Researchers from Carnegie Mellon University published a paper about peoples behavior after their passwords were compromised in a data breach. The study looked at the effectiveness of password-related breach notifications and practices enforced after a breach. Only 33% of the 63 people affected changed their passwords immediately after the breach announcement, and only 13% did so within three months of the announcement. The same people also had, on average, 30 other passwords that were similar to the breached password. 70% of these password changes resulted in passwords that are weaker or no stronger.”]

