Security

Security center

Current advisories plus practical, plain-language steps to protect your accounts, your data, and your business. Anything urgent will also show in the status banner on the home page.

Current advisories

Medium

Paidwork breach reportedly exposes data of 23 million users

2026-07-22

A database allegedly taken from the microtask/reward platform Paidwork is circulating on cybercrime forums. Reports put the exposure at more than 23 million users and say it includes full names, email and home addresses, phone numbers, dates of birth, bank account numbers, transaction records, device/IP data, and passwords stored as hashes. Paidwork has not publicly confirmed the incident, so treat it as reported rather than verified.

What you should do: If you or anyone on your team ever signed up for Paidwork, change that password there and anywhere you reused it, turn on multi-factor authentication for email and banking, and watch your bank statements and inbox for targeted phishing. Use the self-check tools below to see whether your email shows up in known breach data.

Malwarebytes write-up ↗
Medium

Microsoft is retiring text-message (SMS) and voice sign-in codes

2026-07-22

Microsoft is phasing out SMS and voice codes for Microsoft 365 sign-in in favor of passkeys, which can't be phished or intercepted. Starting September 2026 you'll be nudged to set up a passkey, and Microsoft's own text/voice codes stop working on February 1, 2027 — after which anyone relying only on them must set up a passkey before they can sign in.

What you should do: If you sign in to Microsoft 365 with text-message codes, we'll move you to a passkey or your authenticator app over the coming months — nothing you need to do yet. Want to get ahead of it? See our passkey guide on the Help page, open a ticket, or call the TAC.

Microsoft's announcement ↗

Security best practices

Most breaches come down to a handful of habits. These are the ones that protect you the most, for the least effort.

How long would your password take to crack?

Illustrative only — real times depend on how a site stores passwords and the attacker’s hardware. The pattern is the point: every extra character multiplies the effort. Aim for 16+ characters (or let a password manager generate them) and the whole row turns green.

LengthNumbers onlyLettersLetters + numbers + symbols
6InstantInstantMinutes
8InstantMinutesHours
10SecondsHoursWeeks
12MinutesWeeksYears
14HoursYearsCenturies
16+DaysCenturiesEffectively never

Inspired by Hive Systems’ password table, which they refresh each year with current hardware — worth a look for the detailed version.

Use long, unique passwords

Length beats complexity. Use a different 16+ character password (or a four-word passphrase) for every account, and let a password manager like Bitwarden remember them so you don’t have to.

Turn on MFA — and move past text codes

A second step at login stops most account takeovers even if a password leaks. Turn it on everywhere it’s offered, especially email, banking, and admin accounts. Text-message codes are the weakest form and are on their way out — Microsoft is retiring SMS and voice sign-in for Microsoft 365. Use an authenticator app, and better yet a passkey or hardware key.

Use a hardware security key

A physical key (like the YubiKeys we deploy) is the strongest, most phishing-resistant sign-in there is — nobody can log in without the key in hand. Ideal for admins and high-value accounts.

Go passwordless where you can

Passkeys let you sign in with your device and a fingerprint or face instead of a password. There’s nothing to phish and nothing to reuse — enable them when a service offers.

Lock your screen

Lock your computer whenever you step away — Windows key + L, or Control + Command + Q on a Mac — and set it to lock automatically after a few idle minutes. An unlocked, unattended machine is an open door.

Slow down on suspicious messages

Phishing is the number-one way attackers get in. Don’t click links in unexpected “sign-in alert,” “invoice,” or “passcode” emails — go to the site directly. Unsure about a link or file? Check it on VirusTotal (see Help) or send it to us.

Keep devices updated and protected

Install operating-system and app updates promptly — most attacks exploit known holes that are already patched. Keep the endpoint protection we manage running, and keep your drives encrypted.

Don’t share logins

Everyone should have their own account, and credentials should never travel by email or text. When something genuinely needs sharing, we do it securely through Bitwarden.

Backups: your safety net against ransomware

If ransomware ever encrypts your systems, a good backup is what turns a catastrophe into an inconvenience — you restore and carry on instead of paying a ransom. We keep full-image (bare-metal) backups, so an entire machine or server can be rebuilt exactly as it was, not just a few files recovered. The rule worth remembering is 3-2-1: three copies, on two kinds of media, with one kept offline or offsite — because ransomware attacks the backups it can reach, and an offline or immutable copy is the one it can’t touch.