When password theft is mentioned, most people think of phishing campaigns, leaked databases, or ransomware groups selling millions of credentials on the dark web. However, the first recorded password breach occurred at a time when the internet did not exist.
There were no Wi-Fi networks, cloud services, social networks, or even personal computers. Computers occupied entire rooms and were mainly used by universities and research centers. Nevertheless, the problem that represents one of the greatest threats to cybersecurity today already existed back then.
How the First Computer Password Was Created
In the early sixties at MIT, the Compatible Time-Sharing System (CTSS) was being developed, one of the first operating systems that allowed multiple users to use the same computer simultaneously. This was a revolutionary concept at a time when a single computer could generally execute only one task. But a new problem emerged: if multiple researchers use the same system, how to prevent everyone from accessing someone else’s files?
The solution devised by Professor Fernando Corbató was simple: each user received their own account and their own password. No one could have guessed then that this very idea would become one of the foundations of modern digital security.

The First Password Theft Was Not Carried Out by a Sophisticated Hacker
Only a few years after passwords were introduced as a way to protect user accounts, it turned out that they were not infallible either. At MIT, each user had a limited amount of time to work on the computer, as one computer was shared by several people. When a student at the time, Allan Scherr, ran out of his allocated time, instead of requesting a new quota, he found a flaw in the system. He managed to access the file where user passwords were saved, print its contents, and log into other people’s accounts to use their available time. This event is often cited as the first documented case of password compromise in computing history.
Ironically, one of the first security incidents in history was not the result of a sophisticated attack, but a combination of curiosity, insufficiently developed security controls, and the fact that passwords were not protected in the way we take for granted today.
What Has Really Changed in 60 Years?
At first glance, almost everything. Today, organizations use multi-factor authentication, Zero Trust architecture, biometric authentication, advanced threat detection systems, and AI tools for user behavior analysis. But when we look at the attackers’ motives, the picture looks almost the same as in 1962. Back then, the goal was to gain access to user accounts. Today, the goal remains the same; only the tools have changed.
Instead of printing a text file with passwords, attackers today use:
- phishing pages that faithfully imitate legitimate services,
- infostealer malware that collects saved credentials from browsers,
- theft of session cookies (session cookies),
- attacks on authentication tokens,
- purchasing compromised credentials on illegal markets,
- techniques such as MFA fatigue to trick users into approving access themselves.
In other words, attackers today much less frequently try to guess a password. They more often try to steal it.
The Problem Is No Longer Passwords, but Identities
For years, organizations tried to improve security by requiring increasingly complex passwords. At least 12 characters, uppercase and lowercase letters, numbers, special characters, and regular password changes.
However, modern practice shows that even the most complex password provides no protection if the user hands it over to an attacker via a phishing page or if it is compromised by infostealer malware. That is why in recent years, the focus of cybersecurity has shifted from protecting the password itself to protecting the digital identity.
In other words, it is no longer enough to verify what the user knows. It is necessary to confirm who the user is, from which device they are accessing, where they are logging in from, what their usual behavior is, and whether there are indicators of compromise.
That is precisely why more and more organizations are introducing passkeys, adaptive authentication, Privileged Access Management (PAM), and Identity Threat Detection and Response (ITDR) as a response to growing identity-targeted threats.
History Is a Warning to Us
Years later, Fernando Corbató stated that he could not have imagined how much the simple idea of user passwords would shape the future of computing. Ironically, the man who helped create the modern computer password later described it as a kind of nightmare, pointing out how difficult it is for users to manage a large number of different credentials.
More than six decades later, his story remains extremely relevant. Not because we still use the same passwords, but because attackers are still trying to achieve the same goal: to take over someone’s identity. From the first password breach at MIT to today’s identity theft-based attacks, the technology has changed, the tools have changed, and the scale of the attacks has changed.
But the fundamental lesson remains the same: the most valuable target was never the password. It has always been just the shortest path to someone’s identity. If identities are the most valuable target for attackers today, their protection must be a priority for every organization. PULSEC helps companies build reliable digital identity protection through IAM, PAM, MFA, and Zero Trust solutions, with expert support in implementation and access management. Explore our services or contact us so we can together assess the security of your identity environment.