Cyber Heroes · Lesson 1
The password trap
Learning goal
Why password reuse is the single biggest household risk, and the two changes that fix it.
The problem isn't weak passwords — it's reused ones. When any site you use gets breached, attackers take that email-and-password pair and try it on your bank, email, and shopping accounts automatically. One leak becomes many.
The fix is two habits:
- Use a password manager. It generates and remembers a different strong password for every account, so a breach of one site can't unlock the others. You only remember one strong master password. (Built-in browser/phone options are fine; dedicated managers like 1Password or Bitwarden do more.)
- Prefer passkeys where offered. A passkey replaces the password with your phone or laptop's Face/Touch ID. There's nothing to type, nothing to steal, and it can't be phished.
A strong password is long before it's complicated — a passphrase of four random words beats "P@ssw0rd!". You don't need to change passwords on a schedule; only change one if it's been exposed.
Try today
- Install a password manager and add your email + bank logins first.
- Turn on passkeys for any account that offers them.
- Stop reusing the same password anywhere that matters.
Demo mode — your progress is not saved. Sign up to play the full game.