level frameworks like Android’s Autofill API or iOS’s AutoFill. These methods bypass the keyboard entirely, rendering keyloggers unable to capture any useful data during the login process.

Although a keylogger could potentially capture the master password during the initial login to the password manager, modern password managers mitigate part of this risk by minimizing the need for repeated master password entry. Many password managers support biometric authentication, like fingerprint or facial recognition, allowing users to unlock the manager without typing anything after the initial login. Biometric data is securely stored on the device and cannot be intercepted by keyloggers, making it a highly secure and convenient method of authentication.

5. Database leaks

Database leaks occur when attackers gain unauthorized access to databases storing sensitive user information, such as usernames, passwords, and personal details. Businesses face huge losses when customer data spills out. These leaks often happen due to issues like web-application vulnerabilities, misconfigured servers, or outdated software. 

Once a database is leaked, attackers can use the stolen credentials in further attacks, like credential stuffing (as mentioned above) or direct account takeovers, particularly if the passwords are weak or reused across multiple accounts.

For example, in a typical breach, a compromised database may store passwords in plain text or use weak hashing algorithms like MD5 or SHA-1, which are vulnerable to tools like Hashcat. 

Hashcat, a high-performance password-cracking tool, allows attackers or researchers to brute-force or perform dictionary attacks on leaked password hashes to recover plaintext passwords. Even strong passwords can become vulnerable if the hashing algorithm is outdated or poorly implemented (e.g., missing salting).

asset6

Image: A researcher or cybercriminal trying to use Hashcat to crack passwords

Password managers protect users from the consequences of database leaks in several key ways. First, they encourage the use of unique, strong passwords for every account. This ensures that even if one set of credentials is exposed in a breach, it cannot be used to access other accounts. For example, a leaked password from an e-commerce site would not provide access to a user’s banking or email accounts if unique credentials were used.

In addition to promoting password uniqueness, password managers generate and store randomized passwords that are resistant to brute-force attacks. A password like T&$9jf@3#1Px2! is much harder to crack using tools like Hashcat compared to common or weak passwords. Password managers also make it easy to update compromised passwords quickly by identifying affected accounts and help in generating secure replacements.

Many password managers further enhance protection by integrating breach monitoring tools. For example, NordPass offers an integrated Data Breach Scanner that provides real-time alerts when your email or credit card details appear in a data breach or leak. This feature allows you to respond proactively by updating your credentials before attackers can exploit the compromised data.

NordPass follows a zero-knowledge architecture, meaning it never has access to user passwords. Additionally, NordPass provides businesses with a free tool to check for potential leaks through its dark web monitoring service. This service helps companies detect any exposed employee or customer data across the dark web, adding an essential layer of defense for businesses concerned about database breaches.

Get protection with NordPass

Credential theft can cause serious problems for businesses of all sizes. When someone’s login details are stolen, it can lead to unauthorized access to accounts, financial scams, identity theft, or even corporate spying. Hackers often sell stolen login details on dark web marketplaces, making them available to criminals around the world.

If a hacker gets into someone’s email, they can reset passwords for other accounts, giving them access to even more services. To protect against credential theft and its harmful effects, it’s important to use strong passwords and a password manager.

Start taking control of your security today. As a business owner, you have the power to strengthen your company’s defenses by mandating the use of a password manager. NordPass Business makes it easy to implement best practices across your team, protecting against the very threats we’ve discussed. 

asset1

NordPass also constantly passes security audits, ensuring it meets the highest levels of protection. This helps your business achieve information security standard compliance (like ISO and NIS2), which protects against high penalties for non-compliance and potential data leaks.

Get started with a complimentary 3-month trial by clicking here and using the code “danielk”—no credit card required. Don’t wait until it’s too late; secure your business now.

Disclaimer: Examples are provided for informational and educational purposes only. NordPass does not endorse, promote, or support their use and has no affiliation with them. Readers are strongly advised to comply with all applicable laws and regulations. All trademarks mentioned are the property of their respective owners.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.