Say you use the same password for a design app and your email. The design app has a data breach, which happens constantly and rarely makes the news. That password is now sitting in a file being tried against email logins everywhere, including yours.
Why this works so well for scammers
Most people reuse a handful of passwords across dozens of accounts, because remembering dozens of unique ones is genuinely hard without help. Scammers know this, and automated tools can try a leaked password against thousands of other services in minutes. It doesn't take a skilled hacker, just a list and some patience.
The password itself doesn't need to be weak. It just needs to be shared.
The realistic fix
You don't need to memorise thirty different passwords. A password manager does the remembering for you and can generate a unique one for each account in a couple of clicks. Start with email, since it's usually the key that resets everything else.
Check if you're already exposed
Have I Been Pwned lets you check whether your email address has turned up in a known breach, free. Find it on the Free Resources page.