When a password appears in a stolen data set, criminals may try to use it almost immediately.
One common method is called credential stuffing. Attackers take a known email address and password combination and test it against many popular services. If the user reused that password, one breach can lead to access at several other sites.
Business email accounts are a major target because they can contain invoices, customer conversations, password reset messages, and other useful information.
If a password is known to be exposed, it should be changed anywhere it was reused. MFA should also be enabled, especially on business systems.
Businesses should not wait for proof that an attacker has already logged in. Exposed credentials should be treated as a warning.
A good response also includes checking sign-in history, reviewing mailbox forwarding rules, and looking for unusual account changes. Stolen credentials can be the first step in a larger attack.
