Credential stuffing
Reuse leaked username/password pairs on other sites. Your 'unique' login was the same as the breach last year.
Credential stuffing takes usernames and passwords spilled from one service and tries them on others. It works because people reuse. Related ACSC language: credential theft — once the proof of identity is stolen, the thief inherits the privileges.
Unique passwords in a manager, MFA, and checking whether your corp domains appear in known dumps. Detect impossible travel and burst logins. Do not lecture users while SSO still shares one tired password to eight SaaS apps without MFA.
Fact source: ASD's ACSC glossary.
