Kyle Milliken used lists of login credentials to target accounts automatically, relying on the fact that many people reuse passwords across multiple online services. Some of his largest thefts included Disqus (17.5 million), Kickstarter (5.2 million) and Imgur (1.7 million) He hacked his targets via a hosted server that he rented under an alias, and always accessed it via a VPN to protect his IP. When he hacked Disqus, he forgot to use the VPN, and in 2014 the FBI caught him. He cooperated with the FBI and received a 17-month prison term in a federal work camp.”]
Source: https://nakedsecurity.sophos.com/2019/09/17/former-hacker-warns-against-password-reuse/