2 min read
What's happening
Passwords get known in ordinary ways: they were once shared with a colleague who has since left, written somewhere visible, reused on a site that was breached, or handed over in a phishing scam. Any of these means the password can no longer be trusted, even if nothing has gone wrong yet.
What to do
Change your password to a new, unique passphrase, turn on two-factor authentication so the old one is useless anyway, and review your sessions. If it was shared in a scam, report it via reporting suspected fraud.
Related reading

Choosing a strong passphrase for your business account
A passphrase — three or four unrelated words — is both stronger and easier to remember than the old-style…
Read →
Setting up an authenticator app for two-factor authentication
Two-factor authentication adds a second step to sign-in: after your password you enter a six-digit code from…
Read →
Managing trusted devices and active sessions
Your account keeps a list of the devices and browsers currently signed in. Reviewing it — and removing…
Read →
Reporting suspected fraud to Credit Corp
If you spot something wrong — a scam pretending to be us, a strange login, an unexpected change — report it…
Read →Funding for UK limited companies
Credit Corp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.