A database of plaintext passwords is a breach that reaches every other service your users touch, because people reuse. Hashing makes verification possible without storage of the secret: you hash the attempt and compare. The algorithm matters — bcrypt, scrypt or Argon2 are designed to be expensive to guess; plain SHA-256 is not a password hash, just a fast one.
The salt defeats the shortcut: an identical per-password random value means two users with 'password1' get different hashes, so attackers cannot crack the whole table in one pass. 'We encrypt passwords' is the red flag — encryption is reversible by whoever holds the key; the point is that nobody should be able to get the password back.
Related terms
MFA / 2FA
Multi-factor authentication — proving identity with something you know plus something you have, so a leaked password alone cannot log in.
Encryption at rest
Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.
Data minimization
Collecting and keeping only the data the job needs — the GDPR principle that is also the cheapest security control: what you do not hold cannot leak.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
