https://www.random.org/passwords/
Generate a list of random passwords, then mix in or add some special characters.
Two-factor auth everywhere possible. Credential stuffing is expensive and processor-heavy and the second factor on an identity takes revenue away from the bad actors.