The Oklahoma Department of Education can't log in to its own website because the person who had the password left and didn't give it to anyone. They haven't been able to login for 2 years.
honestly based. everyone should have insecure passwords when working for a corporation. you should also message your local hacker group that the corporation is vulnerable
Setting unreasonably complex “strong password” requirements and making everyone choose a new password every three months to social engineer the use of sticky notes on screens
Sounds more like everyone used [realname][number] as their password because IT decided that changing your password every couple months is the most "secure". Even though it's not and causes [realname][number] passwords in the first place.
The adrenochrome factory made me do some shit like that so I started keeping a sticky note with the log in name and password on the monitor and the password for some other system in a clear text .txt file in the documents tab titled "[other system] password"
There may have been some password expiration set for the windows users, but I'm referring specifically to their database. My trainer literally told me that although I could change it if I wanted to, nearly everyone kept the same default password.