I recently got back from Door County, Wisconsin, and if you’ve ever been, you know there’s no place quite like it. One of the most memorable stops was Al Johnson’s Swedish Restaurant, famous for its grass turf roof and the goats that casually graze on top of it. And before you ask, yes, they mow the grass on the roof. It’s quirky. It’s fun. It’s unforgettable.
But the image of goats on the roof stuck with me for another reason. Just as I returned, a Forbes article headline started calling a recent breach the GOAT, the “Greatest of All Time,” of password leaks. Over 16 billion account credentials from Apple, Google, Facebook, and other major platforms had been compiled and dumped onto a hacking forum. This wasn’t one new breach. It was a massive compilation of past and present breaches, all bundled together into one searchable database.
In other words, the goats aren’t just on the roof. If we’re careless, they could already be inside the office.
The GOAT of credential leaks
This credential dump is one of the largest on record. What makes it particularly dangerous isn’t just the sheer number of accounts; it’s the searchable nature of the dataset. Cybercriminals don’t need to try endless guesses; they can simply query and find what they want.
Credentials are the modern skeleton key. Threat actors don’t need to break down the front door when they can just log in with your username and password. And thanks to infostealers, phishing kits, and AI-powered automation, attackers are more effective than ever at weaponizing stolen credentials.
This “GOAT leak” is a stark reminder that identity is the top-line attack vector. Whether personal or professional, our digital keys are at constant risk.
Identity as the frontline of attack
The perimeter defense model of firewalls, locked-down networks, and physical barriers has been eroded by the rise of cloud, SaaS, and remote work. Today, identity is the perimeter.
Consider the scale: according to Verizon’s 2024 Data Breach Investigations Report, over 80% of breaches involve stolen or weak credentials. Attackers don’t need to exploit zero days when they can simply buy or steal logins at scale. The underground economy for credentials has matured and complete “access packages” to corporate networks, with usernames, passwords, and even MFA tokens, are openly sold on dark web markets.
Attackers exploit identity through:
Phishing: Luring employees into surrendering login information.
Infostealers: Malware that silently records keystrokes and steals credentials.
AI-enhanced attacks: Threat actors using generative AI to craft convincing spear-phishing campaigns or mimic trusted voices.
The impact isn’t limited to a single compromised login. Because so many employees reuse passwords across personal and professional accounts, one cracked Netflix password may end up being the key to an enterprise cloud account. In other words, the line between personal life and work life has been blurred, and cybersecurity habits at home directly impact the office.
Password hygiene: from roof to reality
We’ve been talking about password hygiene for decades, yet it remains one of the weakest links in cybersecurity. Here are three critical reminders:
- Stop reusing passwords. Reused passwords are an open invitation for credential-stuffing attacks. A personal account breach can cascade into professional compromise.
- Adopt password managers and passkeys. Tools exist to generate and store unique, complex passwords. The industry shift toward passkeys, which use cryptographic authentication, offers a path to eliminating the password reuse problem entirely.
- Enable multifactor authentication (MFA) everywhere. MFA dramatically reduces account compromise, yet too many organizations treat it as optional. It needs to be a baseline requirement, not an upgrade.
Because when the GOAT of password leaks is here, we don’t want to be looking up, wondering what just trampled our roof.
Cybersecurity awareness month: extending the hygiene conversation
October is Cybersecurity Awareness Month, a time when organizations worldwide emphasize the small, practical steps that make the biggest difference. Think of it as an annual checkup, the moment to revisit not just passwords, but all the foundational hygiene items that secure the modern office.
Let’s walk through the essential areas every organization should reinforce this October.
Phishing resistance. Phishing remains the single most common attack vector. Despite years of training, people still click. Why? Attackers constantly adapt using AI to personalize messages, mimicking executives, or exploiting current events.
Office takeaway:
- Provide regular phishing simulations to build resilience.
- Teach employees the red flags: urgency, odd grammar, and unexpected attachments.
- Empower them with a “report phish” button to turn mistakes into learning moments.
Device hygiene. Work devices are gateways to sensitive data, and attackers know unpatched systems are easy wins. Outdated software and unprotected endpoints are like unlocked windows.
Office takeaway:
- Patch regularly and enforce automatic updates.
- Deploy endpoint protection with behavioral analysis.
- Limit admin rights to reduce damage if a system is compromised.
Shadow IT and SaaS hygiene. Employees love convenience. That often means signing up for unsanctioned apps with corporate credentials. Shadow IT not only fragments security controls but also widens the attack surface.
Office takeaway:
- Use SaaS monitoring tools to track app usage.
- Provide sanctioned, secure alternatives to common “shadow” apps.
- Establish a clear app approval process so employees don’t feel the need to go rogue.
Third-party and supply chain risks. Even the most secure office can be compromised through a partner’s vulnerability. Attackers increasingly exploit vendors as a back door into enterprises.
Office takeaway:
- Vet vendors with security questionnaires and audits.
- Require MFA and logging on third-party portals.
- Monitor and limit access to only what’s necessary.
Social media awareness. Social media is a gold mine for attackers gathering intel. Oversharing details about work, travel, or projects makes it easier to craft believable spear-phishing attacks.
Office takeaway:
- Train employees on what not to share publicly.
- Watch for impersonation scams (fake LinkedIn profiles of executives are common).
- Encourage staff to lock down privacy settings.
Backups and business continuity. Cyber hygiene isn’t only about prevention; it’s also about resilience. When ransomware or a breach occurs, backup often determines whether recovery takes days or months.
Office takeaway:
- Maintain regular, tested backups with both onsite and offsite copies.
- Ensure backup systems are segmented from production networks.
- Incorporate restoration drills into business continuity planning.
The human factor: why awareness is hard
Cybersecurity is often described as a “people problem.” Not because employees don’t care, but because attackers are skilled at exploiting psychology. They prey on urgency, curiosity, and trust. A well-crafted phishing email doesn’t look like a scam; it looks like an urgent request from a boss, a shipping notification, or even a tax refund alert.
Building awareness is hard because:
- Habits are sticky. People fall back on convenience, like reusing passwords, even when they know better.
- Information overload. Security teams flood employees with warnings, but without context, it becomes background noise.
- Lack of visible consequences. Unlike physical safety lapses (forgetting to lock a door), the risk from a missed patch or clicked link feels abstract.
To counter this, organizations must frame cybersecurity not as punishment but as shared responsibility. Training should be bite-sized, relevant, and continuous. Gamified phishing simulations, recognition for “security champions,” and storytelling about real attacks are far more effective than annual slide decks.
Top 10 cyber hygiene habits
To make Cybersecurity Awareness Month practical, here’s a quick-hit checklist every office should revisit:
- Use unique passwords for every account.
- Turn on MFA everywhere it’s offered.
- Store credentials in a password manager, not sticky notes.
- Embrace passkeys when available.
- Keep devices updated with the latest patches.
- Verify links and attachments before clicking, and when in doubt, report.
- Don’t install unauthorized apps or browser extensions.
- Separate personal and work accounts, don’t mix them.
- Lock down social media privacy settings.
- Ensure backups are tested and accessible during an outage.
These habits may seem simple, but when applied consistently across an organization, they build resilience and reduce risk dramatically.
Leadership’s role: setting the tone
Awareness is cultural. If leadership treats cybersecurity as a checklist item, employees will too. If leadership models strong habits by using MFA, attending training, and taking phishing simulations seriously, it signals that hygiene matters, and we become healthier.
Great leaders go beyond compliance. They tell stories that make cybersecurity relatable, they ask questions about security in meetings, and they make it clear that protecting data is part of protecting the mission of the organization. Just as workplace safety became ingrained over decades, so too must cyber hygiene become second nature.
IT service providers also have a responsibility to lead from the front. That means:
- Educating clients with plain-language explanations.
- Proactively monitoring for breaches and credential leaks.
- Encouraging adoption of tools and practices that make hygiene easier, not harder.
Cybersecurity awareness isn’t just IT’s problem. It’s everyone’s.
Closing the gate: keeping the goats outside
Standing at Al Johnson’s restaurant, looking at goats on the roof, was whimsical and safe. But in the world of cybersecurity, if we treat leaks and hygiene lapses lightly, those goats won’t stay on the roof; they’ll be inside, eating through the foundation of trust and business operations.
This October, let’s not just look up in wonder at the size of recent breaches. Let’s look around our offices, our accounts, and our daily habits. The GOAT of password leaks is a wake-up call.
The question is: Will we tighten our hygiene and keep the goats outside, or wait until they’ve already made themselves comfortable in the office?
Keith Johnson

Keith Johnson
With over 25 years of managed security experience, Keith Johnson is the Executive Vice President of Obviam. He leads a team of cybersecurity professionals dedicated to aiding clients with compliance security initiatives, enhancing operational risk management, and providing continuous visibility into cyber threat identification, resolution, and response. Before joining Obviam, Keith served as COO at Logically, where he spearheaded transformative strategic initiatives across managed services, professional services, and cybersecurity. Keith holds an MBA from the University of Phoenix and a BSBA in Computer Information Systems from the University of Louisville and is a passionate advocate for customer service excellence, cybersecurity awareness, and mentorship initiatives.
