1. The first thing and most common is people
using a skeleton key, A skeleton key is when you use the same password for everything, If you check this site
https://haveibeenpwned.com/ many big websites you have used leaked your passwords and emails (LinkedIn, This forum, Myspace, are just to name a few). If you have coins on a exchange and you use the same password as your email, consider your coins gone. In addition If you are using coins on a exchange you did not read the first sentence of the white paper and I suggest you do that before holding any bitcoins, it is meant to be p2p and not go through two financial institution.
Skeleton key is the term for this?on using up same passwords on any site you are engage into,sounds pretty new to me.
I had this mistake where using passwords the same on all accounts plus in my email and that one hack which results for me to lost up all of my savings
in a flash after that I had learned that mistake.This may sounds pretty basic but this is one of the most important thing to be done.