Skip to main content
August 25, 2026

Using Watchtower to catch reused passwords across client accounts we manage, caught something scary last month

  • August 25, 2026
  • 0 replies
  • 1 view

We manage Google Business Profile, hosting, and social logins for a decent number of clients, and it used to be normal for a client to reuse the same password across their GBP, their hosting, and their personal email, since a lot of small business owners just aren't thinking about it when they hand over access.

Started running Watchtower reports across the vaults where we store client credentials, mainly looking for weak or reused passwords rather than just breach alerts. Last month it flagged a client whose hosting password was identical to a password that had shown up in a known breach from an unrelated site years earlier. Nothing had happened yet, but it was sitting there as an open door.

Walked the client through resetting it and moving them onto a unique, generated password for that account specifically. Small thing, but it's the kind of issue that's invisible until it's actually exploited, and a client would never think to check for it themselves.

Now we run a Watchtower pass across all managed client vaults roughly once a month as part of our own internal checklist rather than waiting for something to go wrong first.

Curious if others managing multiple clients' credentials do something similar on a schedule, or if this tends to only get checked reactively after an incident. Also wondering if anyone's automated this via the CLI rather than checking manually each time.

We're a small team handling this across quite a few client accounts now, so a recurring check like this has genuinely caught something real before it became a problem.