Learn more about data breach detection
What is data breach detection?
To further improve the security of My Effectory accounts, we check whether newly chosen passwords have previously appeared in known data breaches. This is called data breach detection.
When you set a new password, we verify whether it exists in databases containing leaked passwords. If this is the case, you will be asked to choose a different, unique password.
Why do we do this?
Security audits and penetration tests show that reused or previously leaked passwords are one of the biggest risks to account security. Even if a password seems strong, it may still be unsafe if it has already been exposed in another data breach.
With data breach detection, we:
- reduce the risk of unauthorized access;
- better protect your account and research data;
- comply with current security standards and best practices.
What happens if my password is found in a data breach?
If the password you choose appears in a known data breach, you will see the following message:
'This password has been found in a known data breach. Please choose a new, unique password to continue.'
You can only change your password after selecting one that has not been found in a data breach.
How does this check work?
Effectory uses Have I Been Pwned - Pwned Passwords. This is a globally trusted dataset containing millions of passwords that have previously been exposed in data breaches.
Important to know:
- Your password is not stored and not shared;
- Effectory does not see or save your actual password;
- The check is performed in a secure and privacy-friendly way.
Tips for creating a secure password
To avoid seeing this message, follow these guidelines:
- Choose a unique password that you do not use anywhere else
- Use at least 15 characters
- Combine multiple words or a sentence instead of a single word
- Avoid common or predictable combinations
Using a passphrase is often the best option: easy to remember and well protected.
Want to know more?
If you would like to learn more about the underlying technology, visit:
- Have I Been Pwned – Pwned Passwords: https://haveibeenpwned.com/Passwords
If you have any questions or experience issues while changing your password, please contact our support team.