94% of the 19 billion passwords exposed in breaches between April 2024 and April 2025 were reused or duplicated, according to a Cybernews analysis of leaked credential data. That single figure explains why passwords keep failing: attackers no longer crack them, they collect them once and replay them everywhere. Stolen credentials were the top initial access vector in 22% of breaches in the Verizon 2025 Data Breach Investigations Report, Microsoft now blocks roughly 7,000 password attacks per second, and the FIDO Alliance estimates 5 billion passkeys are already in active use as the industry races toward a passwordless future. This analysis consolidates data from the Verizon DBIR, the FIDO Alliance, NordPass, IBM, Microsoft, and 13 other primary sources to map where password security actually stands in 2026. For the wider threat picture, see our cybersecurity statistics roundup.
TL;DR
- 94% of 19 billion breached passwords were reused or duplicated (Cybernews, 19 Billion Password Analysis 2025).
- 22% of breaches started with stolen credentials, the single most common initial access vector (Verizon, 2025 DBIR).
- 78% of the world’s most common passwords crack in under one second (NordPass, Top 200 Most Common Passwords 2025).
- A random 8-character password using all character types takes about 132 years to brute-force offline (Hive Systems, 2026 Password Table).
- Microsoft blocks about 7,000 password attacks per second and tracks 600 million daily identity attacks (Microsoft, Digital Defense Report 2025).
- Credential-based breaches cost $4.67 million on average and take 292 days to contain (IBM, Cost of a Data Breach 2025).
- 5 billion passkeys are estimated in active use, with 90% consumer awareness (FIDO Alliance, State of Passkeys 2026).
- Phishing-resistant MFA blocks more than 99% of identity-based attacks (Microsoft, Digital Defense Report 2025).
- 70% of workforce users had MFA enabled as of January 2025, up from prior years (Okta, Secure Sign-in Trends Report 2025).
- Roughly 16 billion credentials surfaced in a June 2025 compilation of about 30 datasets (Cybernews, 2025).
1. Password Reuse and Weak Habits
Reuse, not weak complexity, is the structural flaw. When 94% of exposed passwords repeat across accounts, one breach at a low-value site hands attackers keys to email, banking, and work logins. Bitwarden’s 2025 survey found 72% of Gen Z reuse passwords against 42% of Boomers, so the problem is not confined to older or less technical users. The awareness gap is the tell: people know the rules and break them anyway. The same behavior fuels downstream fraud tracked in our identity theft statistics.
| Metric | Value | Source |
|---|---|---|
| Breached passwords that were reused or duplicated | 94% | Cybernews, 19 Billion Password Analysis 2025 |
| Americans who often or always reuse a password | 62% | NordPass survey, 2025 |
| Users who reuse passwords across accounts | 66% | Google/Harris Poll Online Security Survey (most recent available) |
| Gen Z reuse rate vs Boomers | 72% vs 42% | Bitwarden, World Password Day Survey 2025 |
| Gen Z who rarely or never update passwords after a breach | 35% | Bitwarden, World Password Day Survey 2025 |
| Times “123456” was counted as the top global password | 4.5 million+ | NordPass, Top 200 Most Common Passwords 2025 |
| Americans who have used a weak password like ‘password’ or ‘123456’ | 24% | Google/Harris Poll Online Security Survey (most recent available) |
| Users who call themselves familiar with best practices yet struggle to apply them | 90% | Bitwarden, World Password Day Survey 2025 |
Note: The Google/Harris Poll figures are the most recent publicly available from that survey and are flagged accordingly; 2025 reuse readings from Cybernews, NordPass, and Bitwarden corroborate the direction.
2. How Fast Weak Passwords Fall
Cracking economics keep improving for attackers. Consumer GPUs get cheaper and faster every year, so the same weak password buys less protection than it did last year. NordPass reports 78% of the world’s most common passwords crack in under one second, and Hive Systems shows the crack time for an 8-character complex password sliding from 225 years in 2024 to 132 years in 2026 as rented GPU fleets speed up. The defensive takeaway is blunt: length and randomness matter far more than swapping a letter for a symbol.
| Metric | Value | Source |
|---|---|---|
| World’s most common passwords cracked in under 1 second | 78% | NordPass, Top 200 Most Common Passwords 2025 |
| Time to crack ‘123456’ or ‘admin’ | Under 1 second | NordPass, Top 200 Most Common Passwords 2025 |
| Random 8-character password, all character types | ~132 years | Hive Systems, 2026 Password Table |
| Same 8-character password, lowercase letters only | ~2 weeks | Hive Systems, 2026 Password Table |
| 8-character complex crack-time trend (2024 to 2026) | 225 to 164 to 132 years | Hive Systems, 2026 Password Table |
| Year-over-year drop in crack time on rented GPUs | ~20% | Hive Systems, 2026 Password Table |
Outlier: Hive Systems benchmarks a rented 16x RTX 5090 fleet at 138,675 hashes per second against bcrypt (work factor 10); poorly hashed passwords fall far faster than these bcrypt figures suggest.
3. Stolen Credentials and Data Breaches
The credential is now the product. Attackers buy or harvest valid logins rather than defeating cryptography, which is why credential-driven intrusions are slow to detect and expensive to clean up. The Verizon 2025 DBIR found stolen credentials in 32% of all breaches and behind 88% of Basic Web Application attacks, while IBM measured credential-based breaches at $4.67 million each and 292 days to contain, the slowest of any breach type. The June 2025 mega-compilation of 16 billion records shows the raw supply feeding these attacks. This section pairs with our dedicated data breach statistics.
| Metric | Value | Source |
|---|---|---|
| Breaches with stolen credentials as the initial access vector | 22% | Verizon, 2025 Data Breach Investigations Report |
| All breaches involving stolen credentials | 32% | Verizon, 2025 DBIR |
| Basic Web Application attacks using stolen credentials | 88% | Verizon, 2025 DBIR |
| Breaches involving the human element | 60% | Verizon, 2025 DBIR |
| Credentials exposed in the June 2025 compilation | ~16 billion (across ~30 datasets) | Cybernews, 2025 |
| Average cost of a credential-based breach | $4.67 million | IBM, Cost of a Data Breach 2025 |
| Time to identify and contain a credential-based breach | 292 days | IBM, Cost of a Data Breach 2025 |
| Global average cost of a data breach (down 9% year over year) | $4.44 million | IBM, Cost of a Data Breach 2025 |
Context: The 16 billion figure is a compilation of infostealer logs and repackaged older leaks, not a single new breach, per Cybernews and BleepingComputer.
4. Credential Stuffing and Automated Attacks
Reuse plus automation equals scale. Because the same passwords repeat everywhere, attackers script millions of login attempts against stolen lists and let the hits roll in. Akamai counted roughly 26 billion credential-stuffing attempts per month, and Verizon found stuffing accounted for a median 19% of daily authentication attempts on single-sign-on providers, meaning about one in five login attempts on typical services is an attacker testing stolen credentials. AI now supercharges the social-engineering side, including voice-cloned phone scams covered in our vishing statistics.
| Metric | Value | Source |
|---|---|---|
| Credential-stuffing attempts per month | ~26 billion | Akamai, State of the Internet / Securing Apps (2024, most recent available) |
| Median share of daily authentication attempts that were credential stuffing | 19% | Verizon, 2025 DBIR |
| Password attacks blocked per second | ~7,000 | Microsoft, Digital Defense Report 2025 |
| Daily identity attacks tracked | 600 million | Microsoft, Digital Defense Report 2025 |
| Share of identity attacks that are password attacks | 97% | Microsoft, Digital Defense Report 2025 |
| Rise in identity-based attacks in H1 2025 | 32% | Microsoft, Digital Defense Report 2025 |
| Ransomware victims with prior credentials in infostealer logs | 54% | Verizon, 2025 DBIR |
| Phishing attacks tracked in 2025 | 3.8 million | APWG, Phishing Activity Trends Reports 2025 |
Outlier: Microsoft reports more than 97% of identity attacks are password spray attempts against weak or overused passwords, underscoring that automation targets the reuse problem directly.
5. Passkeys and the Passwordless Shift
The replacement is arriving faster than most password behavior is improving. Passkeys are phishing-resistant by design because there is no shared secret to steal or replay, and adoption has moved from pilot to mainstream in a single year. The FIDO Alliance estimates 5 billion passkeys are now in active use, with consumer awareness at 90%, up from 75% a year earlier. Google’s default-passkey decision alone exposed hundreds of millions of accounts to passwordless sign-in, the largest real-world deployment to date.
| Metric | Value | Source |
|---|---|---|
| Consumer awareness of passkeys (up from 75%) | 90% | FIDO Alliance, State of Passkeys 2026 |
| Consumers who have enabled a passkey on at least one account | 75% | FIDO Alliance, State of Passkeys 2026 |
| Passkeys estimated in active use worldwide | 5 billion | FIDO Alliance, State of Passkeys 2026 |
| Organizations deploying, piloting, or rolling out passkeys | 68% | FIDO Alliance, State of Passkeys 2026 |
| Top 100 websites that now offer passkeys | 48% | FIDO Alliance, State of Passkeys 2026 |
| Google accounts using passkeys / total passkey sign-ins | 800 million / 2.5 billion | Google, 2025 |
| Passkey login success rate vs passwords | 93% vs 63% | FIDO Alliance, Passkey Index 2025 |
Context: Google reports passkey sign-ins are about 20% faster and post a 30% higher success rate than passwords, matching the FIDO Passkey Index direction.
6. MFA Adoption and Effectiveness
MFA works, but coverage is uneven and often not phishing-resistant. The effectiveness data is decisive, yet a large share of accounts and companies still leave gaps that attackers probe daily. Microsoft states phishing-resistant MFA blocks more than 99% of identity-based attacks, even when the attacker already holds a valid username and password. The lag is on the human side: basic SMS or push MFA remains common, and many personal email accounts, the reset hub for everything else, still have no second factor. Weak authentication is a recurring theme in our digital privacy statistics.
| Metric | Value | Source |
|---|---|---|
| Identity-based attacks blocked by phishing-resistant MFA | 99%+ | Microsoft, Digital Defense Report 2025 |
| Workforce users with MFA enabled (January 2025) | 70% | Okta, Secure Sign-in Trends Report 2025 |
| Year-over-year growth in phishing-resistant authenticator adoption | 63% | Okta, Secure Sign-in Trends Report 2025 |
| Workforce users who used no password for any sign-in | 7% | Okta, Secure Sign-in Trends Report 2025 |
| Companies using MFA across all applications | 48% | Yubico, Global State of Authentication 2025 |
| Users with no MFA on personal email | 29% | Yubico, Global State of Authentication 2025 |
| Users who consider username and password the most secure option | 26% | Yubico, Global State of Authentication 2025 |
Outlier: Yubico’s survey of 18,000 adults across nine countries found only 26% still rank passwords as most secure, yet 60% keep using them for personal accounts, a clear perception-versus-behavior gap.
7. The Cost of Passwords and the Passwordless Market
Passwords are expensive even when nothing is breached. Reset tickets, help-desk labor, and lost productivity add up long before an attacker succeeds, which is the business case behind the passwordless market’s growth. Analysts value the passwordless authentication market at roughly $24 to $25 billion in 2025, projected to reach about $55.7 billion by 2030 at a 17 to 18% CAGR. Meanwhile organizations that deploy passkeys report sharply lower support costs, and password-manager users report materially less identity theft than non-users.
| Metric | Value | Source |
|---|---|---|
| Passwordless authentication market size (2025) | ~$24 to $25 billion | Mordor Intelligence / Grand View Research, 2025 |
| Projected passwordless market size (2030) | ~$55.7 billion (17 to 18% CAGR) | Grand View Research / Mordor Intelligence, 2025 |
| Average help-desk cost per password reset | ~$70 | Forrester (most recent available) |
| Help-desk calls that are password resets | 20% to 50% | Gartner (most recent available) |
| US adults who use a password manager | 36% (~94 million) | Security.org, Password Manager Annual Report |
| Identity or credential theft: password-manager users vs non-users | 17% vs 32% | Security.org, Password Manager Annual Report |
| Reduction in sign-in time with passkeys (avg 8.5 seconds) | 73% | FIDO Alliance, Passkey Index 2025 |
| Reduction in login-related help-desk incidents with passkeys | 81% | FIDO Alliance, Passkey Index 2025 |
Context: The Forrester and Gartner reset-cost figures are the most recent widely cited estimates and are flagged as such; 2025 market forecasts are cross-referenced across Mordor Intelligence and Grand View Research.
Summary: Password Security by the Numbers
| Metric | Value | Source |
|---|---|---|
| Breached passwords reused or duplicated | 94% | Cybernews, 19 Billion Password Analysis 2025 |
| Americans who often or always reuse a password | 62% | NordPass survey, 2025 |
| Gen Z reuse rate vs Boomers | 72% vs 42% | Bitwarden, World Password Day Survey 2025 |
| Common passwords cracked in under 1 second | 78% | NordPass, Top 200 Most Common Passwords 2025 |
| Random 8-character complex password crack time | ~132 years | Hive Systems, 2026 Password Table |
| Breaches with stolen credentials as initial access vector | 22% | Verizon, 2025 DBIR |
| All breaches involving stolen credentials | 32% | Verizon, 2025 DBIR |
| Breaches involving the human element | 60% | Verizon, 2025 DBIR |
| Average cost of a credential-based breach | $4.67 million | IBM, Cost of a Data Breach 2025 |
| Global average data-breach cost (down 9%) | $4.44 million | IBM, Cost of a Data Breach 2025 |
| Credentials in the June 2025 compilation | ~16 billion | Cybernews, 2025 |
| Credential-stuffing attempts per month | ~26 billion | Akamai, State of the Internet (2024) |
| Password attacks blocked per second | ~7,000 | Microsoft, Digital Defense Report 2025 |
| Identity-based attacks blocked by phishing-resistant MFA | 99%+ | Microsoft, Digital Defense Report 2025 |
| Passkeys in active use worldwide | 5 billion | FIDO Alliance, State of Passkeys 2026 |
| Consumer awareness of passkeys | 90% | FIDO Alliance, State of Passkeys 2026 |
| Google accounts using passkeys | 800 million | Google, 2025 |
| Workforce users with MFA enabled (Jan 2025) | 70% | Okta, Secure Sign-in Trends Report 2025 |
| Companies using MFA across all applications | 48% | Yubico, Global State of Authentication 2025 |
| Passwordless market size by 2030 | ~$55.7 billion | Grand View Research / Mordor Intelligence, 2025 |
Methodology and Sources
Data was gathered by aggregating figures directly from primary reports, surveys, and datasets published by the organizations below, prioritizing 2025 and 2026 editions and flagging older figures as most recent available. Every statistic in this article was taken from a source reviewed during research; no numbers were estimated or derived.
- Verizon, 2025 Data Breach Investigations Report (2025) - report
- FIDO Alliance, State of Passkeys 2026 and Passkey Index (2025-2026) - report
- NordPass, Top 200 Most Common Passwords and reuse survey (2025) - report
- IBM, Cost of a Data Breach Report 2025 (2025) - report
- Hive Systems, 2026 Password Table (2026) - report
- Microsoft, Digital Defense Report 2025 (2025) - report
- Okta, Secure Sign-in Trends Report 2025 (2025) - report
- Yubico, Global State of Authentication Report 2025 (2025)
- Bitwarden, World Password Day Global Survey 2025 (2025) - report
- Cybernews, 19 Billion Password Analysis and 16 Billion Credential Compilation (2025) - report
- Google, passkey adoption figures (2025)
- Google/Harris Poll, Online Security Survey (most recent available)
- Security.org, Password Manager Annual Report - report
- APWG, Phishing Activity Trends Reports 2025 (2025)
- Akamai, State of the Internet / credential stuffing (2024)
- Mordor Intelligence, Passwordless Authentication Market (2025)
- Grand View Research, Passwordless Authentication Market (2025) - report
- Forrester and Gartner, password reset cost estimates (most recent available)
Data watch: The Verizon DBIR publishes annually each spring (a 2026 edition is expected), the FIDO Alliance updates its State of Passkeys and Passkey Index yearly, NordPass releases its Top 200 Most Common Passwords each November, IBM’s Cost of a Data Breach lands mid-year, Hive Systems refreshes its Password Table annually, and Microsoft’s Digital Defense Report and Okta’s Secure Sign-in Trends Report are annual; the next editions of several are due within months.
Last updated: July 16, 2026.
We review and update this page quarterly as new data is published.