A mere email... I had a situation with a bank when their website accepted new password but the backend implicitly and without feedback trimmed the new password to 10 characters.
I don't know if it truncated it automatically or it just stopped accepting input after 20 characters and I of course did not notice since the password entry fields were masked.